Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-14 Thread Walter van Lille
Roughly 128 clients.. But when the services start going gaa-gaa it also causes time-outs with the naming service running on the same server. I may be wrong, but wouldn't that basically kill any chance of a client connecting to the server anyway? I'm just lucky that the clients aren't really there

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-13 Thread Ludwig Krispenz
Hmm, the symbols are there now, but all threads are idle, DS is just waiting on work to do. Which client do you expect to connect to DS, maybe you need to debug this client. On 11/13/2014 11:02 AM, Walter van Lille wrote: Thanks Rich, I have installed the packages and run gdb again. Hopefully

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-13 Thread Rich Megginson
On 11/13/2014 03:02 AM, Walter van Lille wrote: Thanks Rich, I have installed the packages and run gdb again. Hopefully the attached file is more useful. The symbols are there. However, the server is almost completely idle - no hangs, no deadlocks, no waiting on I/O. You must catch dirsrv

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Martin Basti
IMHO It's DS bug, can you share DS error log? pspacek CCed to examine named logs. Martin^2 On 11/11/14 12:13, Walter van Lille wrote: Hi Martin, thanks for the reply. My version: bind-dyndb-ldap-2.3-5.el6.x86_64 The server doesn't have journalctl installed but I have the outputs from the

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Walter van Lille
I've just cleaned out a ton of slapd_poll timed out messages from the output and changed the names to protect the innocent, :-) Here is the output as requested: *[05/Nov/2014:11:44:05 +0200] - SASL encrypted packet length exceeds maximum allowed limit (length=805634565, limit=2097152). Change

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Petr Spacek
On 11.11.2014 13:13, Walter van Lille wrote: SASL encrypted packet length exceeds maximum allowed limit Martin, do you remember where is the appropriate knob? -- Petr^2 Spacek -- Manage your subscription for the Freeipa-users mailing list:

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Martin Basti
Ludiwg (CCed) this seems like old (fixed?) DS bug. On 11/11/14 13:13, Walter van Lille wrote: I've just cleaned out a ton of slapd_poll timed out messages from the output and changed the names to protect the innocent, :-) Here is the output as requested: *[05/Nov/2014:11:44:05 +0200] - SASL

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Martin Kosek
On 11/11/2014 01:29 PM, Petr Spacek wrote: On 11.11.2014 13:13, Walter van Lille wrote: SASL encrypted packet length exceeds maximum allowed limit Martin, do you remember where is the appropriate knob? Do you mean nsslapd-sasl-max-buffer-size setting in cn=config? This is a related ticket

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Ludwig Krispenz
On 11/11/2014 02:14 PM, Martin Basti wrote: Ludiwg (CCed) this seems like old (fixed?) DS bug. hmm, it says limit is 2097152, so it already has the new setting, but the error message says the packet is 800MB* * On 11/11/14 13:13, Walter van Lille wrote: I've just cleaned out a ton of

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Rich Megginson
On 11/11/2014 06:20 AM, Ludwig Krispenz wrote: On 11/11/2014 02:14 PM, Martin Basti wrote: Ludiwg (CCed) this seems like old (fixed?) DS bug. hmm, it says limit is 2097152, so it already has the new setting, but the error message says the packet is 800MB* * *Right. That usually means the

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Martin Basti
On 11/11/14 15:58, Rich Megginson wrote: On 11/11/2014 06:20 AM, Ludwig Krispenz wrote: On 11/11/2014 02:14 PM, Martin Basti wrote: Ludiwg (CCed) this seems like old (fixed?) DS bug. hmm, it says limit is 2097152, so it already has the new setting, but the error message says the packet is

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-11 Thread Rich Megginson
On 11/11/2014 10:37 AM, Martin Basti wrote: On 11/11/14 15:58, Rich Megginson wrote: On 11/11/2014 06:20 AM, Ludwig Krispenz wrote: On 11/11/2014 02:14 PM, Martin Basti wrote: Ludiwg (CCed) this seems like old (fixed?) DS bug. hmm, it says limit is 2097152, so it already has the new setting,

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-07 Thread Petr Spacek
On 6.11.2014 16:41, Dmitri Pal wrote: On 11/06/2014 10:00 AM, Martin Basti wrote: On 06/11/14 14:58, Walter van Lille wrote: Hi, I need some assistance please. I've taken over an IPA server to manage a few months ago, and it was working fine until recently when it started acting up seemingly

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-06 Thread Martin Basti
On 06/11/14 14:58, Walter van Lille wrote: Hi, I need some assistance please. I've taken over an IPA server to manage a few months ago, and it was working fine until recently when it started acting up seemingly off its own accord. When I do an ipactl status it basically gives an output as

Re: [Freeipa-users] FreeIPA unresponsive - Causes DOS situations

2014-11-06 Thread Dmitri Pal
On 11/06/2014 10:00 AM, Martin Basti wrote: On 06/11/14 14:58, Walter van Lille wrote: Hi, I need some assistance please. I've taken over an IPA server to manage a few months ago, and it was working fine until recently when it started acting up seemingly off its own accord. When I do an