This problem occurs as a result of misconfiguration.
If you typo or leave blank the LDAP server name to use in LDAPData, then whenever a user is loaded or edited there is a heinous two or three minute delay. The page does eventually load, and in the error log you see an error like this:
LDAP Bind failure for user cn=username,ou=Users,dc=domain,dc=org. Error -1: Can't contact LDAP server
The problem is usually just misconfiguration - you called the server "ldapserver" in admin/settings/ldapauth and called it "ldap server" in admin/settings/ldapdata.
When it's time for ldapdata to bind in the user hooks it calls _ldapdata_edition_dn() which in turn attempts to figure out the correct DN for the user. The user's ldap_config variable is read (e.g. "ldap server") and then it looks up the LDAP server address and bind info in the DB's ldapauth table. At this point if there was a typo, a blank DN and pass come back.
The delay can be avoided and a useful message can be logged to the error log with the following patch. It is in ldap_integration/LDAPInterface.php so it catches this problem anywhere it occurs by ldapdata or other future ldap modules that use the LDAP Interface. It merely adds a check to ldap->connect() so that it will not disconnect or attempt a connection with a blank DN,password.
This patch is against LDAPInterface.php,v 1.7 2007/03/03 03:23:56 scafmac
D.
| Comment | File | Size | Author |
|---|---|---|---|
| ldap_integration_5.x-1.2_blank_connect_timeout_fix_0.patch | 1015 bytes | damien_vancouver |
Comments
Comment #1
damien_vancouver commentedLooking at this some more I discovered that it wasn't a typo - there is nowhere to just type in the ldapdata server. Somehow my ldapdata got pointing at the wrong configuration name... maybe due to the ldap server being renamed.
I will try and reproduce the problem, it should be fixed there as well. This patch is still very useful as a catch all to prevent that 2 minute delay... I have seen it several times in the last year of using ldap integration when there are configuration issues. I will follow up when I find what it is and submit a separate patch to fix.
Comment #2
damien_vancouver commentedIt looks like my error condition occurred when upgrading ldap_integration from 5.x-1.0 to 5.x-1.2. If I modify the name of the server in admin/settings/ldapauth, the name is correctly updated in admin/settings/ldapdata.
So the original patch to stop the bind timeout should be sufficient.
D.
Comment #3
kreaper commentedDamien
Thanks for the patch. I will commit it soon.
kreaper
Comment #4
kreaper commentedpatch committed.