This problem occurs as a result of misconfiguration.

If you typo or leave blank the LDAP server name to use in LDAPData, then whenever a user is loaded or edited there is a heinous two or three minute delay. The page does eventually load, and in the error log you see an error like this:

LDAP Bind failure for user cn=username,ou=Users,dc=domain,dc=org. Error -1: Can't contact LDAP server

The problem is usually just misconfiguration - you called the server "ldapserver" in admin/settings/ldapauth and called it "ldap server" in admin/settings/ldapdata.

When it's time for ldapdata to bind in the user hooks it calls _ldapdata_edition_dn() which in turn attempts to figure out the correct DN for the user. The user's ldap_config variable is read (e.g. "ldap server") and then it looks up the LDAP server address and bind info in the DB's ldapauth table. At this point if there was a typo, a blank DN and pass come back.

The delay can be avoided and a useful message can be logged to the error log with the following patch. It is in ldap_integration/LDAPInterface.php so it catches this problem anywhere it occurs by ldapdata or other future ldap modules that use the LDAP Interface. It merely adds a check to ldap->connect() so that it will not disconnect or attempt a connection with a blank DN,password.

This patch is against LDAPInterface.php,v 1.7 2007/03/03 03:23:56 scafmac

D.

Comments

damien_vancouver’s picture

Looking at this some more I discovered that it wasn't a typo - there is nowhere to just type in the ldapdata server. Somehow my ldapdata got pointing at the wrong configuration name... maybe due to the ldap server being renamed.

I will try and reproduce the problem, it should be fixed there as well. This patch is still very useful as a catch all to prevent that 2 minute delay... I have seen it several times in the last year of using ldap integration when there are configuration issues. I will follow up when I find what it is and submit a separate patch to fix.

damien_vancouver’s picture

It looks like my error condition occurred when upgrading ldap_integration from 5.x-1.0 to 5.x-1.2. If I modify the name of the server in admin/settings/ldapauth, the name is correctly updated in admin/settings/ldapdata.

So the original patch to stop the bind timeout should be sufficient.

D.

kreaper’s picture

Damien

Thanks for the patch. I will commit it soon.

kreaper

kreaper’s picture

Version: master » 5.x-1.2
Assigned: Unassigned » kreaper
Status: Reviewed & tested by the community » Closed (fixed)

patch committed.