Once you're satisfied that it's working correctly, could you share your
options/settings in this thread? I know I (and probably others) will be
coming to this point Real Soon Now and the additional knowledge would be
helpful.

Thanks,
--Dave


--

DAVID A. CURRY, CISSP
*DIRECTOR OF INFORMATION SECURITY*
INFORMATION TECHNOLOGY

71 FIFTH AVE., 9TH FL., NEW YORK, NY 10003
+1 212 229-5300 x4728 • [email protected]

[image: The New School]

On Thu, Dec 21, 2017 at 12:42 PM, William E. <[email protected]> wrote:

> Thanks Uxio.
>
> Luckily, since changing to delegating IDP functions to Shibboleth, as it
> was on cas 3 setup on this same server, memory seems to be stable.  That
> and adding the -XX:-UseCompressedOops opt recommended by Unicon
> support(many thanks!).  Not entirely sure which item gets the kudos,
> perhaps both, but I will test a bit more with one or the other over the
> holidays to try and determine which was the factor.
>
> Screenshot of stats.
>
> Primary server now has 8GB of swap.  Added to server while up without
> disruption.  Linux rocks!
>
> Thanks,
> William
>
>
>
>
>
> On Thursday, December 21, 2017 at 11:10:40 AM UTC-6, Uxío Prego wrote:
>>
>> Swap is good, generally, but as more dedicated is the server, it should
>> make less of a difference, because of your -Xmx configuration.
>>
>> I don't know about the specific numbers of version 5, but (pending
>> knowing how many concurrent sessions do you normally manage) maybe the
>> server is having a deployment problem (maybe not).
>>
>> I think 8G should be enough for your case, but I don't really know. While
>> you keep investigating, maybe adding swap and more memory can help you...
>> maybe not!
>>
>> Good luck with it,
>>
>> Uxío Prego
>>
>>
>>
>> Madiva Soluciones
>> CL / SERRANO GALVACHE 56
>> <https://maps.google.com/?q=CL+/+SERRANO+GALVACHE+56&entry=gmail&source=g>
>> BLOQUE ABEDUL PLANTA 4
>> 28033 MADRID
>> +34 917 56 84 94
>> www.madiva.com
>> www.bbva.com
>>
>> The activity of email inboxes can be systematically tracked by
>> colleagues, business partners and third parties. Turn off automatic loading
>> of images to hamper it.
>>
>> 2017-12-21 16:45 GMT+00:00 William E. <[email protected]>:
>>
>>> Martin,
>>>
>>> Thank you.  You might be on to something.  I was quoting from memory and
>>> I was wrong on swap.  Of the two nodes, both in my mind identical VM's, the
>>> secondary node has 8GB of swap and a tiny bit used, but the primary, the
>>> one that is crashing, has no swap configured.  I have requested our systems
>>> team add 8GB of swap to the primary.
>>>
>>> Primary server:
>>>
>>>               total        used        free      shared  buff/cache
>>>  available
>>> Mem:        8010840     4872660      420488      107484     2717692
>>>  2679336
>>> Swap:             0           0           0
>>>
>>>
>>>
>>> Secondary server:
>>>
>>>               total        used        free      shared  buff/cache
>>>  available
>>> Mem:        8010972     1192296     1530500       23196     5288176
>>>  6449948
>>> Swap:       8388604        4604     8384000
>>>
>>>
>>> Not sure I understand why it would matter since in theory swap should
>>> not be needed on a server with 8GB of ram with jvm limit set to 6GB
>>> though.  Any more insight on why, because I would really like to understand
>>> the reason.
>>>
>>>
>>> Additionally, I've put the shibboleth IDP back into play, effectively
>>> rendering the saml services in cas "unused".  I am using proxy_ajp to front
>>> tomcat with apache so it was easy to copy the idp.war into tomcat and
>>> re-enable the shib-cas-authenticator. I guess my hope of moving from
>>> cas+shibb. to just cas will have to wait....
>>>
>>>
>>> Thanks,
>>> William
>>>
>>> P.S. Jeff, thank you for posting your catalina opts!
>>>
>>>
>>> On Wednesday, December 20, 2017 at 11:30:40 PM UTC-6, Martin Bohun wrote:
>>>>
>>>> I have seen the behavior you are describing when people ran cas
>>>> (tomcat, mysql, etc.) on a (what I would consider a misconfigured) Linux
>>>> box with 0 swap.
>>>> However you are saying you have 4gb of swap.
>>>> I still do prefer to set my swap to 2 * $MY_RAM; can you try that?
>>>> adjust or add a swapfile to your swap (so you have 8gb RAM / 16gb swap), I
>>>> am curious if that would help / solve your problem?
>>>> What error messages are you getting in the jvm and syslog/systemd
>>>> journal from the OS?
>>>>
>>>> regards,
>>>>
>>>> martin
>>>>
>>>> On Thursday, December 21, 2017 at 1:35:45 PM UTC+11, William E. wrote:
>>>>>
>>>>> RHEL 7, 8GB ram, swap is 4GB.  It's a VM in our vSphere cluster+SAN.
>>>>> I actually have three, two PROD nodes behind a load balancer and one test
>>>>> node.  All have same specs and all show the issue.  Steadily chews up
>>>>> memory until eventual crash, 1-6 hours depending on load.
>>>>>
>>>>> The asme servers were running cas 3.6 . + shibboleth 3.3.x for quite a
>>>>> while without memory issues.  Upgraded and tried to consolidate to just 
>>>>> cas
>>>>> 5, using it's saml2 capabilities to replace the shibboleth component.  
>>>>> But,
>>>>> it's not going as well as I had hoped.
>>>>>
>>>>> Been working with Unicon Support on it, but it appears to be a memory
>>>>> leak in cas 5.2, based on heap analysis.  So I am kinda of stuck.
>>>>>
>>>>> Thanks for your help!
>>>>>
>>>>>
>>>>>
>>>>> On Wednesday, December 20, 2017 at 6:49:39 PM UTC-6, Martin Bohun
>>>>> wrote:
>>>>>>
>>>>>> What is your:
>>>>>> 1. operation system
>>>>>> 2. how much RAM do you have
>>>>>> 3. how much swap do you have
>>>>>>
>>>>>> if you are on  Linux you can do:
>>>>>> 1.    uname -a
>>>>>> 2-3. free -m
>>>>>>
>>>>>> and post the output here
>>>>>>
>>>>>> regards,
>>>>>>
>>>>>> martin
>>>>>>
>>>>>> On Thursday, December 21, 2017 at 11:00:30 AM UTC+11, William E.
>>>>>> wrote:
>>>>>>>
>>>>>>> Does anyone have any recommendations for CATALINA_OPTS for cas 5.x
>>>>>>> on tomcat 8?
>>>>>>>
>>>>>>> I am finding that our setup steadily eats up memory to the point
>>>>>>> that it eventually crashes from out of memory and has to be restarted.
>>>>>>>
>>>>>>> Current settings:
>>>>>>>
>>>>>>> CATALINA_OPTS="-Djava.awt.headless=true -Dfile.encoding=UTF-8
>>>>>>> -server -Xms1g -Xmx6g -XX:-UseGCOverheadLimit -XX:+UseConcMarkSweepGC
>>>>>>> -XX:-UseCompressedOops"
>>>>>>>
>>>>>>> JAVA_OPTS=$CATALINA_OPTS
>>>>>>>
>>>>>>>
>>>>>>> Thanks,
>>>>>>> William
>>>>>>>
>>>>>>> --
>>> - Website: https://apereo.github.io/cas
>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>> - List Guidelines: https://goo.gl/1VRrw7
>>> - Contributions: https://goo.gl/mh7qDG
>>> ---
>>> You received this message because you are subscribed to the Google
>>> Groups "CAS Community" group.
>>> To unsubscribe from this group and stop receiving emails from it, send
>>> an email to [email protected].
>>> To view this discussion on the web visit https://groups.google.com/a/ap
>>> ereo.org/d/msgid/cas-user/7e36f7d2-3bf7-49d2-bcd8-bbc0e22b90
>>> 1b%40apereo.org
>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/7e36f7d2-3bf7-49d2-bcd8-bbc0e22b901b%40apereo.org?utm_medium=email&utm_source=footer>
>>> .
>>>
>>
>> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit https://groups.google.com/a/
> apereo.org/d/msgid/cas-user/0a78c6f4-9f32-4456-8adc-
> 9f82ff6d7c56%40apereo.org
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/0a78c6f4-9f32-4456-8adc-9f82ff6d7c56%40apereo.org?utm_medium=email&utm_source=footer>
> .
>

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CA%2Bd9XAO2dS0JZwV-utpNNWi3GkxKvJ2GtBo6WyNUXB0hEwp2rg%40mail.gmail.com.

Reply via email to