Thanks for the quick reply! We have indeed the timelimit option set low. Just didn't check all changelog files of the lastest version. Sorry for the noise.
Durk Strooisma Scrum Master, Senior Unix/Linux System Engineer Tele2 / IT Infrastructure / Unix (formerly Datacenter) Tel. +31 (0) 20 750 1471 Cel. +31 (0) 6 2128 2452 From: Arthur de Jong <[email protected]> To: Durk Strooisma <[email protected]>, [email protected], Date: 2013-01-10 22:28 Subject: Re: Bug#697851: nslcd: idle_timelimit is only checked at a new request, which may cause undesired delays Version: 0.8.0 On Thu, 2013-01-10 at 13:20 +0100, Durk Strooisma wrote: > It seems that the idle_timelimit setting is only checked at a new > request. [snip] This is correct for the 0.7 series, in the 0.8 this is fixed. > In this case the process of cleaning up the connection takes longer, > because it doesn't get a response from the LDAP server, as the > firewall doesn't have an open session anymore. You should be able to use the timelimit option to make the delay for timeouts shorter as a workaround. For disconnecting half the timelimit value is set to ensure faster shutdown of the connection to the LDAP server. > Not an easy or nice fix would be to have a thread running all the time > that checks all connections for idle_timelimit and cleans them up if > needed. In 0.8.0 the worker threads wake up every idle_timelimit seconds to check if an LDAP connection needs to be closed. Thanks, -- -- arthur - [email protected] - http://people.debian.org/~adejong -- [attachment "signature.asc" deleted by Durk Strooisma/NL/Tele2] ******** IMPORTANT NOTICE ******** This e-mail (including any attachments) may contain information that is confidential or otherwise protected from disclosure and it is intended only for the addressees. If you are not the intended recipient, please note that any copying, distribution or other use of information contained in this e-mail (and its attachments) is not allowed. If you have received this e-mail in error, kindly notify us immediately by telephone or e-mail and delete the message (including any attachments) from your system. Please note that e-mail messages may contain computer viruses or other defects, may not be accurately replicated on other systems, or may be subject of unauthorized interception or other interference without the knowledge of sender or recipient. Tele2 only send and receive e-mails on the basis that Tele2 is not responsible for any such computer viruses, corruption or other interference or any consequences thereof.

