On Mon, 2025-09-15 at 10:21 -0400, Rob Crittenden via FreeIPA-users
wrote:
> I'd suggest you reduce this to a smaller value, say 200, and see how
> that goes. Every API command that does an LDAP search uses this value
> to
> restrict the amount of data returned. The value of 100 was chosen to
> discourage bad practices like in NIS doing things like ypcat passwd |
> grep someuser.
> 
> A value too large could impact overall performance depending on the
> number of users using the WebUI and/or ipa command-line tools.

Our team isn't huge and generally maybe a couple of us are using the
web UI at a time on any given master. I think I'm the only one using
the ipa cli. Still, I heeded your warning and tried out a value of 200.
Thus far it's OK.

I wasn't sure what number I should use. The 1000 I set it to before
seemed questionable. I did see warnings about setting it too large, but
I didn't see anything on what is considered too big or how to size it
properly.

Thanks for the tip.

-- 
Ranbir
-- 
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to