--On Friday, March 08, 2013 9:41 AM -0800 Quanah Gibson-Mount <qua...@zimbra.com> wrote:

--On Friday, March 08, 2013 5:29 PM +0000 Viktor Dukhovni
<postfix-us...@dukhovni.org> wrote:

The effect of the "proxy:" prefix is to reduce the number of
processes that make LDAP connections, by pooling all the connections
via a small number of proxy processes.

On a sufficiently idle system (say a test system which only receives
intermittent email messages) the processes that are connected to LDAP
may exit when idle for long enough, and then new connections will be
made later.  The same happens on systems where some misguidedly runs
"postfix reload" frequently.

This is not really the behavior I see from proxy:.  For example, the
connection I pasted from this morning:

Mar  8 08:12:27 ldap01-zcs slapd[7644]: conn=29791 op=7801 SRCH
attr=zimbraMailCanonicalAddress zimbraMailCatchAllCanonicalAddress
Mar  8 08:12:27 ldap01-zcs slapd[7644]: conn=29791 op=7801 SEARCH RESULT
tag=101 err=0 nentries=0 text=
Mar  8 08:12:32 ldap01-zcs slapd[7644]: conn=29791 fd=84 closed
(connection lost)


You can see that postfix closed the connection (without sending an
unbind) 5 seconds after operation 7801.  Postfix has established 258
connections since 4 am this morning, all of which it initiates a close on
after some amount of time (i.e., the LDAP server is not the one closing
the connection).

Vs, for example, our OpenDKIM setup, which has used a persistent connection to our ldap server for a few days, and is now on op=137251.

--Quanah

--

Quanah Gibson-Mount
Sr. Member of Technical Staff
Zimbra, Inc
A Division of VMware, Inc.
--------------------
Zimbra ::  the leader in open source messaging and collaboration

Reply via email to