Re: LDAP authentication slow

2018-06-03 Thread Tim Cross
Jeff Janes writes: > On Thu, May 31, 2018 at 8:23 AM, C GG wrote: > > In the meantime, I did what I promised Adrian Klaver I would do and I added >> the AD servers to the /etc/hosts file. That had an immediate and dramatic >> effect on the performance. That confirms (at least to me) that DNS >

Re: LDAP authentication slow

2018-06-03 Thread Jeff Janes
On Thu, May 31, 2018 at 8:23 AM, C GG wrote: In the meantime, I did what I promised Adrian Klaver I would do and I added > the AD servers to the /etc/hosts file. That had an immediate and dramatic > effect on the performance. That confirms (at least to me) that DNS > resolution was playing a larg

Re: LDAP authentication slow

2018-05-31 Thread C GG
On Wed, May 30, 2018 at 6:31 PM, Tim Cross wrote: > > C GG writes: > > > On Wed, May 30, 2018 at 2:50 PM, Stephen Frost > wrote: > > > >> Greetings, > >> > >> * C GG (cgg0...@gmail.com) wrote: > >> > On Wed, May 30, 2018 at 12:04 PM, Stephen Frost > >> wrote: > >> > > What's the reason for wis

Re: LDAP authentication slow

2018-05-30 Thread Tim Cross
C GG writes: > On Wed, May 30, 2018 at 2:50 PM, Stephen Frost wrote: > >> Greetings, >> >> * C GG (cgg0...@gmail.com) wrote: >> > On Wed, May 30, 2018 at 12:04 PM, Stephen Frost >> wrote: >> > > What's the reason for wishing for them to "be able to type in a >> > > password"? With GSSAPI/Ker

Re: LDAP authentication slow

2018-05-30 Thread C GG
On Wed, May 30, 2018 at 5:43 PM, Adrian Klaver wrote: > On 05/30/2018 01:41 PM, C GG wrote: > >> >> >> > Please let me be clear, this is not a question about whether or not to use >> passwords. This is a question of how to determine the cause of and remedy a >> slowdown retrieving data from Postg

Re: LDAP authentication slow

2018-05-30 Thread Adrian Klaver
On 05/30/2018 01:41 PM, C GG wrote: Please let me be clear, this is not a question about whether or not to use passwords. This is a question of how to determine the cause of and remedy a slowdown retrieving data from PostgreSQL when using LDAP(S) to authenticate PostgreSQL users. One of th

Re: LDAP authentication slow

2018-05-30 Thread C GG
On Wed, May 30, 2018 at 2:50 PM, Stephen Frost wrote: > Greetings, > > * C GG (cgg0...@gmail.com) wrote: > > On Wed, May 30, 2018 at 12:04 PM, Stephen Frost > wrote: > > > What's the reason for wishing for them to "be able to type in a > > > password"? With GSSAPI/Kerberos, users get true singl

Re: LDAP authentication slow

2018-05-30 Thread Stephen Frost
Greetings, * C GG (cgg0...@gmail.com) wrote: > On Wed, May 30, 2018 at 12:04 PM, Stephen Frost wrote: > > What's the reason for wishing for them to "be able to type in a > > password"? With GSSAPI/Kerberos, users get true single-sign-on, so they > > would log into the Windows system with a passw

Re: LDAP authentication slow

2018-05-30 Thread C GG
On Wed, May 30, 2018 at 12:04 PM, Stephen Frost wrote: > Greetings, > > * C GG (cgg0...@gmail.com) wrote: > > This is PostgreSQL 9.5 -- We just enabled LDAP(S) authentication (to an > > Active Directory server) for a certain grouping of users > > You really shouldn't be using LDAP auth to an Acti

Re: LDAP authentication slow

2018-05-30 Thread Stephen Frost
Greetings, * C GG (cgg0...@gmail.com) wrote: > This is PostgreSQL 9.5 -- We just enabled LDAP(S) authentication (to an > Active Directory server) for a certain grouping of users You really shouldn't be using LDAP auth to an Active Directory system. Active Directory supports Kerberos, which is a m