LDAP Connection Pool
The plugin makes use of the UnboundID LDAP SDK.
Note: If several plugins share the same main connection settings (server addresses with ports, bind DN, SSL settings) they also share one single connection pool.
Connection Pooling
This plugin manages a pool of open connections to the LDAP server. To perform an operation a connection is checked out of the pool, then used for the operation and afterward checked into the pool of available connections again.
There are several configuration properties that influence how these connections are managed and how connection errors are handled.
To debug the LDAP connections set the following Java system properties:
- com.unboundid.ldap.sdk.debug.enabled=true - If set to true, LDAP debugging is enabled.
- com.unboundid.ldap.sdk.debug.type=asn1,connect,exception,ldap,ldif,monitor,coding-error,other - If set, only the given categories will be logged.
- com.unboundid.ldap.sdk.debug.includeStackTrace=true - If set to true, a stack trace will be included with every log message.
- com.unboundid.ldap.sdk.debug.level=ALL - If set, only messages with a level higher than specified (like ALL, FINE, INFO, WARNING, ...) will be written.
- javax.net.debug=all - Set this property to diagnose SSL related issues.
serversWithPorts) server-name:port . If no port number is specified, the default port 389 (or 636 if using SSL) is assumed. serverSelectionPolicy) - FAILOVER: Always try to get a connection from the first server, if that fails from the second, etc...
- ROUND_ROBIN: Cycle through the configured servers to get connections.
bindDn) password) anonymousBind) connectionSecurity) The type of connection security, one of NONE, START_TLS or SSL.
Notice: Most directories will refuse to perform a password change operation if the connection is not secured using SSL/TLS.
Notice: Microsoft disabled support for Server certificates using MD5 with KB2862973 (mandatory update in early 2014). Using any server certificate with an MD5 signature in its entire chain will result in a connection error. The same error will be raised when using a certificate using SHA-512 without having KB2973337 installed.
keystoreFile) Note: If the keystore file name is relative, it is loaded relative to the current directory of the JVM process.
keystorePassword) keyAlias) checkCertificateServerName) checkCertificateValidity) trustAllServerCertificates) truststoreFile) Note: If the file name is relative, it is loaded relative to the current directory of the JVM process.
truststorePassword) useSynchronousMode) followReferrals) connectTimeoutInMs) responseTimeoutInMs) This timeout may be reached if the connection has been dropped by a firewall without actively terminating the connection or when a query requires a lot of time on the server.
initialConnections) maximumConnections) createNewConnectionsIfNecessary) maxWaitTimeInMs) maxConnectionAgeInMs) trySynchronousReadDuringHealthCheck) healthCheckResponseTimeoutInMs) retryUponInvalidConnectionError) enableHealthCheckOnCheckout) enableHealthCheckInBackground) enableHealthCheckOnException) enableHealthCheckOnCreate) enableHealthCheckOnRelease) backgroundHealthCheckIntervalInMs) healthCheckQueryDn) useSchema)
type: LdapConnectionPool
id: LdapConnectionPool-xxxxxx
displayName:
comment:
properties:
anonymousBind: false
backgroundHealthCheckIntervalInMs: 60000
bindDn:
checkCertificateServerName: true
checkCertificateValidity: true
connectTimeoutInMs: 2000
connectionSecurity: NONE
createNewConnectionsIfNecessary: false
enableHealthCheckInBackground: true
enableHealthCheckOnCheckout: true
enableHealthCheckOnCreate: false
enableHealthCheckOnException: false
enableHealthCheckOnRelease: false
followReferrals: false
healthCheckQueryDn:
healthCheckResponseTimeoutInMs: 30000
initialConnections: 10
keyAlias:
keystoreFile:
keystorePassword:
maxConnectionAgeInMs: 3600000
maxWaitTimeInMs: 5000
maximumConnections: 100
password:
responseTimeoutInMs: 20000
retryUponInvalidConnectionError: true
serverSelectionPolicy: FAILOVER
serversWithPorts:
trustAllServerCertificates: false
truststoreFile:
truststorePassword:
trySynchronousReadDuringHealthCheck: false
useSchema: false
useSynchronousMode: true