FYI

*** Finished

verify_data:  { 211, 149, 17, 160, 89, 28, 181, 252, 91, 11, 70, 209 }

***

%% Cached client session: [Session-3, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA]

TP-Processor2, setSoTimeout(0) called

TP-Processor2, WRITE: TLSv1 Application Data, length = 128

Thread-11, READ: TLSv1 Application Data, length = 48

TP-Processor2, WRITE: TLSv1 Application Data, length = 32

TP-Processor2, WRITE: TLSv1 Application Data, length = 128

TP-Processor2, WRITE: TLSv1 Application Data, length = 32

TP-Processor2, WRITE: TLSv1 Application Data, length = 32

TP-Processor2, WRITE: TLSv1 Application Data, length = 32

TP-Processor2, WRITE: TLSv1 Application Data, length = 64

TP-Processor2, called close()

TP-Processor2, called closeInternal(true)

TP-Processor2, SEND TLSv1 ALERT:  warning, description = close_notify

TP-Processor2, WRITE: TLSv1 Alert, length = 32

TP-Processor2, called closeSocket(true)

Thread-11, handling exception: java.net.SocketException: Socket closed

%% Invalidated:  [Session-3, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA]

Thread-11, called closeSocket()

2017-01-07 18:07:50,916 INFO 
[com.github.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit 
trail record BEGIN

=============================================================

WHO: [username: delaitt]

WHAT: supplied credentials: [username: delaitt]

ACTION: AUTHENTICATION_FAILED

APPLICATION: CAS

WHEN: Sat Jan 07 18:07:50 GMT 2017


From: Thierry Delaitre 
<[email protected]<mailto:[email protected]>>
Date: Saturday, 7 January 2017 at 17:29
To: CAS Community <[email protected]<mailto:[email protected]>>
Subject: LDAP response read timed

Hello

I’ve got a CAS server that works fine when connecting to eDirectory.

I’ve changed it to connect to Active Directory but I get the below. The strange 
thing is that half of CAS says that the user has been authenticated while the 
second half of the log says there is a timeout. The JVM does have the ca certs 
for the LDAP servers and an ldapsearch query to AD works fine so it should not 
be a firewall problem.

Is there some hint to debug this?

Thanks

Thierry


2017-01-06 17:24:08,867 INFO [org.jasig.cas.web.flow.InitialFlowSetupAction] - 
<Setting path for cookies to: />

2017-01-06 17:24:17,186 INFO 
[org.jasig.cas.authentication.AuthenticationManagerImpl] - 
<org.jasig.cas.adaptors.ldap.BindLdapAuthenticationHandler successfully 
authenticated [username: delaitt]>

2017-01-06 17:24:19,590 INFO 
[com.github.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit 
trail record BEGIN

=============================================================

WHO: [username: delaitt]

WHAT: supplied credentials: [username: delaitt]

ACTION: AUTHENTICATION_FAILED

APPLICATION: CAS

WHEN: Fri Jan 06 17:24:19 GMT 2017

CLIENT IP ADDRESS: XX

SERVER IP ADDRESS: XX

=============================================================


>

2017-01-06 17:24:19,592 INFO 
[com.github.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit 
trail record BEGIN

=============================================================

WHO: [username: delaitt]

WHAT: Uncategorized exception occured during LDAP processing; nested exception 
is javax.naming.NamingException: LDAP response read timed out, timeout 
used:2000ms.; remaining name ‘OU=XX'

ACTION: TICKET_GRANTING_TICKET_NOT_CREATED

APPLICATION: CAS

WHEN: Fri Jan 06 17:24:19 GMT 2017

CLIENT IP ADDRESS: XX

SERVER IP ADDRESS: XX

=============================================================


The University of Westminster is a charity and a company limited by guarantee. 
Registration number: 977818 England. Registered Office: 309 Regent Street, 
London W1B 2UW.

This message and its attachments are private and confidential. If you have 
received this message in error, please notify the sender and remove it and its 
attachments from your system.

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/C6393E20-9B52-41CA-8761-E6414BDFB591%40westminster.ac.uk.

Reply via email to