Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: OD master LDAP instability



As far as I have been informed (please correct me if I'm wrong) but there is an issue with the version of OpenLDAP that Apple ships in the server software...They use 2.1 which is allegedly buggy compared to 2.2 which is the accepted stable series..

I had an issue with an OD master which kept crashing out, I had around 150 10.3 Macs, and somewhere in the region of 350 Red Hat clients authenticating off it

So we moved on to plan v2.0, we created an OD replica for the RedHat boys incase it was being caused by network issues between buildings on campus.. The same thing happened to the OD replica, CPU use went through the roof and the machine would hang.. The cause seemed to tie in when users first logged in a lecture and there was a large amounts of passwords being change.

We ended up ditching the RH boxes authenticating off the server and et voila the CPU issues ceased..

Does anyone else have similar experiences?


On 31 Jan 2005, at 10:20, Matt Jenns wrote:

Hi all,

Have a customer with around 300+ 10.3.7 clients connected to an OD. I set it up three weeks ago and they've been slowly adding machines into the system. The master (dual G4 Xserve, 10.3.7) has in the last week had a series of slapd crashes (two or three a day, seemingly load related). The log shows that the crashed thread seems to have something to do with password server eg:

Thread 3 Crashed:
0 <<00000000>> 0xffff8acc __memcpy + 0x32c
1 libpscrammd5.2.so 0x001c2d54 cr_getsecret + 0x80
2 libsasl2.2.0.1.dylib 0x9450db5c _plug_get_password + 0x138
3 libpscrammd5.2.so 0x001c4f88 crammd5_server_plug_init + 0x318
4 libsasl2.2.0.1.dylib 0x94507b80 sasl_client_step + 0xf8
5 libpscrammd5.2.so 0x001c39b0 DoSASLAuth + 0x1fc
6 libpscrammd5.2.so 0x001c41a0 DoPSCRAMMD5Auth + 0x298
7 libpscrammd5.2.so 0x001c48a4 DoPSCRAMMD5Auth + 0x99c
8 libsasl2.2.0.1.dylib 0x945034f8 sasl_server_step + 0x100



I'm hoping it's just a load issue, but the two main AFP servers (dual G5 Xserves, 10.3.7) are both OD replicas, yet hardly any client ever seems to use them. If i look at all three boxes' LDAP connections right now, for example, i get this:


[master:~] root# lsof -i | grep slapd | wc -l
      139
[bdata:~] root# lsof -i | grep slapd | wc -l
       3
[adata:~] root# lsof -i | grep slapd | wc -l
       7

Not great.

In the absence of any better ideas, i'm adding a StartupItem that will randomly pick an ldap server, use ipfw to block the other two, restart DirectoryService, and then flush ipfw again. What sort of load are others seeing on their LDAP boxes? Is it worth adding an idle timeout to slapd.conf?

thanks in advance

matt jenns

_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/ email@hidden


This email sent to email@hidden

Richard Pride

Senior IT Technician - Mac Support, Video Post and New Media.
Bournemouth Media School.

Apple Centre of Excellence

Tel : (01202) 595040

 "So we went to Atari and said, 'Hey, we've got this
  amazing thing, even built with some of your parts,
  and what do you think about funding us?  Or we'll
  give it to you.  We just want to do it.  Pay our
  salary, we'll come work for you.'  And they said,
  'No.'  So then we went to Hewlett-Packard, and they
  said, 'Hey, we don't need you.  You haven't got
  through college yet.'"
  --Apple Computer Inc. founder Steve Jobs on attempts
    to get Atari and H-P interested in his and Steve
    Wozniak's personal computer.

The day Microsoft make something that doesn't suck will be the day they start making vacuum cleaners
This e-mail is intended only for the person to whom it is addressed and may contain confidential information. If you have received this e-mail in error, please notify the sender and delete this e-mail, which must not be copied, distributed or disclosed to any other person.
Any views or opinions presented are solely those of the author and do not necessarily represent those of Bournemouth University. Nor can any contract be formed on the University's behalf via e-mail.
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/email@hidden


This email sent to email@hidden
References: 
 >OD master LDAP instability (From: Matt Jenns <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.