Resolving Performance Slowness in Single Identity Manager Environment - Identity Manager
search cancel

Resolving Performance Slowness in Single Identity Manager Environment - Identity Manager

book

Article ID: 216628

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This article addresses performance slowness in the TEWS and User Console occurring within a single Identity Manager Environment (IME).

Environment

Identity Manager 14.5

Cause

Performance degradation in a single IME is often caused by enabled AD referrals within the SSO or LDAP configuration. When LDAP queries reach the AD user store, enabled referrals cause significant response delays (20-30 seconds) despite the query processing quickly on the AD server side.

Resolution

To resolve performance issues caused by AD referral settings, perform the following configuration adjustments:

  1. Disable AD Referrals in Policy Server: Update the Policy Server registry entry to disable referrals: EnableReferrals = 0

  2. Update Directory Configuration: Modify the directory.xml file on the Identity Manager side to ignore referrals and apply the necessary tuning values:

    • Locate the directory configuration element.
    • Add the ignore parameter to the relevant referral configuration.
    • Ensure tuning values (e.g., connection pools and timeout settings) are set according to your specific environment requirements.
  3. Restart Service: Restart the Identity Manager Environment (IME) to apply the new registry and configuration changes.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.