Unable to configure LDAP server or slowness in adding LDAP server on SSP
search cancel

Unable to configure LDAP server or slowness in adding LDAP server on SSP

book

Article ID: 394506

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

  • On the SSP UI when you configure LDAP server configuration, it gets stuck on check status or takes long time to check status.
  • Restore of SSP with LDAP server configured will take long time.

Environment

SSP 5.0

Cause

  • On SSP UI when we try to configure LDAP server configuration at System > User Management > Authentication Provider
  • Once you fill the details and click check status as below, it just spins and gets stuck there.

  • If we add LDAP server(with a 10000+ users) to SSP, the validation step is currently taking more than 10 minutes. Validation includes a check for Base DN. Currently the search scope configuration for this check is set to Subtree, which means server has to go through all entries under the Base DN, which can be time consuming, especially if the directory is large or deeply nested.
  • For LDAP server with a 30000 users, it might take 15-17 minutes. For larger LDAP servers, SSP UI will timeout in 60 minutes and LDAP server is not added eventually.
  • For Restore: The validation step is used as part of restore to bring up LDAP server as well. The above reason applies for this scenario too.

Resolution

This issue is fixed in SSP 5.1

As a temporary workaround, a hotfix image is applied and then reverted. This workaround remains effective as long as there are no changes made to the LDAP server configuration. However, if any LDAP-related changes occur—such as a password update that requires modifying the existing configuration on the SSP side—the workaround will need to be reapplied.

Please contact Broadcom Technical Support for assistance with implementing this workaround.

Additional Information

Note: After applying the new patch some times on "User Role assignment" page we see a warning to set up authentication providers, even though it is configured. The warning goes away on SSP GUI refresh or GUI tab traverse/ change.

Attachments

cluster_api_image.tar get_app
patch-cluster-api.sh get_app