#1581 When ldap server is not reachable the Directory Authenticated profile requests from CA EE page hangs.
Closed: migrated by dmoluguw. Opened by aakkiang.

When ldap server is not reachable (behind the firewall or ldap port is
forbidden access) the Directory Authenticated profile requests from CA EE page
hangs.

Steps to Reproduce:

1. set-up a TLS enabled ldap on host1. Create user testuser.
uid=testuser,ou=People,dc=pki-ldap-test1
2. Set-up CS subsystems on host2.
3. Goto the ca's admin console. goto the configuration/authentication tab.
4. Select add and add 'uidpwddirauth' and fill in the reqd fields
        dnpattern: UID=$attr.uid, OU=$dn.ou,
        ldap host: host1
        ldap port: someport [ make sure you specify the LDAPS port ].
        ldapStringAttrs: mail
        ldapbasedn: dc=pki-test-ldap2
5.Then goto the ca's eeSSL page and select the profile 'caDirUserCert' for
enrollment.
        fill in the user id and password and click submit.
            userid = testuser
            password = netscape
        { make sure this user exists in the directory server }
6. Enrollment should succeed.
7. Now forbidden the ldap port on host1
iptables -A INPUT -p tcp --dport <ssl-port> -j REJECT
8. Then goto the ca's eeSSL page and select the profile 'caDirUserCert' for
enrollment.
        fill in the user id and password and click submit.
            userid = testuser
            password = netscape

Actual results:

You can see the spinning icon. UI hangs.
Same problem observed when host1 has firewall turned on.

Expected results:

Enrollment should fail with message 'Authentication Error'.

Additional info:

No log messages found on ldap logs as expected.
CA's debug log has this:
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet:service() uri =
/ca/ee/ca/profileSubmit
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param
name='uid' value='testuser'
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param
name='pwd' value='(sensitive)'
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param
name='cert_request_type' value='keygen'
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param
name='cert_request'
value='MIICQDCCASgwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCkrWIo5Yve
jDZFBs5iddrIYglvM0Ze0atuElwCN7259ezByZV1zh32r2jfYYhCtqorrIC7zDbq
KBRbSl4FJ7TA6vA/gP9H7ktLSmF0CeejTUUE0oRj1x0kwoZpBxzUNH9nbt2ImTZR
MCtHy/66BfwG2uxfnUU6vSaf7FI450XZp5TQPQoracPYJwYZbS7dMwZYQAxGpB/j
hs0CUzWfDqWRTzQVETo5sHNzF4Lg/o3ZEM90P+dkHSfkzgoM9tSz/p/i8/xnD5r7
n/2FkoKvxie+JAMFwpxcI5YIzunhBtKY+0H3dAas/4d/CqcMi288kMpnWw6MoKty
f3uejFjw2JAzAgMBAAEWADANBgkqhkiG9w0BAQQFAAOCAQEAcRYlpx9V+iG3UPbR
ngavJAL5+dMRA9KVo8iphA/EhO7uONwrNP2KjmlIUpgfkbDRV321tMtsQZy4DiBI
P6dpf6QYErQyHPJcuYedhN5zAQFkns8198e7EK9OULFHpqdUJ6Wx+RaMkkYN3fEk
k9WDCDfAjn4I12+dg6Qfjb++0B5TNBVP2ifV33GXL14cms6ufGeMLT0rQNYivb5x
UxPsGoMLvQRVu2V6zhN9Be2EdWZr259Rp9MhpMco0tyT6Xg72weF8pBQbCx2Oo7s
8ZjWW4J4B46QGDyK2zuCJ6cBOr4GdURQA/OMFDM62I7kOzByZEoo8lCvW1e5Ruo6
30bSBQ=='
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param
name='selectKeyType' value='RSA'
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param
name='profileId' value='caDirUserCert'
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param
name='renewal' value='false'
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet::service() param
name='xmlOutput' value='false'
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet: caProfileSubmit
start to service.
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: xmlOutput false
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: ProfileSubmitServlet: isRenewal
false
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: according to ccMode,
authorization for servlet: caProfileSubmit is LDAP based, not XML {1}, use
default authz mgr: {2}.
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: Input Parameters:
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - profileId:
caDirUserCert
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: -
cert_request_type: keygen
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - isRenewal: false
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - cert_request:
MIICQDCCASgwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCkrWIo5Yve
jDZFBs5iddrIYglvM0Ze0atuElwCN7259ezByZV1zh32r2jfYYhCtqorrIC7zDbq
KBRbSl4FJ7TA6vA/gP9H7ktLSmF0CeejTUUE0oRj1x0kwoZpBxzUNH9nbt2ImTZR
MCtHy/66BfwG2uxfnUU6vSaf7FI450XZp5TQPQoracPYJwYZbS7dMwZYQAxGpB/j
hs0CUzWfDqWRTzQVETo5sHNzF4Lg/o3ZEM90P+dkHSfkzgoM9tSz/p/i8/xnD5r7
n/2FkoKvxie+JAMFwpxcI5YIzunhBtKY+0H3dAas/4d/CqcMi288kMpnWw6MoKty
f3uejFjw2JAzAgMBAAEWADANBgkqhkiG9w0BAQQFAAOCAQEAcRYlpx9V+iG3UPbR
ngavJAL5+dMRA9KVo8iphA/EhO7uONwrNP2KjmlIUpgfkbDRV321tMtsQZy4DiBI
P6dpf6QYErQyHPJcuYedhN5zAQFkns8198e7EK9OULFHpqdUJ6Wx+RaMkkYN3fEk
k9WDCDfAjn4I12+dg6Qfjb++0B5TNBVP2ifV33GXL14cms6ufGeMLT0rQNYivb5x
UxPsGoMLvQRVu2V6zhN9Be2EdWZr259Rp9MhpMco0tyT6Xg72weF8pBQbCx2Oo7s
8ZjWW4J4B46QGDyK2zuCJ6cBOr4GdURQA/OMFDM62I7kOzByZEoo8lCvW1e5Ruo6
30bSBQ==
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - remoteAddr:
10.8.0.85
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CAProcessor: - remoteHost:
10.8.0.85
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: isRenewal
false
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: profileId
caDirUserCert
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: set Inputs
into profile Context
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor:
authenticator UserDirEnrollment found
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]:
CertRequestSubmitter:setCredentialsIntoContext() authNames not null
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]:
CertRequestSubmitter:setCredentialsIntoContext() authName:uid
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]:
CertRequestSubmitter:setCredentialsIntoContext() authName found in request
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]:
CertRequestSubmitter:setCredentialsIntoContext() authName:pwd
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]:
CertRequestSubmitter:setCredentialsIntoContext() authName found in request
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: EnrollmentProcessor: set
sslClientCertProvider
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: authenticate: authentication
required.
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet: in auditSubjectID
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet: auditSubjectID
auditContext {sslClientCertProvider=com.netscape.cms.servlet.profile.SSLClientC
ertProvider@eaf3bef,
profileContext=com.netscape.cms.profile.common.ProfileContext@1287cf71}
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: CMSServlet auditSubjectID:
subjectID: null
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: DirBasedAuthentication:
authenticate: begins...mBoundConnEnable=false
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: DirBasedAuthentication:
authenticate: mConnFactory class name =
com.netscape.cmscore.ldapconn.LdapAnonConnFactory
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: DirBasedAuthentication:
authenticate: mConnFactory not null, calling getConn
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: LdapAnonConnFactory::getConn
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: LdapAnonConnFactory.getConn():
num avail conns now 0
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: DirBasedAuthentication:
authenticate: before authenticate() call
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: Authenticating UID=testuser
[20/Aug/2015:14:08:34][http-bio-30042-exec-17]: UidPwdDirAuthentication:
Authenticating: Searching for uid=testuser base DN=dc=pki-test-ldap2

Per CS/DS Meeting of 08/24/2015: 10.3, low priority

  • corner case
  • not a blocker
  • use a load balancer and replication

Per Bug Triage of 05/05/2016: 10.4

Metadata Update from @aakkiang:
- Issue set to the milestone: UNTRIAGED

Metadata Update from @mharmsen:
- Custom field feature adjusted to None
- Custom field proposedmilestone adjusted to None
- Custom field proposedpriority adjusted to None
- Custom field reviewer adjusted to None
- Custom field version adjusted to None
- Issue close_status updated to: None
- Issue set to the milestone: FUTURE (was: UNTRIAGED)

Per 10.5.x/10.6 Triage: FUTURE

mharmsen: sounds more irritating than anything else, although a proper error should be returned if possible

Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new
issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.

This issue has been cloned to GitHub and is available here:
https://github.com/dogtagpki/pki/issues/2140

If you want to receive further updates on the issue, please navigate to the
GitHub issue and click on Subscribe button.

Thank you for understanding, and we apologize for any inconvenience.

Metadata Update from @dmoluguw:
- Issue close_status updated to: migrated
- Issue status updated to: Closed (was: Open)

Metadata