Bug 2142639
Summary: | pam mutex lock causing high etimes, affecting red hat internal sso | ||
---|---|---|---|
Product: | Red Hat Directory Server | Reporter: | thierry bordaz <tbordaz> |
Component: | 389-ds-base | Assignee: | thierry bordaz <tbordaz> |
Status: | CLOSED ERRATA | QA Contact: | LDAP QA Team <idm-ds-qe-bugs> |
Severity: | high | Docs Contact: | Mugdha Soni <musoni> |
Priority: | high | ||
Version: | 12.2 | CC: | atikhono, bsmejkal, emartyny, idm-ds-dev-bugs, mreynolds, musoni, pasik, pbrezina, pcech, striker, tbordaz |
Target Milestone: | DS12.2 | Keywords: | Triaged |
Target Release: | dirsrv-12.2 | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | sync-to-jira | ||
Fixed In Version: | redhat-ds-12-9020020221130212339.1674d57 | Doc Type: | Enhancement |
Doc Text: |
.New `pamModuleIsThreadSafe` configuration option is now available
When a PAM module is thread-safe, you can improve the PAM authentication throughput and response time of that specific module, by setting the new `pamModuleIsThreadSafe` configuration option to `yes`:
----
pamModuleIsThreadSafe: yes
----
This configuration applies on the PAM module configuration entry (child of `cn=PAM Pass Through Auth,cn=plugins,cn=config`).
Use `pamModuleIsThreadSafe` option in the `dse.ldif` configuration file or the `ldapmodify` command. Note that the `ldapmodify` command requires you to restart the server.
|
Story Points: | --- |
Clone Of: | 2075858 | Environment: | |
Last Closed: | 2023-05-30 09:40:35 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2075858 | ||
Bug Blocks: | 2142636, 2142638, 2177232, 2177233, 2177234 |
Comment 3
thierry bordaz
2022-11-15 09:29:02 UTC
Developer Sanity Test Internal repo for RHDS 12.2 shows code is present: $ git checkout Directory_Server_12_2_0 Switched to branch 'Directory_Server_12_2_0' $ grep -r pamModuleIsThreadSafe * ldap/servers/plugins/pam_passthru/pam_passthru.h:#define PAMPT_THREAD_SAFE_ATTR "pamModuleIsThreadSafe" /* single */ As per comment #c6 marking as VERIFIED. Hi Thierry! I agree with you. For now we will create a RN text for DS 12.2. Thanks, Evgenia Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (redhat-ds:12 bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:3344 |