Bug 1631005 - When User Group sync is enabled, customer wait long time to authenticate / login
Summary: When User Group sync is enabled, customer wait long time to authenticate / login
Product: Red Hat Satellite
Component: Authentication
Version: 6.3.2
Target Milestone: 6.6.0
Assignee: Ondřej Ezr
QA Contact: Nikhil Kathole
Reported: 2018-09-19 17:03 UTC by Waldirio M Pinheiro
Modified: 2023-03-24 14:14 UTC (History)
7 users (show)

Fixed In Version: foreman-1.22.0-0
Last Closed: 2019-10-22 19:50:21 UTC
System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 25795 0 Normal Closed LDAP - When User Group sync is enabled, user wait long time to authenticate / login 2020-06-11 17:20:04 UTC

Description Waldirio M Pinheiro 2018-09-19 17:03:05 UTC
Description of problem:
Currently, there is a feature called User Group sync, so when enabled, Satellite will bind the external Auth Source and will try to match the user on User Group already defined on the Sat side. If match, the system will assign automatically the role related and on the fly / first login, the login page will be according to the roles.

This feature works fine when the account is member of few groups, but when we are talking about a huge number of groups *this happens all the time* the login process can spend a long time to conclude.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Configure the LDAP Auth
2. Create the user on AD
3. Create a bunch of groups on AD *like 100*
4. Add the user on all groups
5. Login on the Satellite via webUI with the User Group Sync enabled

Actual results:
Spend a long time to conclude the process/check and login.

Expected results:
Be faster then today.

Additional info:

Comment 9 Bryan Kearney 2019-04-08 14:01:49 UTC
Upstream bug assigned to oezr

Comment 10 Bryan Kearney 2019-04-08 14:01:50 UTC
Moving this bug to POST for triage into Satellite 6 since the upstream issue has been resolved.

Comment 13 Sanket Jagtap 2019-08-09 15:06:06 UTC
Build: Satellite 6.6 snap15

AD usern and Time from raw ldapsearch for use in 900 groups

New login from AD user to Satellite:

Repeated this couple of times, the time taken is around 6 seconds

I think this is considerable improvement from 23 secs

Comment 14 Waldirio M Pinheiro 2019-08-12 13:26:51 UTC

For sure it's :)

Thank you.

Best Regards
Waldirio M Pinheiro | Senior Software Maintenance Engineer

Comment 15 Bryan Kearney 2019-10-22 19:50:21 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

