[Geoserver-devel] [JIRA] (GEOS-8686) Problem with GeoFence roles checking

Julien SABATIER created an issue

GeoServer / BugGEOS-8686

Problem with GeoFence roles checking

Issue Type:

BugBug

Affects Versions:

2.12.1

Assignee:

Unassigned

Attachments:

geoserver.getcap.log

Components:

GeoFence

Created:

16/Apr/18 12:10 PM

Environment:

Debian 9, Oracle JAVA 8
External OpenLDAP server configured as User, groups and roles service.
17 workspaces, 218 layers, 54 geofence’s rules
On LDAP : 836 users and 124 roles

Priority:

HighHigh

Reporter:

Julien SABATIER

When request a GetCapabilities with a user who have different roles (tested with 3, not admin) on the main wfs/wms URL (/geoserver/wfs), It took a very long time to generate the response (~10minutes).

If I set VERBOSE_MODE, I see in the log that for a single user, GeoFence seems to request LDAP for user and user’s role a huge amount of time (cf attached file).

With tcpdump, I see a huge traffic on port 636 (ldaps) when requesting getcap document.

I think there is a huge problem with GeoFence access right checking as it took 10 minutes for a simple GetCapabilities.

Add Comment

Add Comment

Get Jira notifications on your phone! Download the Jira Cloud app for Android or iOS


This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100082-sha1:c5202d1)

Atlassian logo