Re: DOS and LDAP...!!!

Juan Antonio Botia Blaya (juanbot@gaia.fcu.um.es)
Thu, 16 May 1996 14:51:46 +0100

Here is part of your question.

>The ldap server in turn initiates the DSA for searching the Data base.
>However the DSA sends "Time limit exceeded" message.
>
>The exact sequence of messages (as captured by running the ldapd in debug
>mode) is:
> *------------------------------------------------------*
> | initiate_dap_operation | =20
> | operation initiated 0 |
> | DapInitWaitRequest : result 0 type 3 |
> | DI_ERROR |
> | x500err2ldaperr |
> | ***Service error : Time limit exceeded *** |
> *------------------------------------------------------*

As I can see from your loggs the error is generated in your DSA. I suposse=
=20
that you know you can control the time spent for a user query. However Ill=
=20
tell you. You can use the management comand:

/usr/local/bin dsacontrol -tailoring "admintime:xxx"

where xxx are the seconds the DSA will wait before returning this error or=
=20
the response to the query.

Hope this helps.
***************************************
Juan Bot=EDa Blaya=20
Becario de Investigaci=F3n
Sala Iris
Campus de Espinardo
Universidad de Murcia
Tel: 307100-x2035
E-Mail:juanbot@gaia.um.es
***************************************