Keystone: redundant ldap url do not got to fail-over one when firewall silently drops packets
Issue
In kyestone V3, a list of LDAP servers is possible but there isn't a built-in timeout mechanism in Keystone to failover to the next LDAP server in the list if there is no response. For example LDAP server in the list will not respond on 636 i.e. behind a firewall that silently drops packets. Keystone will hang waiting for a connection timeout and eventually keystone authentication will timeout.
Environment
- Red Hat OpenStack,
- Keystone V3
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
