delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2015/02/18/06:18:22

X-Recipient: archive-cygwin AT delorie DOT com
DomainKey-Signature: a=rsa-sha1; c=nofws; d=sourceware.org; h=list-id
:list-unsubscribe:list-subscribe:list-archive:list-post
:list-help:sender:date:from:to:cc:subject:message-id:reply-to
:references:mime-version:content-type:in-reply-to; q=dns; s=
default; b=aSzy34ZvgPoT5tb5kpbo+wEZOvpolIQso+8RtSxHAlnkFdltZMX0i
ujSnfktPhYuhJUWoMsLR/vs1J2M+lX52NW/hZhYLorZV3TEc9szmtF881IC7YRQU
X3Ch522RH4zvQRIEtiQ7ikvhV6cB56ekEx7KKxrgjPE7+sMXqDsxGM=
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sourceware.org; h=list-id
:list-unsubscribe:list-subscribe:list-archive:list-post
:list-help:sender:date:from:to:cc:subject:message-id:reply-to
:references:mime-version:content-type:in-reply-to; s=default;
bh=uMFb0qGt5m1S95C+rNROLDblcbw=; b=sMJAOhxK8/ZTXPzDLBYuoYI/xDk1
Y58619lgQQhCATXfO4OE5CNBz5tIeO/B5QDsEPT2V07/uoU0si6jfDK+Ym+C8r1E
PAUeWSORpSblzyDWmETUKv0Xu3WUSCUgouc3V1/JzpmEVhulaWQ4sjs6VvN/6F2T
qHaqGeAUXYnaR2I=
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Authentication-Results: sourceware.org; auth=none
X-Virus-Found: No
X-Spam-SWARE-Status: No, score=-5.9 required=5.0 tests=AWL,BAYES_00 autolearn=ham version=3.3.2
X-HELO: calimero.vinschen.de
Date: Wed, 18 Feb 2015 12:18:02 +0100
From: Corinna Vinschen <corinna-cygwin AT cygwin DOT com>
To: cygwin AT cygwin DOT com
Cc: Roger Orr <rogero AT howzatt DOT demon DOT co DOT uk>
Subject: Re: slow startup after upgrade
Message-ID: <20150218111802.GM8493@calimero.vinschen.de>
Reply-To: cygwin AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com, Roger Orr <rogero AT howzatt DOT demon DOT co DOT uk>
References: <20150216210132 DOT GM8493 AT calimero DOT vinschen DOT de> <7C9A9F7AB74D423499279676D7FA905A AT Tamar> <20150217213255 DOT GC4340 AT calimero DOT vinschen DOT de>
MIME-Version: 1.0
In-Reply-To: <20150217213255.GC4340@calimero.vinschen.de>
User-Agent: Mutt/1.5.23 (2014-03-12)

--W8NyRpvKkamwD9y8
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi Roger,

On Feb 17 22:32, Corinna Vinschen wrote:
> On Feb 17 19:13, Roger Orr wrote:
> > According to nltest /dclist:
> > Our environment has 6 London based DCs=20
> >=20
> > According to ldp.exe Live Enterprise Tree we have a tree structure for =
LDAP.
> >=20
> > 6 leaf nodes at the top matching ther 6 DCs
> > 4 leaf nodes under an "AUS" (Australia) node
> > 3 leaf nodes under a "CHI" (Chicago) node
> > and a few more similar to this in other regions.
> >=20
> > When running mkpasswd I see active sessions to all the nodes in the tre=
e on
> > port 389 (ldap)
> >=20
> > I have tried using Sysinternals ADInsight (with a 32bit cygwin) to see =
what
> > requests are made with 'echo.exe'
> >=20
> > There are two searches shown:
> >=20
> > A) RootDSE:LDAP_SCOPE_BASE:(objectclass=3D*)  (1.113ms)
> > B) <London DNS>:LDAP_SCOPE_SUBTREE:((objectClass=3DtrustedDomain) AND
> > (name=3D<Australian DNS>))     (4.426s)
> >=20
> > I don't know why the second query is being made with the Australian DNS=
 name
> > but I suspect this is the problem.
>=20
> Thanks for doing that!  It's really cool to get this info since it seems
> to point to the culprit.
>=20
> It's not the problem that the Australian DNS is mentioned here.  This is
> perfectly valid.  The LDAP query is going to the London DNS DC
> (apparently, I hope that's right in your case) and the query is for
> information on a trusted domain.  It looks like you have a group from
> the australian domain in your user token.  To compute the gid of the
> group, cygwin asks *your* DC for a value called "posixOffset" for *that*
> trusted domain.
>=20
> The bottom line is, this is not going to Australia, because all DCs have
> this info for their trusted domains in their own DB so it's a planly
> local query.
>=20
> However, that mean this local LDAP query is *extremly* slow.  I changed
> the query now to limit the scope of the database search.  This should spe=
ed
> up the request a lot.
> [...etc...]

I just release a new test release, 1.7.35-0.3, see
https://cygwin.com/ml/cygwin-announce/2015-02/msg00133.html

This should speed up the search for the trustedDomain info a lot.

Can you please give it a try and perform your fantastic timing test as
above?


Thanks in advance,
Corinna

--=20
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Maintainer                 cygwin AT cygwin DOT com
Red Hat

--W8NyRpvKkamwD9y8
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBAgAGBQJU5HTqAAoJEPU2Bp2uRE+gVCgP+wfQYHG7ra0AAPzHimLZb6Q8
ZEBqVGoz3/ZR231OseekFkISJa7GAcDmvCKGRTJVGhQ/Lf+qnd5kIa5e0nK6frZ1
WkJDUw04TwCUU3nCTpK/j7SEQVQ8VmCErZNsj76qrNr5xgM6gZEg7rcgEg1Vvrw4
+0yGztv8FxcYziXJHCoyZs+DvFQMPJmIO2D61gynl1Gl1Q/SysAXOBaNcCSTGcpw
x2db1qOLmghIMiT91sNXSKJNTUzmEgMgEqsoM31e1yCbcu69FgVv4Mgd9TQvTdaK
jh3jNsXtKKJ6g4avSyBS9nP/9EoRItPwYAHl/tzNiWk1mfmG/9x9qzMJVZDsXFPK
MezC49/0Wtt68FwolLt6sAzNRGXBYJKkFfTwQkyS8oDfN4qyxjEj9BnDwgWj+XpV
PFxeFoVbtruOmbm+SzEH9E4PyGRiJ/35HQuhLPc1KuVAgyV7Z4BPSMb7AZr7kyK3
2iYn3HB81Jmfe9gKWfwj0OAtLLDejh7dhNCDDS1qFjeMx3aw6Q8je4MIZLoPw/8t
WYpRvMbVXafYIAWuFVoXIqzivCVywT5+HQmiWXeFEGxhwD9+Oixmk5UcamS5R3js
l1USKGqOpvIKudD3o52R4boYHtlYej2bGfkDwhufu2qCTRvvYji5Q/3niHoBbuj+
cex4+4j4/G9onZebasmH
=A0st
-----END PGP SIGNATURE-----

--W8NyRpvKkamwD9y8--

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019