LDAP Errors: Size Limit Exceeded or Time Limit Exceeded
PrivX displays the following status for an LDAP directory:
Error / LDAP Result Code 4 "Size Limit Exceeded"
Also PrivX logs contain entries similar to the following:
20xx/xx/xx xx:xx:xx [WARNING] Query '(objectclass=inetOrgPerson)' error: 'LDAP Result Code 4 "Size Limit Exceeded": '
20xx/xx/xx xx:xx:xx [ERROR] source 5b938e7a-398c-5628-7a39-7535417fe7d9: scanning failed, retrying: LDAP Result Code 4 "Size Limit Exceeded":
Alternatively, the directory status and log entries contain Time Limit Exceeded instead of Size Limit Exceeded.
Both symptoms indicate that PrivX queries exceed the target directory's administrative limits: the LDAP client query may contain more entries than allowed by the target directory, or it may be taking longer than allowed by the target directory.
Potential Solutions
LDAP queries from PrivX are always paginated. You can set the maximum page size in the PrivX Web UI Administration → Settings → Role Store, using the LDAP Query Pagination Size option. For queries to succeed, this value should typically be below your LDAP directory's hard size limit.
Alternatively, set the target directory's client limits:
- In the PrivX Web UI Administration → Directories, select Edit for the target directory.
- Configure the following fields:
- Query Size Limit: set a number greater than the number of PrivX users coming from this directory.
- Query Time Limit: set a duration long enough for PrivX to complete queries to the directory.
- Save your changes, then select Refresh for the directory and verify that the error no longer occurs.
If the error persists, increase the corresponding hard limits of the target directory. Ensure that the hard limits are greater than the limits required by PrivX. Consult your LDAP vendor's documentation for more information about setting query limits.
LDAP Administrative-Limits Behavior
LDAP administrative limits typically work as follows:
- If PrivX does not specify client limits, the LDAP server applies its soft limits.
- When PrivX specifies client limits, the LDAP server applies its hard limits.