From 90788a25d6d54b084541336a83946d37a73076ef Mon Sep 17 00:00:00 2001 From: Martin Babinsky Date: Tue, 26 May 2015 18:11:08 +0200 Subject: increase NSS memcache timeout for IPA server Increasing memcache timeout to 600 seconds when configuring sssd on IPA server should improve performance when dealing with large groups in trusts. https://fedorahosted.org/freeipa/ticket/4964 Reviewed-By: Martin Basti --- ipa-client/ipa-install/ipa-client-install | 9 +++++++++ 1 file changed, 9 insertions(+) (limited to 'ipa-client/ipa-install') diff --git a/ipa-client/ipa-install/ipa-client-install b/ipa-client/ipa-install/ipa-client-install index 0f032888e..c46a7a8a6 100755 --- a/ipa-client/ipa-install/ipa-client-install +++ b/ipa-client/ipa-install/ipa-client-install @@ -1274,6 +1274,15 @@ def configure_sssd_conf(fstore, cli_realm, cli_domain, cli_server, options, clie # the master should only use itself for Kerberos domain.set_option('ipa_server', cli_server[0]) + # increase memcache timeout to 10 minutes when in server mode + try: + nss_service = sssdconfig.get_service('nss') + except SSSDConfig.NoServiceError: + nss_service = sssdconfig.new_service('nss') + + nss_service.set_option('memcache_timeout', 600) + sssdconfig.save_service(nss_service) + domain.set_option('ipa_domain', cli_domain) domain.set_option('ipa_hostname', client_hostname) if cli_domain.lower() != cli_realm.lower(): -- cgit