Monday, 2 July 2012

LDAP_MATCHING_RULE_IN_CHAIN Load Test

You can use following LDAP search filter to list all the groups that a user is a member of.

member:1.2.840.113556.1.4.1941:=(cn=user1,cn=users,DC=x)

However this operation can be very expensive on the DC if you have a deep nesting structure for your groups.

You can use Apache JMeter to do LDAP load test.

Ever wonder a simpler way (without any third-party tool involved) to test the performance? Well, try MS dsquery.

First of all, get the user's DN string with the following command

dsquery user -name "john*"

Assume it returns

"CN=john smith,CN=Users,DC=ds03,DC=local"

Then execute the following command to see if the results are expected.

dsquery * domainroot -filter "(&(member:1.2.840.113556.1.4.1941:=CN=john smith,CN=Users,DC=ds03,DC=local))" -limit 10

Now, save the following as a DOS batch file, don't forget to modify it to use your own LDAP filter.

@echo off
@rem --------------------------------------------
setlocal ENABLEEXTENSIONS

set start_time=%time%
echo Beginning at: %start_time%
echo Running Timed Batch File
echo.


@rem CHANGE YOUR OWN LDAP Filter
dsquery * domainroot -filter "(&(member:1.2.840.113556.1.4.1941:=CN=john smith,CN=Users,DC=ds03,DC=local))" -limit 10


set stop_time=%time%
echo.
echo Timed Batch File Completed
echo Start time: %start_time%
echo Stop time : %stop_time%


set TEMPRESULT=%start_time:~0,2%
call:FN_REMOVELEADINGZEROS
set start_hour=%TEMPRESULT%
@rem
set TEMPRESULT=%start_time:~3,2%
call:FN_REMOVELEADINGZEROS
set start_min=%TEMPRESULT%
@rem
set TEMPRESULT=%start_time:~6,2%
call:FN_REMOVELEADINGZEROS
set start_sec=%TEMPRESULT%
@rem
set TEMPRESULT=%start_time:~9,2%
call:FN_REMOVELEADINGZEROS
set start_hundredths=%TEMPRESULT%

set TEMPRESULT=%stop_time:~0,2%
call:FN_REMOVELEADINGZEROS
set stop_hour=%TEMPRESULT%
@rem
set TEMPRESULT=%stop_time:~3,2%
call:FN_REMOVELEADINGZEROS
set stop_min=%TEMPRESULT%
@rem
set TEMPRESULT=%stop_time:~6,2%
call:FN_REMOVELEADINGZEROS
set stop_sec=%TEMPRESULT%
@rem
set TEMPRESULT=%stop_time:~9,2%
call:FN_REMOVELEADINGZEROS
set stop_hundredths=%TEMPRESULT%

set /A start_total=(((((%start_hour%*60)+%start_min%)*60)+%start_sec%)*100)+%start_hundredths%
set /A stop_total=(((((%stop_hour%*60)+%stop_min%)*60)+%stop_sec%)*100)+%stop_hundredths%

set /A total_time=%stop_total% - %start_total%

set /A total_hundredths=%total_time% %% 100
set total_hundredths=00%total_hundredths%
set total_hundredths=%total_hundredths:~-2%
set /A total_time=%total_time% / 100

set /A total_sec="%total_time% %% 60"
set total_sec=00%total_sec%
set total_sec=%total_sec:~-2%
set /A total_time=%total_time% / 60

set /A total_min="%total_time% %% 60"
set total_min=00%total_min%
set total_min=%total_min:~-2%
set /A total_time=%total_time% / 60

set /A total_hour="%total_time% %% 60"
@rem Handle if it wrapped around over midnight
if "%total_hour:~0,1%"=="-" set /A total_hour=%total_hour% + 24

echo Total time: %total_hour%:%total_min%:%total_sec%.%total_hundredths%

@rem --------------------------------------------
@rem Exit the BAT Program
endlocal
goto END

@rem --------------------------------------------
@rem FN_REMOVELEADINGZEROS function
@rem  Used to remove leading zeros from Decimal
@rem  numbers so they are not treated as Octal.
:FN_REMOVELEADINGZEROS
if "%TEMPRESULT%"=="0" goto END
if "%TEMPRESULT:~0,1%" NEQ "0" goto END
set TEMPRESULT=%TEMPRESULT:~1%
goto FN_REMOVELEADINGZEROS

@rem --------------------------------------------
@rem BAT PROGRAM / FUNCTION FILE EXIT
:END


Tuesday, 12 June 2012

KVM Practice

Recently I had chance to try KVM on server4you dedicated server. The result is quiet impressive. Nowadays KVM is on a par with the commercial bare metal technoligy like ESX.

Please read this PDF version for what I have done, which includes upgrading Linux kernal, KVM, iptables firewall, VNC, VPN, SFTP, SAMBA, even NGINX.

Tuesday, 17 April 2012

Configure TLS on Exchange 2010 with own certificate


In this article, I try to describe how to use the certificate signed by own CA to configure TLS on Exchange server 2010. The OpenSSL setting on crlDistributionPoints is very important, without a reachable CRL Distribution Point the certificate will not work (properly) in Exchange. Please read the PDF version for the details.

Thursday, 16 February 2012

Juniper SAML and ADFS 2.0

Juniper adds SAML to SSL VPN, however I can hardly find the technical document for how to make it work with MS ADFS 2.0. Luckily I worked it out by myself. Here is the details.

Monday, 16 January 2012

Yet another LDAP Benchmark

It seems this LDAP benchmark (from Novell Cool Solutions) doesn't support LDAPS, so I decided to write my own one.



You can download the project (source code). Please download and install WTL if you want to recompile it.


Note: I added a DDX DDX_COMBO_INDEX, you need to customize atlddx.h. For your convenience, I attached the modified atlddx.h in the project.

Thread Dump Beheaded

Tomcat(Windows version) Thread Dump adds some time info which makes it unloadable with Thread Dump Analyzer (like TDA). I can't figure out the settings(if any) to remove it, so I wrote a small utility - Thread Dump Beheaded, Horror? but it is true, remove the head.


The original thread dump has the following format.



[2012-01-06 11:48:57] [info] Procrun (2.0.6.0) started
[2012-01-06 11:48:57] [info] Running Service...
[2012-01-06 11:48:57] [info] Starting service...
[2012-01-06 11:49:04] [info] Service started in 6921 ms.
[2012-01-09 11:45:11] [info] Console CTRL+BREAK event signaled
[2012-01-09 11:45:11] [info] 2012-01-09 11:45:11
[2012-01-09 11:45:11] [info] Full thread dump Java HotSpot(TM) Server VM (11.2-b01 mixed mode):
[2012-01-09 11:45:11] [info]
[2012-01-09 11:45:11] [info] "http-8074-44"
[2012-01-09 11:45:11] [info] daemon
[2012-01-09 11:45:11] [info] prio=6 tid=0x6c14c800
[2012-01-09 11:45:11] [info] nid=0x1158
[2012-01-09 11:45:11] [info] in Object.wait()
[2012-01-09 11:45:11] [info] [0x715bf000..0x715bfbe8]
[2012-01-09 11:45:11] [info] java.lang.Thread.State: WAITING (on object monitor)
[2012-01-09 11:45:11] [info] at java.lang.Object.wait(Native Method)
[2012-01-09 11:45:11] [info] - waiting on <0x6296a3b0>
[2012-01-09 11:45:11] [info] (a org.apache.tomcat.util.net.JIoEndpoint$Worker)
[2012-01-09 11:45:11] [info] at java.lang.Object.wait(Object.java:485)
[2012-01-09 11:45:11] [info] at org.apache.tomcat.util.net.JIoEndpoint$Worker.await(JIoEndpoint.java:458)
[2012-01-09 11:45:11] [info] - locked <0x6296a3b0>
[2012-01-09 11:45:11] [info] (a org.apache.tomcat.util.net.JIoEndpoint$Worker)
[2012-01-09 11:45:11] [info] at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:484)
[2012-01-09 11:45:12] [info] at java.lang.Thread.run(Unknown Source)
[2012-01-09 11:45:12] [info]

After removing head, and organizing the line.



Procrun (2.0.6.0) started
Running Service...
Starting service...
Service started in 6921 ms.
Console CTRL+BREAK event signaled
2012-01-09 11:45:11
Full thread dump Java HotSpot(TM) Server VM (11.2-b01 mixed mode):

"http-8074-44" daemon prio=6 tid=0x6c14c800 nid=0x1158 in Object.wait() [0x715bf000..0x715bfbe8]
java.lang.Thread.State: WAITING (on object monitor)
at java.lang.Object.wait(Native Method)
- waiting on <0x6296a3b0> (a org.apache.tomcat.util.net.JIoEndpoint$Worker)
at java.lang.Object.wait(Object.java:485)
at org.apache.tomcat.util.net.JIoEndpoint$Worker.await(JIoEndpoint.java:458)
- locked <0x6296a3b0> (a org.apache.tomcat.util.net.JIoEndpoint$Worker)
at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:484)
at java.lang.Thread.run(Unknown Source)


This is a Windows console application, so go to Windows Prompt, execute tdbehead tdorginal.log, it will produce a file called tdorginal.bhd which now can be loaded by TDA. You can download the whole project which contains source code, binary and the thread dump sample.

Monday, 7 November 2011

Tomcat CPU Hog Monitoring service

Have you ever been in this kind of trouble? You use Tomcat as the servlet container. In general your web service runs smoothly, however it has CPU hog issue randomly on the production server of your customer. You are told it is not a load issue (CPU is expected high when there is a huge demand for your service, it can only be solved by load balancing) which means your Java coding may have a bug or bad design. The problem is, you are unable to reproduce this issue in your environment, and even your customer can’t reproduce it on purpose.


Anyway, the issue does happen, but no pattern at all. You are under a big pressure to sort it out quickly, what can you do?


Struggled and frustrated? Don’t worry, NanoFish comes to rescue!


Please check this PDF version for the details. You can download the binary and source code, I wish they are helpful.