Re: nsswitch.conf and openldap-server

Buchan Milne <[email protected]> Wed, 8 Feb 2006 13:20:48 +0200
Newsgroups gmane.linux.mandrake.server
Message-ID <[email protected]>
--nextPart2340685.pqkzIFmA5D
Content-Type: text/plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

On Wednesday 08 February 2006 12:49, Frederic Bongat wrote:
> > Any machine which may lose access to its LDAP server should have
> > something like this in /etc/ldap.conf:
> >
> > timelimit 5
> > bind_timelimit 5
> >
> > (to allow local users to log in if the LDAP server is not available)
>
> that does not change anything the problem is the same one.
>
> Just for information the client and the server is on the same machine
> (it is thus the server which starts in a mode with the problem)

As all my machines (1 desktop running 2006.0, one laptop running 2006.0, an=
d=20
my work laptop which mostly runs cooker) are in the same position.

While testing nss_ldap 244 and later, I also had to add:

bind_policy soft

to nsswitch.conf, but, I don't think the patches that were added for the=20
2006.0 update included the changes that cause the problems. Note that in my=
=20
case (on my laptop running cooker), I have always used ldap for=20
authentication on it (since I installed 2006.0 beta3 on it when I changed=20
jobs), it gets booted a few times a week, and I didn't see any problems (wi=
th=20
the limits as I mentioned) until I started looking at upgrading nss_ldap in=
=20
cooker to 244 or later.

> > Whether this should affect udev so badly is another question (IMHO the
> > machine should at least be able to boot without these set ...)
>
> Yes I think so,but the fact is there
>
> I created a script which copies a file (nsswitch.conf) with ldap words
> which starts at the time when scripts rc3 starts and there that
> functions well, then when I stop the machine, it recopies the version
> without ldap words (passwd ldap etc.)


This is a hack, I haven't needed this on my 2006.0 laptop or desktop (but,=
=20
they haven't had any updates as I have almost no bandwidth at home), and it=
=20
would be useful to find the real problem (rather than workaround it).

BTW, you should see some messages from nss_ldap in either case. If you boot=
=20
into runlevel 1, you could test this quite easily just by starting syslog,=
=20
and then running 'getent passwd'. It should "hang", use CTRL-C, and see wha=
t=20
you get in /var/log/syslog or similar.

Also, if you have any name resolution problems, they could come into play a=
s=20
well (I ignored this in the first reply).

Regards,
Buchan

=2D-=20
Buchan Milne
B.Eng,RHCE(803004789010797),LPIC-2(LPI000074592)

--nextPart2340685.pqkzIFmA5D
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQBD6dQZrJK6UGDSBKcRAgzBAKDBKC5dHOjkoKG5SAddAuuvMiwKKwCfV+c7
asT9kWB6E59+Yy9r697Cbt4=
=ThDW
-----END PGP SIGNATURE-----

--nextPart2340685.pqkzIFmA5D--