Re: nsswitch.conf and openldap-server

Frederic Bongat <[email protected]> Wed, 08 Feb 2006 15:03:59 +0100
Newsgroups gmane.linux.mandrake.server
Organization LMD - IPSL
Message-ID <[email protected]>
Hi,

I found the problem, It comes only when I get ldap on host variable :

"host files dns ldap"  in nsswitch.conf

when I remove ldap variable host that functions nice.  It was thus a 
problem of resolution of name

Merci Buchan for your assistance!!!

> On Wednesday 08 February 2006 12:49, Frederic Bongat wrote:
> 
>>>Any machine which may lose access to its LDAP server should have
>>>something like this in /etc/ldap.conf:
>>>
>>>timelimit 5
>>>bind_timelimit 5
>>>
>>>(to allow local users to log in if the LDAP server is not available)
>>
>>that does not change anything the problem is the same one.
>>
>>Just for information the client and the server is on the same machine
>>(it is thus the server which starts in a mode with the problem)
> 
> 
> As all my machines (1 desktop running 2006.0, one laptop running 2006.0, and 
> my work laptop which mostly runs cooker) are in the same position.
> 
> While testing nss_ldap 244 and later, I also had to add:
> 
> bind_policy soft
> 
> to nsswitch.conf, but, I don't think the patches that were added for the 
> 2006.0 update included the changes that cause the problems. Note that in my 
> case (on my laptop running cooker), I have always used ldap for 
> authentication on it (since I installed 2006.0 beta3 on it when I changed 
> jobs), it gets booted a few times a week, and I didn't see any problems (with 
> the limits as I mentioned) until I started looking at upgrading nss_ldap in 
> cooker to 244 or later.
> 
> 
>>>Whether this should affect udev so badly is another question (IMHO the
>>>machine should at least be able to boot without these set ...)
>>
>>Yes I think so,but the fact is there
>>
>>I created a script which copies a file (nsswitch.conf) with ldap words
>>which starts at the time when scripts rc3 starts and there that
>>functions well, then when I stop the machine, it recopies the version
>>without ldap words (passwd ldap etc.)
> 
> 
> 
> This is a hack, I haven't needed this on my 2006.0 laptop or desktop (but, 
> they haven't had any updates as I have almost no bandwidth at home), and it 
> would be useful to find the real problem (rather than workaround it).
> 
> BTW, you should see some messages from nss_ldap in either case. If you boot 
> into runlevel 1, you could test this quite easily just by starting syslog, 
> and then running 'getent passwd'. It should "hang", use CTRL-C, and see what 
> you get in /var/log/syslog or similar.
> 
> Also, if you have any name resolution problems, they could come into play as 
> well (I ignored this in the first reply).
> 
> Regards,
> Buchan
> 


-- 
Frederic Bongat
Administrateur Systeme et Reseau LMD - CNRS
Ingenieur Securite des Systemes d'Information IPSL

e-mail: [email protected]
e-mail: [email protected]