ldap authentication and _ldap._tcp SRV record

Thierry Lacoste <lacoste-JY2aMsvkacKWoTRwy/[email protected]>
Newsgroups gmane.linux.redhat.release.taroon.general
Organization MIAGE
Message-ID <[email protected]>
I have an ES3 server which was a NIS client of an Active Directory
server (though SFU). It's recolv.conf pointed to the AD server.
I installed my own Unix DNS server and I replaced AD with samba/ldap.
Then I configured the ES3 server to use nss_ldap and pam_ldap.

If my DNS server has an entry
_ldap._tcp      IN SRV  01 00 389  nonexistent.
I can login to the ES3 server with an ldap account.
Note that the DNS record can even point to a non-existent machine
which is the case here.

If I remove this DNS entry I can only login with local accounts on
the ES3 server. If I try to su to an ldap account I have an 'incorrect
password' error.
My /var/log/messages contains:
Jul 26 13:58:28 bambi su(pam_unix)[4046]: check pass; user unknown
Jul 26 13:58:28 bambi su(pam_unix)[4046]: authentication failure; logname=root 
uid=100 euid=0 tty= ruser=admin rhost=

I didn't make the original installation of the server so I'm a bit lost.
Any clue would be much appreciated.

Regards,
Thierry.

--
Taroon-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/taroon-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.