[nflug] ldap ubuntu errors

Darin Perusich Darin.Perusich at cognigencorp.com
Wed Nov 28 15:45:45 EST 2007


Can you send a copy of /etc/ldap.conf and /etc/openldap/ldap.conf?

Jon Skulski wrote:
> Hello,
> 
> I'm trying to (eventually) authorize my linux box against an
> ldap/kerberos setup. I am having some trouble. I can talk to the ldap
> server fine with ldaptools. The problem is where nss comes in. getent
> passwd will only list local entries in passwd. Yes I have nssswitch.conf
> configured correctly. I have it configured so correctly that if I listen
> to the network traffic I can actually see the ldap request and response,
> but for some reason NSS ignores it.
> 
> Interesting behaviors:
> 
> - only local users and groups are listed by getent
> - NSS is ignoring the ldap response
> - the ldap response is very very large, so i thought that might be it. i
> tried using a smaller base search (only me) and it still ignored the result.
> - strace of getent does not show anything unusual
> - now whenever I log in or sudo or anything, i have to enter my password
> twice. the first time is thrown out, whether right or wrong. this may
> have more to do with an incomplete setup of pam.
> 
> oh yeah this is all on ubuntu 7.04 fresh install. and i'm about to
> upgrade to 7.10 because well, i'm out of ideas.
> 
> Anyway, I would really like to get this working because if i don't
> they'll make me use windows to develop a php application :O SAVE ME LUG!
> 
>  
> 
> 
> ------------------------------------------------------------------------
> 
> _______________________________________________
> nflug mailing list
> nflug at nflug.org
> http://www.nflug.org/mailman/listinfo/nflug

-- 
Darin Perusich
Unix Systems Administrator
Cognigen Corporation
395 Youngs Rd.
Williamsville, NY 14221
Phone: 716-633-3463
Email: darinper at cognigencorp.com


More information about the nflug mailing list