1 |
Am Montag, 22. Okt 2007, 06:20:56 +0200 schrieb Bertram Scharpf: |
2 |
> Hi, |
3 |
> |
4 |
> Am Freitag, 19. Okt 2007, 21:09:59 +0200 schrieb Bertram Scharpf: |
5 |
> > @(#) $OpenLDAP: slapd 2.3.38 (Oct 18 2007 22:12:26) $ root@myhost:/var/tmp/portage/net-nds/openldap-2.3.38/work/openldap-2.3.38/servers/slapd |
6 |
> > nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server |
7 |
> > nss_ldap: failed to bind to LDAP server ldap://127.0.0.1/: Can't contact LDAP server |
8 |
> > nss_ldap: failed to bind to LDAP server ldapi://%2fvar%2frun%2fldapi_sock/: Can't contact LDAP server |
9 |
> > ... |
10 |
> > nss_ldap: could not search LDAP server - Server is unavailable |
11 |
> > |
12 |
> > I found out that the Gentoo init script activates the |
13 |
> > options "-u ldap -g ldap". |
14 |
> |
15 |
> I detected I have a machine where this didn't happen. Then I |
16 |
> upgraded from glibc-2.5-r4 to glibc-2.6.1 ... |
17 |
> |
18 |
> Could this be a real bug in glibc? Does anybody experience |
19 |
> the same behaviour? |
20 |
|
21 |
The developer list gave me the answer. Glibc checks for |
22 |
group memberships of user ldap. A possible (temporary) |
23 |
solution is to say in /etc/ldap.conf: |
24 |
|
25 |
nss_initgroups_ignoreusers root,ldap |
26 |
|
27 |
Bertram |
28 |
|
29 |
|
30 |
-- |
31 |
Bertram Scharpf |
32 |
Stuttgart, Deutschland/Germany |
33 |
http://www.bertram-scharpf.de |
34 |
-- |
35 |
gentoo-user@g.o mailing list |