LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 07-31-2009, 12:12 AM   #1
luvshines
Member
 
Registered: Apr 2009
Posts: 74

Rep: Reputation: 16
Unhappy LDAP authentication problem in RHEL 5.3


I configured my system to use LDAP as authentication module along with PAM for giving restricted access to ftp and scp services.

the nsswitch.conf file has entries like

passwd: files ldap
shadow: files ldap
group: files ldap

and the pam.d/system-auth is also configured by default configuration one which is obtained by
authconfig command with ldap details

The setup works fine, till the ldap server is up. Problem starts only when the server is down
I am not able to ssh into the machine with even the local users
I googled a bit and found these

https://bugzilla.redhat.com/show_bug.cgi?id=201557

https://bugzilla.redhat.com/show_bug.cgi?id=189624

These are old posts, 2006 and last updated in 2008.
I am running RHEL 5.3 on 64 bit platform
The posts are for 5.1.

Has nebody come across this problem in the later versions like me, or was it resolved.

Any other suggestions are also welcome.
PLS REPLY ASAP, this is a major block for my project.
 
Old 08-01-2009, 08:02 PM   #2
scottro11
Member
 
Registered: Jun 2009
Location: NYC
Posts: 263

Rep: Reputation: 59
Heh, VERY old bug, never fixed. I guess they were too busy working on important things like spinning cubes. (oooh, shame on me).

However, recently, someone gave me the solution.

Actually, what's amusing is that if the LDAP server is running, even if there's no account on it, you won't get the delay--it's as if the system simply wants reassurance that yes, LDAP servers do exist in the world.

Anyway, the solution that has worked for me, gotten, I believe, on these forums....

On the client edit /etc/ldap.conf (not /etc/openldap/ldap.conf)

You will see a line, commented out, that reads bind_policy hard

Change the hard to soft (and remove the comment sign) and that should fix the issue.

In other words, change

#bind_policy hard

To

bind_policy soft
 
Old 08-06-2009, 03:44 AM   #3
luvshines
Member
 
Registered: Apr 2009
Posts: 74

Original Poster
Rep: Reputation: 16
Question

Thanx scottro11

I tried that thing at it works for me too.
But now, i have another issue, in case i specify multiple LDAP servers, and set
bind_policy soft
It doesn't try to contact the second LDAP server in case the first is down.
Is there any other configuration needed to achieve the fallback mechanism
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ldap authentication problem raghavendrat Linux - Server 8 04-08-2008 06:32 AM
Problem wih authentication LDAP zoltrix Red Hat 4 10-28-2007 01:51 PM
Open LDAP Authentication problem Rajesh_Amma Linux - Newbie 1 04-20-2006 06:59 PM
ldap authentication problem anjani.78 Linux - Software 7 12-23-2005 11:00 AM
ldap authentication problem fitz9948 Linux - Networking 0 10-26-2004 02:44 PM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 06:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration