Download your favorite Linux distribution at LQ ISO.
Go Back > Forums > Linux Forums > Linux - Server
User Name
Linux - Server This forum is for the discussion of Linux Software used in a server related context.


  Search this Thread
Old 04-23-2011, 03:24 AM   #1
LQ Newbie
Registered: Mar 2004
Distribution: Archlinux
Posts: 18

Rep: Reputation: 0
DBUS problems after changing LDAP/Kerberos/NSCD settings

we're running an Ubuntu 10.04 LTS network on our company, authenticating against an Openldap/heimdal-kerberos server.
Previously, the clients were authenticating against a Windows 2003 Domain without any problems.
After modifying the krb.conf, ldap.conf, nsswitch.conf and nscd.conf files to authenticate the machines against the openldap/heimdal setup, we started experiencing strange problems.
One issue is, for example, the polkit-agent-gnome not starting. This component integrates policykit into gnome.
It looks like the agent is unable to start due to some kind of delay with DBUS. Starting the agent manually keeps giving errors until about 70 seconds after login, when the agent can be started without problems.
During the delay it is also impossible, for instance, to open the "shut down" menu on the top right of gnome. You can click on the menu, but nothing appears.

Trying to start the polkit-agent manually gives these errors (I'll be attaching detailed errors when at work!):
DBus error org.freedesktop.DBus.Error.NoReply: Did not receive a reply. Possible causes include: the remote application did not send a reply, the message bus security policy blocked the reply, the reply timeout expired, or the network connection was broken

GLIB ERROR ** default - Not enough memory to set up DBusConnection for use with GLib
It really looks like DBus or something related to it is starting "too late" but I can't seem to find the reason. I'm pretty sure this has to do with some timings or whatever in the krb/ldap config files...
Thanks for help, I've got no clue so far. And happy Easter!
Old 04-25-2011, 05:43 AM   #2
LQ Newbie
Registered: Mar 2004
Distribution: Archlinux
Posts: 18

Original Poster
Rep: Reputation: 0
I'm doing some more investigations and I think this could be related to some service starting too soon, probably due to upstart parallel processes starting or something.
Any suggestion on the service startup order? I'm clueless
Old 04-27-2011, 03:53 AM   #3
LQ Newbie
Registered: Mar 2004
Distribution: Archlinux
Posts: 18

Original Poster
Rep: Reputation: 0
Some updates: it really looks like this is somehow related to DBus, but I'm still unable to tackle down the cause of the issue. This is what happens:
If, immediately after login, I restart DBus manually (service dbus restart), gdm restarts also and I can log in. This time, the log in is really fast and all the softwares depending on dbus are working fine (polkit-agent, power manager, network manager, etc.).

So, what's happening?
Old 04-28-2011, 08:09 AM   #4
LQ Newbie
Registered: Mar 2004
Distribution: Archlinux
Posts: 18

Original Poster
Rep: Reputation: 0
Ok, I was right, DBUS was somehow related.

The problem was more complex and the agent was just a "victim" of something bigger.
Basically, DBUS was not starting properly. In fact, the polkit-agent was not the only service unable to start: network manager, gnome-power-manager, bluetooth stuff, etc. were amongst the missing pieces.
What happens is that Dbus starts at boot and queries LDAP authenticating as "messagebus". Since NSCD is not started yet, dbus has problems.
These are some more enlightening errors:
dbus-daemon: GSSAPI Error: Unspecified GSS failure.  Minor code may provide more information (Credentials cache file '/tmp/krb5cc_101' not found)
dbus-daemon: nss_ldap: failed to bind to LDAP server ldap://<server>/: Local error
dbus-daemon: nss_ldap: could not search LDAP server - Server is unavailable
We must start NSCD before DBUS, then. Ubuntu 10.04 is using upstart for many services, including DBUS. Nscd is still relying on symlinks, so the startup order can't be modified easily.
The problem has been solved with a modification of the dbus upstart script and creating a custom Nscd upstart script, to make dbus depend on nscd. Briefly, something of this kind:

upstart dbus.conf modified line:
"start on started nscd"
upstart nscd.conf new file
"description	"name service cache daemon"

start on local-filesystems
stop on runlevel [06]

#expect fork
pre-start script
    mkdir -p /var/run/nscd
end script

exec /usr/sbin/nscd -f /etc/nscd.conf"
I'm pretty scared about the maintainability of this solution, an update could break everything. At least, we got the cause.
I really don't know who should be contacted here, whether ubuntu devs, dbus devs or whatever!

Last edited by spidernik84; 04-28-2011 at 08:14 AM. Reason: markup cleanup, added some details


dbus, kerberos, openldap

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
nscd: nss_ldap: reconnected to LDAP server errors RHEL 5.4 smitsc05 Linux - Networking 2 12-02-2010 11:50 PM
Using nscd to cache LDAP and DNS entries kenneho Linux - Server 8 06-30-2009 03:34 PM
NSCD and LDAP Rowley Linux - Software 9 07-31-2008 03:11 AM
DBus not working with Kerberos-LDAP user accounts teamanx Linux - Software 0 09-20-2007 08:33 AM
kerberos/ldap login -> samba problems mesepher Linux - Software 6 02-28-2006 08:33 AM > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 11:54 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration