Thanks, I saw that, the default is root,ldap but that did not make a
difference. I also tried other combinations and a couple of times with
only root with the same results. There are many hits on a google search
for this condition but no resolutions. I am seeing this condition for
udevd, securitytty, and some othe services. I assume these all run under
root as there are no ids or groups specifically for udevd and the rest. I
am kind of stumped. I am leaning towards a possible bug at this point.
Maybe something will come to be over a couple (or six) beers this weekend.


Peter




From:   Mark Post <mp...@novell.com>
To:     LINUX-390@vm.marist.edu
Date:   08/19/2011 02:45 PM
Subject:        Re: udevd-349-: nss_ldap: failed to bind to LDAP server
ldap:// . . .
Sent by:        Linux on 390 Port <LINUX-390@vm.marist.edu>



>>> On 8/19/2011 at 10:53 AM, "Peter E. Abresch Jr.   - at Pepco"
<peabre...@pepco.com> wrote:
> I have the following specified:
> nss_initgroups_ignoreusers
>
root,ldap,haldaemon,messagebus,dbus,bin,daemon,postfix,sshd,polkituser,uuidd
> ,100,101
>
> I know I probably only need a few of these but I wanted to eliminate the

> messages.
>
> This does not appear to be working as expected. Of course my
expectations
> could be off. What are everyone?s thoughts on this? Is this an issue
that
> I need to push to support? What are others doing with Linux RACF LDAP
> authorizations? All comments are welcome. Thanks

A Google search found something that indicates perhaps having "too many"
users listed can be a problem.  They were able to get the ignore list to
work with 2 entries, but having 13 didn't.  This was on RHEL5 from June of
this year, so fairly recent.  Give that a try and see what happens.  Then
regardless of the result, open up a support request.


Mark Post

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to lists...@vm.marist.edu with the message: INFO LINUX-390 or
visit
http://www.marist.edu/htbin/wlvindex?LINUX-390
----------------------------------------------------------------------
For more information on Linux on System z, visit
http://wiki.linuxvm.org/


This Email message and any attachment may contain information that is
proprietary, legally privileged, confidential and/or subject to copyright
belonging to Pepco Holdings, Inc. or its affiliates ("PHI").  This Email is
intended solely for the use of the person(s) to which it is addressed.  If
you are not an intended recipient, or the employee or agent responsible for
delivery of this Email to the intended recipient(s), you are hereby notified
that any dissemination, distribution or copying of this Email is strictly
prohibited.  If you have received this message in error, please immediately
notify the sender and permanently delete this Email and any copies.  PHI
policies expressly prohibit employees from making defamatory or offensive
statements and infringing any copyright or any other legal right by Email
communication.  PHI will not accept any liability in respect of such
communications.

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to lists...@vm.marist.edu with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390
----------------------------------------------------------------------
For more information on Linux on System z, visit
http://wiki.linuxvm.org/

Reply via email to