Package: nslcd Version: 0.8.10-4 Severity: important Dear Maintainer,
I just switched from libnss-ldap / OpenLDAP with TLS auth to libnssd-ldap / Samba4 AD DC with Kerberos auth. So the issue might have existed for some time. During boot k5start fails: Fri Oct 24 12:34:55 2014: [FAIL] Starting Keep alive Kerberos ticket: k5startk5start: error getting credentials: Cannot contact any KDC for realm 'AD.MICROSULT.DE' Fri Oct 24 12:34:55 2014: [ ok ] Starting LDAP connection daemon: nslcd which means that nslcd cannot read from the AD DC and all AD users are unknown. Logging in as root following start-up and restarting nslcd by /etc/init.d/nslcd restart works fine and also starts k5start. Could it be that it is run too early in the start-up? However, NFS is started before nslcd and I use kerberized NFS4! Regards, - lars -- System Information: Debian Release: 7.7 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores) Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages nslcd depends on: ii adduser 3.113+nmu3 ii debconf [debconf-2.0] 1.5.49 ii libc6 2.13-38+deb7u6 ii libgssapi-krb5-2 1.10.1+dfsg-5+deb7u2 ii libldap-2.4-2 2.4.31-1+nmu2 Versions of packages nslcd recommends: ii bind9-host [host] 1:9.8.4.dfsg.P1-6+nmu2+deb7u2 ii host 1:9.8.4.dfsg.P1-6+nmu2+deb7u2 ii ldap-utils 2.4.31-1+nmu2 ii libnss-ldapd [libnss-ldap] 0.8.10-4 ii libpam-krb5 4.6-1 pn nscd <none> Versions of packages nslcd suggests: ii kstart 4.1-2 -- Configuration Files: /etc/default/nslcd changed: K5START_PRINCIPAL="MIDGARD\[email protected]" -- debconf information: nslcd/ldap-sasl-realm: nslcd/ldap-starttls: false nslcd/ldap-sasl-krb5-ccname: /var/run/nslcd/nslcd.tkt nslcd/ldap-auth-type: none nslcd/ldap-reqcert: * nslcd/ldap-uris: ldap://samba.ad.microsult.de/ nslcd/ldap-sasl-secprops: nslcd/ldap-binddn: nslcd/ldap-sasl-authcid: nslcd/ldap-sasl-mech: * nslcd/ldap-base: DC=ad,DC=microsult,DC=de nslcd/ldap-sasl-authzid: -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

