Package: nslcd
Version: 0.8.10-4
Severity: important

Dear Maintainer,

I just switched from libnss-ldap / OpenLDAP with TLS auth to 
libnssd-ldap / Samba4 AD DC with Kerberos auth. So the issue might have
existed for some time.

During boot k5start fails:

Fri Oct 24 12:34:55 2014: [FAIL] Starting Keep alive Kerberos ticket: 
k5startk5start: error getting credentials: Cannot contact any KDC for realm 
'AD.MICROSULT.DE'
Fri Oct 24 12:34:55 2014: [ ok ] Starting LDAP connection daemon: nslcd

which means that nslcd cannot read from the AD DC and all AD users are 
unknown. Logging in as root following start-up and restarting nslcd by
/etc/init.d/nslcd restart
works fine and also starts k5start.

Could it be that it is run too early in the start-up?

However, NFS is started before nslcd and I use kerberized NFS4!

Regards,
 - lars

-- System Information:
Debian Release: 7.7
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages nslcd depends on:
ii  adduser                3.113+nmu3
ii  debconf [debconf-2.0]  1.5.49
ii  libc6                  2.13-38+deb7u6
ii  libgssapi-krb5-2       1.10.1+dfsg-5+deb7u2
ii  libldap-2.4-2          2.4.31-1+nmu2

Versions of packages nslcd recommends:
ii  bind9-host [host]           1:9.8.4.dfsg.P1-6+nmu2+deb7u2
ii  host                        1:9.8.4.dfsg.P1-6+nmu2+deb7u2
ii  ldap-utils                  2.4.31-1+nmu2
ii  libnss-ldapd [libnss-ldap]  0.8.10-4
ii  libpam-krb5                 4.6-1
pn  nscd                        <none>

Versions of packages nslcd suggests:
ii  kstart  4.1-2

-- Configuration Files:
/etc/default/nslcd changed:
K5START_PRINCIPAL="MIDGARD\[email protected]"


-- debconf information:
  nslcd/ldap-sasl-realm:
  nslcd/ldap-starttls: false
  nslcd/ldap-sasl-krb5-ccname: /var/run/nslcd/nslcd.tkt
  nslcd/ldap-auth-type: none
  nslcd/ldap-reqcert:
* nslcd/ldap-uris: ldap://samba.ad.microsult.de/
  nslcd/ldap-sasl-secprops:
  nslcd/ldap-binddn:
  nslcd/ldap-sasl-authcid:
  nslcd/ldap-sasl-mech:
* nslcd/ldap-base: DC=ad,DC=microsult,DC=de
  nslcd/ldap-sasl-authzid:


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to