Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
SSH - Corrupt MAC on linux, but works on PuTTY!? Whaa?!
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
sven_sol
Tux's lil' helper
Tux's lil' helper


Joined: 27 Apr 2005
Posts: 120
Location: Royston, Herts. UK

PostPosted: Wed Dec 17, 2008 11:54 am    Post subject: SSH - Corrupt MAC on linux, but works on PuTTY!? Whaa?! Reply with quote

Hi all,

this is good... I really am confused by this.

There is a server, running SSH. I cannot connect to it either from my Mac OSX 10.5.6 or from any of my linux boxes. However, if I use PuTTY on a Windows machine it connects fine.

What I reeeaaaallllyy find odd is that the user database is in OpenLDAP, an no user that is in the LDAP i.e. an Administrator account can log on - however the root user can!

After debugging the connections it seems that the local nss cannot connect to the ldap directory due to certificates. Now, the services are all based on the LDAP - Samba, Mail etc. and they work fine.

Any ideas?!

Code:
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: >>> slap_listener(ldaps://)
Dec 15 13:02:12 main slapd[11157]: daemon: listen=7, new connection on 20
Dec 15 13:02:12 main slapd[11157]: daemon: added 20r (active) listener=(nil)
Dec 15 13:02:12 main slapd[11157]: conn=16 fd=20 ACCEPT from IP=192.168.1.60:54270 (IP=0.0.0.0:636)
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main sshd[11183]: nss_ldap: failed to bind to LDAP server ldaps://svenmachine: Can't contact LDAP server
Dec 15 13:02:12 main sshd[11183]: nss_ldap: could not search LDAP server - Server is unavailable
Dec 15 13:02:12 main sshd[11183]: pam_unix(sshd:auth): check pass; user unknown
Dec 15 13:02:12 main sshd[11183]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=my-external-ip
Dec 15 13:02:12 main sshd[11183]: pam_ldap: ldap_simple_bind Can't contact LDAP server
Dec 15 13:02:12 main sshd[11183]: pam_ldap: reconnecting to LDAP server...
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:  20r
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: daemon: read active on 20
Dec 15 13:02:12 main slapd[11157]: connection_get(20)
Dec 15 13:02:12 main slapd[11157]: connection_get(20): got connid=16
Dec 15 13:02:12 main slapd[11157]: connection_read(20): checking for input on id=16
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:  20r
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: daemon: read active on 20
Dec 15 13:02:12 main slapd[11157]: connection_get(20)
Dec 15 13:02:12 main slapd[11157]: connection_get(20): got connid=16
Dec 15 13:02:12 main slapd[11157]: connection_read(20): checking for input on id=16
Dec 15 13:02:12 main slapd[11157]: connection_read(20): TLS accept failure error=-1 id=16, closing
Dec 15 13:02:12 main slapd[11157]: connection_closing: readying conn=16 sd=20 for close
Dec 15 13:02:12 main slapd[11157]: connection_close: conn=16 sd=-1
Dec 15 13:02:12 main slapd[11157]: daemon: removing 20
Dec 15 13:02:12 main slapd[11157]: conn=16 fd=20 closed (TLS negotiation failure)
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 2 descriptors
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: >>> slap_listener(ldaps://)
Dec 15 13:02:12 main slapd[11157]: daemon: listen=7, new connection on 20
Dec 15 13:02:12 main slapd[11157]: daemon: added 20r (active) listener=(nil)
Dec 15 13:02:12 main slapd[11157]: conn=17 fd=20 ACCEPT from IP=192.168.1.60:54271 (IP=0.0.0.0:636)
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:  20r
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: daemon: read active on 20
Dec 15 13:02:12 main slapd[11157]: connection_get(20)
Dec 15 13:02:12 main slapd[11157]: connection_get(20): got connid=17
Dec 15 13:02:12 main slapd[11157]: connection_read(20): checking for input on id=17
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:  20r
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: daemon: read active on 20
Dec 15 13:02:12 main slapd[11157]: connection_get(20)
Dec 15 13:02:12 main slapd[11157]: connection_get(20): got connid=17
Dec 15 13:02:12 main slapd[11157]: connection_read(20): checking for input on id=17
Dec 15 13:02:12 main slapd[11157]: connection_read(20): unable to get TLS client DN, error=49 id=17
Dec 15 13:02:12 main slapd[11157]: conn=17 fd=20 TLS established tls_ssf=256 ssf=256
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 2 descriptors
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:  20r
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: daemon: read active on 20
Dec 15 13:02:12 main slapd[11157]: connection_get(20)
Dec 15 13:02:12 main slapd[11157]: connection_get(20): got connid=17
Dec 15 13:02:12 main slapd[11157]: connection_read(20): checking for input on id=17
Dec 15 13:02:12 main slapd[11157]: ber_get_next on fd 20 failed errno=0 (Success)
Dec 15 13:02:12 main slapd[11157]: connection_read(20): input error=-2 id=17, closing.
Dec 15 13:02:12 main slapd[11157]: connection_closing: readying conn=17 sd=20 for close
Dec 15 13:02:12 main slapd[11157]: connection_close: conn=17 sd=-1
Dec 15 13:02:12 main slapd[11157]: daemon: removing 20
Dec 15 13:02:12 main slapd[11157]: conn=17 fd=20 closed (connection lost)
Dec 15 13:02:12 main slapd[11157]: >>> slap_listener(ldaps://)
Dec 15 13:02:12 main slapd[11157]: daemon: listen=7, new connection on 20
Dec 15 13:02:12 main slapd[11157]: daemon: added 20r (active) listener=(nil)
Dec 15 13:02:12 main slapd[11157]: conn=18 fd=20 ACCEPT from IP=192.168.1.60:54272 (IP=0.0.0.0:636)
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 2 descriptors
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:  20r
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:  20r
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: daemon: read active on 20
Dec 15 13:02:12 main slapd[11157]: connection_get(20)
Dec 15 13:02:12 main slapd[11157]: connection_get(20): got connid=18
Dec 15 13:02:12 main slapd[11157]: connection_read(20): checking for input on id=18
Dec 15 13:02:12 main sshd[11183]: pam_ldap: ldap_simple_bind Can't contact LDAP server
Dec 15 13:02:12 main slapd[11157]: connection_read(20): TLS accept failure error=-1 id=18, closing
Dec 15 13:02:12 main slapd[11157]: connection_closing: readying conn=18 sd=20 for close
Dec 15 13:02:12 main slapd[11157]: connection_close: conn=18 sd=-1
Dec 15 13:02:12 main slapd[11157]: daemon: removing 20
Dec 15 13:02:12 main slapd[11157]: conn=18 fd=20 closed (TLS negotiation failure)
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:12 main slapd[11157]: daemon: activity on:
Dec 15 13:02:12 main slapd[11157]:
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:12 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:14 main sshd[11171]: error: PAM: Authentication failure for illegal user administrator from my-external-ip
Dec 15 13:02:14 main sshd[11171]: Failed keyboard-interactive/pam for invalid user administrator from my-external-ip port 45229 ssh2
Dec 15 13:02:14 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:14 main slapd[11157]: daemon: activity on:
Dec 15 13:02:14 main slapd[11157]:
Dec 15 13:02:14 main slapd[11157]: >>> slap_listener(ldaps://)
Dec 15 13:02:14 main slapd[11157]: daemon: listen=7, new connection on 20
Dec 15 13:02:14 main slapd[11157]: daemon: added 20r (active) listener=(nil)
Dec 15 13:02:14 main slapd[11157]: conn=19 fd=20 ACCEPT from IP=192.168.1.60:54273 (IP=0.0.0.0:636)
Dec 15 13:02:14 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:14 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:14 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:14 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:14 main slapd[11157]: daemon: activity on:
Dec 15 13:02:14 main slapd[11157]:  20r
Dec 15 13:02:14 main slapd[11157]:
Dec 15 13:02:14 main slapd[11157]: daemon: read active on 20
Dec 15 13:02:14 main slapd[11157]: connection_get(20)
Dec 15 13:02:14 main slapd[11157]: connection_get(20): got connid=19
Dec 15 13:02:14 main slapd[11157]: connection_read(20): checking for input on id=19
Dec 15 13:02:15 main sshd[11202]: nss_ldap: failed to bind to LDAP server ldaps://svenmachine: Can't contact LDAP server
Dec 15 13:02:15 main sshd[11202]: nss_ldap: could not search LDAP server - Server is unavailable
Dec 15 13:02:15 main sshd[11202]: pam_tally(sshd:auth): pam_get_uid; no such user
Dec 15 13:02:15 main slapd[11157]: connection_read(20): TLS accept failure error=-1 id=19, closing
Dec 15 13:02:15 main slapd[11157]: connection_closing: readying conn=19 sd=20 for close
Dec 15 13:02:15 main slapd[11157]: connection_close: conn=19 sd=-1
Dec 15 13:02:15 main slapd[11157]: daemon: removing 20
Dec 15 13:02:15 main slapd[11157]: conn=19 fd=20 closed (TLS negotiation failure)
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: activity on 2 descriptors
Dec 15 13:02:15 main slapd[11157]: daemon: activity on:
Dec 15 13:02:15 main slapd[11157]:
Dec 15 13:02:15 main slapd[11157]: >>> slap_listener(ldaps://)
Dec 15 13:02:15 main slapd[11157]: daemon: listen=7, new connection on 20
Dec 15 13:02:15 main slapd[11157]: daemon: added 20r (active) listener=(nil)
Dec 15 13:02:15 main slapd[11157]: conn=20 fd=20 ACCEPT from IP=192.168.1.60:54274 (IP=0.0.0.0:636)
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:15 main slapd[11157]: daemon: activity on:
Dec 15 13:02:15 main slapd[11157]:  20r
Dec 15 13:02:15 main slapd[11157]:
Dec 15 13:02:15 main slapd[11157]: daemon: read active on 20
Dec 15 13:02:15 main slapd[11157]: connection_get(20)
Dec 15 13:02:15 main slapd[11157]: connection_get(20): got connid=20
Dec 15 13:02:15 main slapd[11157]: connection_read(20): checking for input on id=20
Dec 15 13:02:15 main sshd[11202]: nss_ldap: failed to bind to LDAP server ldaps://svenmachine: Can't contact LDAP server
Dec 15 13:02:15 main sshd[11202]: nss_ldap: could not search LDAP server - Server is unavailable
Dec 15 13:02:15 main slapd[11157]: connection_read(20): TLS accept failure error=-1 id=20, closing
Dec 15 13:02:15 main slapd[11157]: connection_closing: readying conn=20 sd=20 for close
Dec 15 13:02:15 main slapd[11157]: connection_close: conn=20 sd=-1
Dec 15 13:02:15 main slapd[11157]: daemon: removing 20
Dec 15 13:02:15 main slapd[11157]: conn=20 fd=20 closed (TLS negotiation failure)
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: activity on 1 descriptor
Dec 15 13:02:15 main slapd[11157]: daemon: activity on:
Dec 15 13:02:15 main slapd[11157]:
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=7 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=8 active_threads=0 tvp=zero
Dec 15 13:02:15 main slapd[11157]: daemon: epoll: listen=9 active_threads=0 tvp=zero

_________________
Tua mater tam antiqua ut linguam latinam loquatur

Linux User: #405647


Last edited by sven_sol on Wed Dec 17, 2008 1:34 pm; edited 1 time in total
Back to top
View user's profile Send private message
nativemad
Developer
Developer


Joined: 30 Aug 2004
Posts: 918
Location: Switzerland

PostPosted: Wed Dec 17, 2008 1:22 pm    Post subject: Reply with quote

Hi,

Quote:
nss_ldap: failed to bind to LDAP server ldaps://svenmachine: Can't contact LDAP server

Just a wild guess... this "svenmachine" is coming from /etc/ldap.conf which is responsible for the pam/nss auth...
If it doesn't work, and in /etc/nsswitch.conf is under passwd and shadow also files (or compat, but not only ldap)... Then furthermore, i would guess the only user in /etc/passwd is root... So it just falls back to "files"! That could be the reason why the root login works! :wink:

Either change /etc/ldap.conf to a resolving address/name, or add "svenmachine" to you /etc/hosts!

--most other services have their own ldap config....--

Cheers
_________________
Power to the people!
Back to top
View user's profile Send private message
sven_sol
Tux's lil' helper
Tux's lil' helper


Joined: 27 Apr 2005
Posts: 120
Location: Royston, Herts. UK

PostPosted: Wed Dec 17, 2008 1:34 pm    Post subject: Reply with quote

you're correct: the /etc/ldap.conf points to that machine.

That machine is itself - the syslog shows "main" as the host name (because it is), but I've set the alias to svenmachine in hosts and for this.

The svenmachine has the correct host to the IP address of the interface (not 127.0.0.1) .The /etc/hosts file is correct, and pointing to the IP address of itself. Doing a "getent passwd" is fine, it enumerates the users as expected.

This is the same config as other machines I have, but this is the only showing this.


What about the errors?

Code:
TLS accept failure error=-1
pam_ldap: ldap_simple_bind Can't contact LDAP server

_________________
Tua mater tam antiqua ut linguam latinam loquatur

Linux User: #405647
Back to top
View user's profile Send private message
nativemad
Developer
Developer


Joined: 30 Aug 2004
Posts: 918
Location: Switzerland

PostPosted: Wed Dec 17, 2008 2:01 pm    Post subject: Reply with quote

Ok, i overlooked that TLS error...

Make sure that you have "tls_checkpeer no" in either /etc/openldap/ldap.conf and/or in /etc/ldap.conf.
Otherwise, if you use an alias-name, which isn't the name that is in the certificate, the verification will fail!
_________________
Power to the people!
Back to top
View user's profile Send private message
sven_sol
Tux's lil' helper
Tux's lil' helper


Joined: 27 Apr 2005
Posts: 120
Location: Royston, Herts. UK

PostPosted: Wed Dec 17, 2008 2:31 pm    Post subject: Reply with quote

nope :(

same thing happening.

The certs are fine too.
_________________
Tua mater tam antiqua ut linguam latinam loquatur

Linux User: #405647
Back to top
View user's profile Send private message
nativemad
Developer
Developer


Joined: 30 Aug 2004
Posts: 918
Location: Switzerland

PostPosted: Wed Dec 17, 2008 3:08 pm    Post subject: Reply with quote

Hmm....
Do you know which servername is used in the certificate? Maybe it would be worth a try with that name as ldaps// url, or just the IP, just to get sure, that nothing else is broken...

Do the other (working) clients also use that slapd? Or do they serve their own?
Do you use client certificates?
A bit more details about your config could be helpful.... slapd and ldap/nss
_________________
Power to the people!
Back to top
View user's profile Send private message
sven_sol
Tux's lil' helper
Tux's lil' helper


Joined: 27 Apr 2005
Posts: 120
Location: Royston, Herts. UK

PostPosted: Wed Dec 17, 2008 3:51 pm    Post subject: Reply with quote

Ok - being honest now.. I've changed a couple of the names to preserve the anonymity of my client. Forget the svenmachine - thats me hiding too much to be useful :oops:

the server name is main. The certificate is registered to main.{their.domain}co.uk

The hosts file contains:

Code:
127.0.0.1  localhost
192.168.1.60  main main.{their.domain}.co.uk


/etc/ldap.conf
Code:
#host 127.0.0.1
#base dc=padl,dc=com
debug 0
ssl start_tls
ssl on
suffix      "dc={their.domain},dc=co,dc=uk"
#rootbinddn uid=root,ou=People,dc=genfic,dc=com
uri ldaps://main.{their.domain}.co.uk
pam_password exop
#ldap_version 3
pam_filter objectclass=posixAccount
pam_login_attribute uid
pam_member_attribute memberuid
nss_base_passwd ou=People,dc={their.domain},dc=co,dc=uk
nss_base_shadow ou=People,dc={their.domain},dc=co,dc=uk
nss_base_group  ou=Group,dc={their.domain},dc=co,dc=uk
nss_base_hosts  ou=Hosts,dc={their.domain},dc=co,dc=uk
nss_initgroups_ignoreusers root,ldap,postfix,lighttpd,amavis,mysql,vmail,dnsmasq,dhcp,squid,cron,sshd
bind_policy soft
scope one
nss_base_passwd         ou=Computers,dc={their.domain},dc=co,dc=uk


/etc/openldap/ldap.conf
Code:
BASE         dc={their.domain},dc=co,dc=uk
URI          ldap://localhost:636/
TLS_REQCERT  allow


All barring the names and domains I have exactly the same config on others... its just that this one doesnt work. 8O
_________________
Tua mater tam antiqua ut linguam latinam loquatur

Linux User: #405647
Back to top
View user's profile Send private message
nativemad
Developer
Developer


Joined: 30 Aug 2004
Posts: 918
Location: Switzerland

PostPosted: Thu Dec 18, 2008 7:09 am    Post subject: Reply with quote

Are you sure that you've got exactly the same on the others? Perhaps different versions of packages could also make a diff...
The only thing which is obviously wrong is in /etc/openldap/ldap.conf the uri... shouldn't it be ldaps://...?? -but i guess (from the logs seen) that its correct...<>>> slap_listener(ldaps://)>

I would try to find out if the problem resides on slapd or pam/nss... You said that you have other (working) machines... What happens, if you point nss to another box's slapd? Or vice versa?

btw: maybe you can see more relevant debugging stuff, if you place a "-d 256" in the "OPTS" in /etc/conf.d/slapd and restart the service... (is this file correct??? -i almost forgot about it...)
_________________
Power to the people!
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum