Re: problem with nss_ldap

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Hartmut Brandt
Date: Saturday, March 7, 2009 - 1:53 pm

tmclaugh@sdf.lonestar.org wrote:

How will gss allow you to go without a host ticket? Somehow the host 
needs to bind to the AD, right?

In any case I rebuilt the two libraries linking them agains libgssapi 
and I can at least log in again. Sendmail dies with signal 11 and after 
I removed the link from /tmp/krb5cc_0 to the host creds cron also dies 
with signal 11. This is somewhat hard to debug, because it doesn't dump 
core.

Sudo does not work and gives:

Mar  7 21:23:57 knopdnsimu13f sudo: GSSAPI Error:  Miscellaneous failure 
(see text) (unknown mech-code 2529638944 for mech unknown)
Mar  7 21:23:57 knopdnsimu13f sudo: GSSAPI Error:  Miscellaneous failure 
(see text)¥¥¥¥¥¥¥¥¥¥¥¥¥¥¥ (Ticket expired¥¥libdefaults)
Mar  7 21:24:27 knopdnsimu13f last message repeated 8 times
Mar  7 21:24:32 knopdnsimu13f sshd[50888]: error: PAM: authentication 
error for root from XXXX.dlr.de
Mar  7 21:25:00 knopdnsimu13f sudo: GSSAPI Error:  Miscellaneous failure 
(see text)¥¥¥¥¥¥¥¥¥¥¥¥¥¥¥ (Ticket expired¥¥libdefaults)
Mar  7 21:25:00 knopdnsimu13f sudo: GSSAPI Error:  Miscellaneous failure 
(see text)¥¥¥¥¥¥¥¥¥¥¥¥¥¥¥ (Ticket expired¥¥libdefaults)
Mar  7 21:26:05 knopdnsimu13f last message repeated 2 times
Mar  7 21:26:05 knopdnsimu13f sudo: nss_ldap: could not search LDAP 
server - Server is unavailable

The host ticket is fine (I checked) and the server is, of course, 
reachable and up. None of the tickets is expired.

I must admit that I'm lost in this twisted maze of libraries: gss, 
nss_ldap, sasl. I can't even grasp how they layer on each other. But if 
you come up with patches I'm ready to try them.

Did I forget to mention that this worked fine for one or two years until 
I decided to update my system (this was when I sent the original mail)?

harti

_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
problem with nss_ldap, Hartmut.Brandt, (Sun Jan 18, 12:39 pm)
Re: problem with nss_ldap, Harti Brandt, (Fri Jan 23, 11:02 am)
Re: problem with nss_ldap, Tom McLaughlin, (Thu Feb 26, 6:39 am)
Re: problem with nss_ldap, Tom McLaughlin, (Sat Feb 28, 11:15 am)
Re: problem with nss_ldap, Hartmut Brandt, (Fri Mar 6, 1:39 pm)
Re: problem with nss_ldap, Kostik Belousov, (Fri Mar 6, 2:16 pm)
Re: problem with nss_ldap, tmclaugh, (Fri Mar 6, 2:33 pm)
Re: problem with nss_ldap, tmclaugh, (Fri Mar 6, 3:00 pm)
Re: problem with nss_ldap, Kostik Belousov, (Fri Mar 6, 3:24 pm)
Re: problem with nss_ldap, Hartmut Brandt, (Sat Mar 7, 1:53 pm)
Re: problem with nss_ldap, Tom McLaughlin, (Sat Mar 7, 2:18 pm)
Re: problem with nss_ldap, Doug Rabson, (Tue Mar 10, 3:38 am)
Re: problem with nss_ldap, Kostik Belousov, (Tue Mar 10, 4:41 am)
Re: problem with nss_ldap, Hartmut Brandt, (Tue Mar 10, 5:39 am)
Re: problem with nss_ldap, Doug Rabson, (Tue Mar 10, 5:47 am)
Re: problem with nss_ldap, Doug Rabson, (Tue Mar 10, 5:52 am)
Re: problem with nss_ldap, Tom McLaughlin, (Tue Mar 10, 9:58 am)
Re: problem with nss_ldap, Hartmut Brandt, (Thu Mar 12, 1:31 am)
Re: problem with nss_ldap, Tom McLaughlin, (Sun Mar 15, 4:07 pm)
Re: problem with nss_ldap, Hartmut Brandt, (Mon Mar 16, 1:56 am)
Re: problem with nss_ldap, Harti Brandt, (Mon Mar 16, 4:04 am)
Re: problem with nss_ldap, O. Hartmann, (Mon Mar 16, 4:10 am)
Re: problem with nss_ldap, tmclaugh, (Mon Mar 16, 7:13 am)
Re: problem with nss_ldap, Tom McLaughlin, (Sun Apr 5, 2:41 pm)
Re: problem with nss_ldap, Hartmut Brandt, (Mon Apr 6, 12:54 am)