SCIENTIFIC-LINUX-USERS Archives

September 2008

SCIENTIFIC-LINUX-USERS@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Condense Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Content-transfer-encoding:
7BIT
Sender:
Mailling list for Scientific Linux users worldwide <[log in to unmask]>
Subject:
From:
Chris Hunter <[log in to unmask]>
Date:
Wed, 3 Sep 2008 15:05:31 -0400
MIME-version:
1.0
Content-type:
text/plain; format=flowed; charset=ISO-8859-1
Reply-To:
Chris Hunter <[log in to unmask]>
Parts/Attachments:
text/plain (36 lines)
Based on my experience, the problem is your ldap failover config (host 
our.server.one our.server.two). Adding a failover host causes all sorts 
of bind timeout problems, we found this behaviour with SciLinux 4.x, 
CentOS and RHEL (ie. most likely orignates at padl.org and not TUV). We 
eventually removed our replicated ldap config and are looking at virtual 
servers for failover.

SciLinux 5.x ldap client uses "ldap://myldapserver" URI syntax instead 
of older "host myldapserver" keyword.

> Hello again.
> Thanks...
> 
> Here is:  cat /etc/ldap.conf | egrep -v "^#|^$"
> 
> host our.server.one our.server.two
> base o=AAAA,c=BBBB
> timelimit 120
> bind_timelimit 120
> bind_policy soft
> idle_timelimit 3600
> nss_initgroups_ignoreusers 
> root,ldap,named,avahi,haldaemon,dbus,radvd,tomcat,radiusd,news,mailman
> ssl no
> tls_cacertdir /etc/openldap/cacerts
> pam_password md5
> 
> 
> I will search the forum entries more carefully and
> also look into: nss_ldap-253-13.el5_2.1
> I have: yum list nss_ldap: nss_ldap.i386 253-12.el5 installed

Chris Hunter

[log in to unmask]

ATOM RSS1 RSS2