Package: nslcd
Version: 0.8.10-4
Severity: serious
Justification: changes to configuration files must be preserved during a 
package upgrade

It seems that a combination of #661872, #671464, and/or #689296 is back again
with version 0.8.10-4.

After upgrading nslcd today, my system stopped recognizing my username:

Setting up nslcd (0.8.10-4) ...
[ ok ] Restarting LDAP connection daemon: nslcd.
Setting up libnss-ldapd:amd64 (0.8.10-4) ...
Setting up libpam-ldapd:amd64 (0.8.10-4) ...
Setting up tzdata-java (2012j-1) ...
getpwuid() can't identify your account!
aschuring@murid:~$ id
uid=10000 gid=10000 
groups=24(cdrom),29(audio),44(video),46(plugdev),60(games),100(users),107(fuse),9000,9001,10000,10002

(note the absence of name resolution for non-local items)


Digging into it was complicated by the fact that ssh told me to go away because
I didn't exist, but syslog contained these lines:
Dec 20 21:52:43 murid nslcd[4034]: [7b23c6] <group/member="root"> 
ldap_start_tls_s() failed (uri=ldap://gnome.loos.site): Connect error: (unknown 
error code)
Dec 20 21:52:43 murid nslcd[4034]: [7b23c6] <group/member="root"> 
ldap_start_tls_s() failed (uri=ldap://genie.loos.site): Connect error: (unknown 
error code)

Which was caused by the removal of the line

tls_cacertfile /etc/ssl/certs/loos.site.pem

from nslcd.conf on upgrade.


Regards,
Arno


-- System Information:
Debian Release: wheezy/sid
  APT prefers testing
  APT policy: (990, 'testing'), (900, 'stable'), (300, 'unstable'), (200, 
'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.2.0-4-rt-amd64 (SMP w/2 CPU cores; PREEMPT)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages nslcd depends on:
ii  adduser                3.113+nmu3
ii  debconf [debconf-2.0]  1.5.46
ii  libc6                  2.13-37
ii  libgssapi-krb5-2       1.10.1+dfsg-3
ii  libldap-2.4-2          2.4.31-1

Versions of packages nslcd recommends:
ii  bind9-host [host]           1:9.8.1.dfsg.P1-4.4
ii  ldap-utils                  2.4.31-1
ii  libnss-ldapd [libnss-ldap]  0.8.10-4
ii  libpam-krb5                 4.6-1
ii  libpam-ldapd [libpam-ldap]  0.8.10-4
pn  nscd                        <none>

Versions of packages nslcd suggests:
pn  kstart  <none>

-- debconf information:
  nslcd/ldap-sasl-realm:
* nslcd/ldap-starttls: true
  nslcd/ldap-sasl-krb5-ccname: /var/run/nslcd/nslcd.tkt
* nslcd/ldap-auth-type: none
* nslcd/ldap-reqcert: try
* nslcd/ldap-uris: ldap://gnome.loos.site ldap://genie.loos.site
  nslcd/ldap-sasl-secprops:
  nslcd/ldap-binddn:
  nslcd/ldap-sasl-authcid:
  nslcd/ldap-sasl-mech:
* nslcd/ldap-base: dc=loos,dc=site
  nslcd/ldap-sasl-authzid:


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to