Discussion on irc and phone resulted in the following solution: Add a new configuration option 'nss_initgroups_ignoreusers_below_uid' (or similar) and have it default to '1000'. This option will be configurable in /etc/ldap.conf. Admins can adjust this to be any valid uid.
-- libnss-ldap: calls to initgroups() causes boot to hang when using 'bind_policy hard' https://bugs.launchpad.net/bugs/155947 You received this bug notification because you are a member of Ubuntu Server Team, which is a subscriber of a duplicate bug. -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs