13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5. No password is defined for the user.When you use ldapaddent, you must use the -p option to ensure that thepassword is added to the user entry. If you use ldapaddent without the -poption, the user’s password is not stored in the directory unless you also add the/etc/shadow file by using ldapaddent.6. No <strong>LDAP</strong> servers are reachable.Check the status of the servers.# /usr/lib/ldap/ldap_cachemgr -g7. pam.conf is configured incorrectly.8. The user is not defined in the <strong>LDAP</strong> namespace.9. NS_<strong>LDAP</strong>_CREDENTIAL_LEVEL is set to anonymous for pam_unix, <strong>and</strong>userPassword is not available to anonymous users.10. The password is not stored in crypt format.11. If pam_ldap is configured to support account management, login failure could bethe result of one of the following:■■■■The user’s password has expired.The user’s account is locked out due to too many failed login attempts.The user’s account has been deactivated by the administrator.The user tried to log in using a nonpassword-based program, such as rsh,rlogin, ssh, orsftp.Lookup Too SlowThe <strong>LDAP</strong> database relies on indexes to improve search performance. A majorperformance degradation occurs when indexes are improperly configured. Thedocumentation includes a common set of attributes that should be indexed. You canalso add your own indexes to improve performance at your site.ldapclient Cannot Bind to Serverldapclient failed to initialize the client when using the init option with theprofileName attribute specified. Possible reasons for failure include the following:1. The incorrect domain name was specified on the comm<strong>and</strong> line.2. The nisDomain attribute is not set in the DIT to represent the entry point for thespecified client domain.3. Access control information is not set up properly on the server, thus disallowinganonymous search in the <strong>LDAP</strong> database.4. An incorrect server address passed to the ldapclient comm<strong>and</strong>. Useldapsearch to verify the server address.Chapter 13 • <strong>LDAP</strong> Troubleshooting (Reference) 193

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!