Bug 697593 - service lookup not conforming nsswitch.conf description
Summary: service lookup not conforming nsswitch.conf description
Keywords:
Status: CLOSED INSUFFICIENT_DATA
Alias: None
Product: Fedora
Classification: Fedora
Component: glibc
Version: 14
Hardware: i686
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Jeff Law
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-04-18 17:18 UTC by Frantisek Hanzlik
Modified: 2016-11-24 15:47 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-03-05 19:42:01 UTC
Type: ---


Attachments (Terms of Use)

Description Frantisek Hanzlik 2011-04-18 17:18:38 UTC
Description of problem:
System configured for searching and authenticating users and groups in LDAP db ignore search order for methods listed in /etc/nsswitch.conf. When nsswitch.conf specify:

passwd:     files ldap
shadow:     files ldap
group:      files ldap

then after successful finding a item in files it should not continue searching with other methods at right of matching. But appropriate glibc routines do it - thus e.g. in case when LDAP server isn't accessible, then come up strange things. E.g. due to timeouts isn't possible log in for local users (in files db) including root login.


Version-Release number of selected component (if applicable):
glibc-2.13-1.i686
(I tried it with nss_ldap-265-6.fc14.i686 and pam_ldap-185-5.fc14.i686)

How reproducible:
Always for me. When I install nss_ldap and add three lines above to nsswitch.conf, then /usr/lib/libnss_ldap-265.so is called even for users as
root and users in /etc/{passwd,shadow} - tested on login, su, passwd.
Verified with strace and setting debug level in /etc/nss_ldap.conf

Even entering action items as these:
passwd:     files [SUCCESS=return] ldap"

not help, ldap library is still called.

Comment 1 Andreas Schwab 2011-05-03 13:52:58 UTC
Please provide a test case.

Comment 2 Fedora Admin XMLRPC Client 2011-11-14 19:43:44 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 3 Jeff Law 2012-03-05 19:42:01 UTC
This has been sitting open waiting for Frantisek to provide a testcase for ~10 months.  At this point I'm going to assume it's abandoned.

Frantisek, if you can still reproduce this on F16 or the upcoming F17, please reopen this bug and work with us so that we can reproduce and ultimately fix this.


Note You need to log in before you can comment on or make changes to this bug.