nslcd doesn't failover to backup server on authentication (bind)

Bug #585966 reported by Yannis Aribaud
24
This bug affects 4 people
Affects Status Importance Assigned to Milestone
nss-pam-ldapd (Debian)
Fix Released
Unknown
nss-pam-ldapd (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

This is a known bug from Debian : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577593
It seems that this bug has been fixed in the next release of libpam-ldapd.

This bug appears on Ubuntu Lucid 10.04 with libpam-ldapd 0.7.2.

If two ldap URI are provided in the /etc/nslcd.conf and that the first one is unavailable then nss lookups just failover the second URI but for any authentication nslcd tries to bind on the first URI fail and just stop there instead of trying the second URI.

So even with two well configured LDAP servers there is no authentication redundancy.

This is not really a security vulnerability but it could be considered as.
It seems to me really important to fix this bug even more for an LTS Ubuntu version used by quite a lot of servers.

Changed in nss-pam-ldapd (Debian):
status: Unknown → Fix Released
description: updated
Changed in nss-pam-ldapd (Ubuntu):
assignee: nobody → Arthur de Jong (adejong)
Arthur de Jong (adejong)
Changed in nss-pam-ldapd (Ubuntu):
assignee: Arthur de Jong (adejong) → nobody
Revision history for this message
Gunnar Thielebein (lorem-ipsum) wrote :

Will there be the new upstream package available for Lucid? Currently it's still 0.7.2!

Changed in nss-pam-ldapd (Ubuntu):
status: New → Confirmed
Revision history for this message
Arthur de Jong (adejong) wrote :

If Ubuntu wants to address this issue I can probably assist in backporting this fix to 0.7.2 if that is needed.

Revision history for this message
Craig Ayliffe (cayliffe-deactivatedaccount) wrote :

Is this ever going to be fixed in 10.04 LTS?

Or maybe a backport of a newer version ofnss-pam-ldapd?

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.