[33375] in Kerberos
Re: Inittab launching K5start too soon
daemon@ATHENA.MIT.EDU (Jaap Winius)
Thu May 12 09:16:42 2011
Message-ID: <20110512151631.13951cfhq086zidc@bitis.umrk.nl>
Date: Thu, 12 May 2011 15:16:31 +0200
From: Jaap Winius <jwinius@umrk.nl>
To: kerberos@mit.edu
In-Reply-To: <8739kkvjnw.fsf@windlord.stanford.edu>
MIME-Version: 1.0
Content-Disposition: inline
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Quoting Russ Allbery <rra@stanford.edu>:
Hi Russ!
> Are you only using k5start to support libnss-ldap?
Yes...
> If so, one option would be to switch to libnss-ldapd (which I think
> is a superior model anyway) and then modify its init script to run
> the daemon under k5start. Then you wouldn't need the inittab entry.
Excellent! The nslcd package gets installed along with libnss-ldapd,
the /etc/libnss-dap.conf file is no longer needed and all I had to do
is make some changes to /etc/nslcd.conf and /etc/default/nslcd (which
already contains hashed-out settings for k5start).
> If you also are using those credentials for other things, such as
> NFS, then it's not so simple.
Not that I care too much about that right now, but how so?
Cheers,
Jaap
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos