local users when ldap is down? (was: Re: libuser's LDAP support (was Re: LDAP Performance))

Jos Vos jos at xos.nl
Thu Aug 7 07:44:56 UTC 2003


On Wed, Aug 06, 2003 at 06:11:23PM -0700, Gordon Messmer wrote:

> No, they haven't.  Edit /etc/pam.d/system-auth and change this line:
> 
> account     required      /lib/security/$ISA/pam_unix.so
> 
> It should read:
> 
> account     sufficient    /lib/security/$ISA/pam_unix.so

Hmm... I did something else (on RH8), which might not be the right
way: I edited the "account [default=bad ...] ... pam_ldap.so line
to the following:

  account     [default=bad success=ok user_unknown=ignore service_err=ignore system_err=ignore authinfo_unavail=ignore] /lib/security/pam_ldap.so

-- 
--    Jos Vos <jos at xos.nl>
--    X/OS Experts in Open Systems BV   |   Phone: +31 20 6938364
--    Amsterdam, The Netherlands        |     Fax: +31 20 6948204





More information about the fedora-test-list mailing list