Steve Langasek vorlon at debian.org
Tue Mar 6 03:15:30 CET 2007

On Mon, Mar 05, 2007 at 01:49:02PM +0100, Mgr. Peter Tuharsky wrote:

> >Are there any log messages when the smbd dies?

> I haven't found any. I'll try it again.

That's unusual; even on a segfault, smbd should throw a stack trace in the

> >And all of these other clients are configured to use starttls?

> AFAIK, no. I haven't found TLS startup in libnss-ldap.conf or pam_ldap.conf

Ok, then it's not much of a comparison.

> >E.g., an /etc/ldap/ldap.conf on another system I know uses starttls has 
> >this
> >line:

> >  TLS_CACERT /etc/ldap/cacert.pem

> On server, yes, there is such a line.


> >Do you have a similar configuration ensuring the integrity of the SSL
> >connection?  (It sounds like you must, if other clients connect
> >successfully, but I just want to be sure.)

> How could I prove it?

The above is what I was looking for.

> >And if you connect to the LDAP server using ldapsearch -ZZ -h 
> >vedko6.misbb.sk,
> >does it connect successfully?

> I'll try.

This is probably going to be the best test of what's happening.

