есть несколько серверов:1.PDC + LDAP
2.Standalone
3.Standalone
Как орагнизовать схему при которой можно было бы 2 и 3 серверам брать учетные записи из ЛДАП 1 сервера.
nss и pam 2 и 3 сервера подключить к ЛДАП удалось, вывод getent passwd дает положительные результаты. Однако при запуске этих (2 и 3) серверов в лДАП каталоге создается domainname=server2 и domainname=server3 со сыоими личными SID.
попытка net setlocalsid доменного контроллера ничего не дает, самба запускается но пользователей не может вытащить.
самба на PDC и Standalone Server практически идентичны.
в логах slapd ошибка:
Apr 19 04:37:06 ns2 slapd[3033]: 27r
Apr 19 04:37:06 ns2 slapd[3033]:
Apr 19 04:37:06 ns2 slapd[3033]: daemon: read active on 27
Apr 19 04:37:06 ns2 slapd[3033]: connection_get(27)
Apr 19 04:37:06 ns2 slapd[3033]: connection_get(27): got connid=381
Apr 19 04:37:06 ns2 slapd[3033]: connection_read(27): checking for input on id=381
Apr 19 04:37:06 ns2 slapd[3033]: ber_get_next on fd 27 failed errno=11 (Resource temporarily unavailable)
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=6 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=7 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=8 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: activity on 1 descriptor
Apr 19 04:37:06 ns2 slapd[3033]: daemon: activity on:
Apr 19 04:37:06 ns2 slapd[3033]:
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=6 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=7 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=8 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: do_search
Apr 19 04:37:06 ns2 slapd[3033]: >>> dnPrettyNormal: <"ou=Group","dc=ns2,dc=aiylbank">
Apr 19 04:37:06 ns2 slapd[3033]: do_search: invalid dn ("ou=Group","dc=ns2,dc=aiylbank")
Apr 19 04:37:06 ns2 slapd[3033]: send_ldap_result: conn=381 op=15 p=3
Apr 19 04:37:06 ns2 slapd[3033]: send_ldap_result: err=34 matched="" text="invalid DN"
Apr 19 04:37:06 ns2 slapd[3033]: send_ldap_response: msgid=16 tag=101 err=34
Apr 19 04:37:06 ns2 slapd[3033]: conn=381 op=15 SEARCH RESULT tag=101 err=34 nentries=0 text=invalid DN
Apr 19 04:37:06 ns2 slapd[3033]: daemon: activity on 1 descriptor
Apr 19 04:37:06 ns2 slapd[3033]: daemon: activity on:
Apr 19 04:37:06 ns2 slapd[3033]: 27r
Apr 19 04:37:06 ns2 slapd[3033]:
Apr 19 04:37:06 ns2 slapd[3033]: daemon: read active on 27
Apr 19 04:37:06 ns2 slapd[3033]: connection_get(27)
Apr 19 04:37:06 ns2 slapd[3033]: connection_get(27): got connid=381
Apr 19 04:37:06 ns2 slapd[3033]: connection_read(27): checking for input on id=381
Apr 19 04:37:06 ns2 slapd[3033]: ber_get_next on fd 27 failed errno=0 (Success)
Apr 19 04:37:06 ns2 slapd[3033]: connection_read(27): input error=-2 id=381, closing.
Apr 19 04:37:06 ns2 slapd[3033]: connection_closing: readying conn=381 sd=27 for close
Apr 19 04:37:06 ns2 slapd[3033]: connection_close: conn=381 sd=-1
Apr 19 04:37:06 ns2 slapd[3033]: daemon: removing 27
Apr 19 04:37:06 ns2 slapd[3033]: conn=381 fd=27 closed (connection lost)
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=6 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=7 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=8 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: activity on 1 descriptor
Apr 19 04:37:06 ns2 slapd[3033]: daemon: activity on:
Apr 19 04:37:06 ns2 slapd[3033]:
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=6 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=7 active_threads=0 tvp=NULL
Apr 19 04:37:06 ns2 slapd[3033]: daemon: epoll: listen=8 active_threads=0 tvp=NULL