> Can't contact LDAP server - ошибка явно говорит о проблеме конекта, например
> мешает firewallЕсли что-то и не пускает, то только не фаервол. Вся проблема в настройке клиента, а именно nss_ldap. Конфиг приведён выше. Только дело явно не в конфиге. (.... но в /dev/hands видимо....) какие есть методы для тестирования и настройки nss_ldap?
Вот что вижу ч-з tcpdump
ssh 192.168.0.4 -l root
06:37:25.522640 IP (tos 0x0, ttl 128, id 2068, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1044 > dn.smbdomain.local.ssh: Flags [.], cksum 0xad42 (correct), seq 450067054, ack 2079354299, win 65059, length 0
06:37:25.522957 IP (tos 0x0, ttl 128, id 2069, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1044 > dn.smbdomain.local.ssh: Flags [.], cksum 0xad42 (correct), seq 0, ack 169, win 64891, length 0
06:37:27.717213 IP (tos 0x0, ttl 128, id 2070, offset 0, flags [DF], proto TCP (6), length 92)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [P.], seq 632206127:632206179, ack 915718555, win 64963, length 52
06:37:27.911334 IP (tos 0x0, ttl 128, id 2071, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [.], cksum 0x5b4f (correct), seq 52, ack 53, win 64911, length 0
06:37:28.213036 IP (tos 0x0, ttl 128, id 2072, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [.], cksum 0x5b4f (correct), seq 52, ack 105, win 64859, length 0
06:37:29.606762 IP (tos 0x0, ttl 128, id 2073, offset 0, flags [DF], proto TCP (6), length 92)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [P.], seq 52:104, ack 105, win 64859, length 52
06:37:29.720451 IP (tos 0x0, ttl 128, id 2074, offset 0, flags [DF], proto TCP (6), length 92)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [P.], seq 104:156, ack 157, win 64807, length 52
06:37:29.822459 IP (tos 0x0, ttl 128, id 2075, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [.], cksum 0x5ae7 (correct), seq 156, ack 209, win 64755, length 0
06:37:29.830981 IP (tos 0x0, ttl 128, id 2076, offset 0, flags [DF], proto TCP (6), length 92)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [P.], seq 156:208, ack 209, win 64755, length 52
06:37:30.023623 IP (tos 0x0, ttl 128, id 2077, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [.], cksum 0x5ab3 (correct), seq 208, ack 261, win 64703, length 0
06:37:30.401972 IP (tos 0x0, ttl 128, id 2078, offset 0, flags [DF], proto TCP (6), length 92)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [P.], seq 208:260, ack 261, win 64703, length 52
06:37:30.526590 IP (tos 0x0, ttl 128, id 2079, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [.], cksum 0x5a7f (correct), seq 260, ack 313, win 64651, length 0
06:37:30.663479 IP (tos 0x0, ttl 128, id 2080, offset 0, flags [DF], proto TCP (6), length 92)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [P.], seq 260:312, ack 313, win 64651, length 52
06:37:30.828339 IP (tos 0x0, ttl 128, id 2081, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [.], cksum 0x5a4b (correct), seq 312, ack 365, win 64599, length 0
06:37:30.879434 IP (tos 0x0, ttl 128, id 2082, offset 0, flags [DF], proto TCP (6), length 92)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [P.], seq 312:364, ack 365, win 64599, length 52
06:37:31.029513 IP (tos 0x0, ttl 128, id 2083, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [.], cksum 0x5a17 (correct), seq 364, ack 417, win 64547, length 0
06:37:31.432483 IP (tos 0x0, ttl 128, id 2084, offset 0, flags [DF], proto TCP (6), length 92)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [P.], seq 364:416, ack 417, win 64547, length 52
06:37:31.633083 IP (tos 0x0, ttl 128, id 2085, offset 0, flags [DF], proto TCP (6), length 40)
sim.smbdomain.local.1043 > dn.smbdomain.local.ssh: Flags [.], cksum 0x59e3 (correct), seq 416, ack 469, win 64495, length 0
06:37:31.886260 IP (tos 0x0, ttl 128, id 2086, offset 0, flags [DF], proto TCP (6), length 92)
как видим, всё только в одну сторону.
И телнет:
telnet> auth status
Authentication enabled
KERBEROS_V5: enabled
SRA: enabled
telnet> auth enable SRA