SMB/LDAP/Fedora 2/Fedora 1 - Blues

O Plameras oscarp at acay.com.au
Mon Jul 19 01:11:06 GMT 2004


Hi,

I have two LDAP Servers with similar configurations. 
The main difference is that one run Linux Fedora 1 
and the other Linux Fedora 2. With ...

smb.conf
...
passdb backend = tdbsam
...
both authenticates correctly.

But with ...
smb.conf
...
passdb backend = tdblsam:ldap://127.0.0.1
...
The Fedora 2 server 
runs correctly whilst the Fedora 1 LdAP doesn't with 
the error:

Failed to issue the StartTLS instruction: Connect error.

Following is an example of error message on Fedora 1.

[root at otr etc]# net getlocalsid
[2004/07/18 21:20:09, 0] lib/smbldap.c:smbldap_open_connection(624)
  Failed to issue the StartTLS instruction: Connect error
[2004/07/18 21:20:09, 0] lib/smbldap.c:smbldap_search_suffix(1126)
  smbldap_search_suffix: Problem during the LDAP search: 
error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake 
failure (Connect error)
SID for domain LINUX is: S-1-5-21-631164965-3065778426-3560323935
[root at otr etc]#

Following is the output from Fedora 2
[root at toshiba cpan]# net getlocalsid

SID for domain TOSHIBA is: S-1-5-21-219989572-3160090951-1547228145

[root at toshiba cpan]#

Tried many combinations of software versions including making the
ff software the same versions:

Samba-3.0.3-5
OpenLDAP-2.1.29
smbldap-tools-0.8.5-1

Configuration files are checked to be similar:

authconfig
/etc/ldap.conf
/etc/openldap/slapd.conf
/etc/nsswitch.conf
/etc/samba/smb.conf


Can someone tell what and where I should be looking for ? Thanks.

O Plameras




More information about the samba-technical mailing list