Maintenance

  • Home
  • Log in
  • « Lab machines - things to do
  • Using the TV workstation for Skype conferencing »

LDAP tuning on lab machines

Posted by gregster on 04 Feb 2014 in Labs, Activity log, Documentation

I've noticed some auth.log entries that suggest that lab machines are constantly connected to the ldap server and other entries that suggest that there is a problem with the apparmor configuration (entries that include apparmor=DENIED and refer to mkdor and telepathy). I believe I've sorted it out, though.

In the first case I've discovered that nslcd DOES stay connected to the server. So, I've added a line to /etc/nslcd.conf that says:

idle_timelimit 60

which should close the ldap connection after 60 seconds. There are other timeouts in the same class that I may need to use, but this looks like the best first choice.

In the second case, there are 'tunables' in apparmor that should be adjusted in cases like ours - specifically, using non-standard home directory locations. In the file '/etc/apparmor.d/tunables/home' I've edited the line that looks like this:

@{HOMEDIRS}=/home/

to look like this:

It appears that both problems have gone away, at least so far. Fingers croseed.

@{HOMEDIRS}=/home/ /home/netlink/

refs:
https://wiki.ubuntu.com/DebuggingApparmor#Adjusting_Tunables
http://arthurdejong.org/nss-pam-ldapd/nslcd.conf.5

This entry was posted by Greg and filed under Labs, Activity log, Documentation.

Maintenance

This blog is the location for all work involving software and hardware maintenance, updates, installs, etc., both routine and urgent.
  • Home
  • Recently
  • Archives
  • Categories

Search

Categories

  • All
  • Announcements
  • Hit by a bus
  • Labs
    • Activity log
    • Documentation
  • Notes
  • R & D
    • Activity log
    • Documentation
  • Servers
    • Activity log
    • Documentation
  • Tasks

All blogs

  • Academic
  • AdaptiveDB
  • Admin
  • Announcements
  • CanMys
  • Cascade
  • CGWP
  • ColDesp
  • Depts
  • DVPP
  • Endings
  • HCMC Blogs
  • Landscapes
  • LEMDO
  • Linguistics
  • Maint
  • LondonMap
  • Mariage
  • MoM
  • Moses
  • Pro-D
  • Projects
  • ScanCan
  • HumsSites
  • Wendat

This collection ©2022 by admin • Help • Web Site Engine