nsswitch.conf [NOTFOUND=return] prevents further processing of entries when server unavailable in RHEL 5
Issue
-
In
/etc/nsswitch.confundersudoers, "[NOTFOUND=return]" causes abortion of lookup on ldap failure -
When the ldap server is unavailable, using the following rule the local files will never be consulted:
sudoers: ldap [NOTFOUND=return] files
Environment
-
Red Hat Enterprise Linux (RHEL) 5
-
nss-ldap prior to version 253-42.el5
- netgroup configured for ldap first in /etc/nsswitch.conf
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.