Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 20 Jun 2008 10:27:51 +0200
From:      Uwe Laverenz <uwe@laverenz.de>
To:        Eric F Crist <ecrist@secure-computing.net>
Cc:        User Questions <freebsd-questions@freebsd.org>
Subject:   Re: LDAP Authentication questions...
Message-ID:  <20080620082751.GA16072@laverenz.de>
In-Reply-To: <C1A0FD74-80D7-4C2E-BB9C-629F50C219DD@secure-computing.net>
References:  <C1A0FD74-80D7-4C2E-BB9C-629F50C219DD@secure-computing.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, Jun 18, 2008 at 02:18:17PM -0500, Eric F Crist wrote:

> configured services like ssh.  Now, shouldn't it eventually fail over  
> to my secondary LDAP server?  I've even tried adding timelimit 10 to  
> the ldap.conf file to set a timeout, to no avail.

IIRC you have to change the parameter "bind_timelimit" to get what you
want. The default is 30 seconds, which is too high. This is documented
in the pam_ldap manpage.

Uwe




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20080620082751.GA16072>