On Wed, 2011-09-14 at 14:05 -0400, Christopher Wood wrote:
> How to best troubleshoot one particular user who cannot log in?

The information provided should already be quite helpful. The changed
usernames make things a bit more difficult though. Are you sure the uid
field is all that is different between both entries?

What version of nss-pam-ldapd are you using?

> I'm puzzled at why nslcd is failing to bind for one specific user when
> I can bind using ldapsearch for that user, and other users have no
> problem.

Apparently nslcd is confused by something.

> nslcd: [5558ec] DEBUG: ldap_simple_bind_s("uid=user1,ou=people,o=co","***") 
> (uri="ldap://")
> nslcd: [5558ec] DEBUG: failed to bind to LDAP server ldap:// 
> Invalid credentials

Are you sure this is the DN that you can bind with
(uid=user1,ou=people,o=co) using ldapsearch?

-- arthur - - --
