On Wed, 2011-11-09 at 10:28 -0800, Ben Hodgens wrote:
> I'm experiencing some problems with 100+ debian 5 lenny machines
> running nss-ldapd connecting to a debian 6 (squeeze) ldap server. I'm
> using TLS and have the machines set up for system-wide pam auth via
> ldap.

Version is quite old and there were quite a few improvements to
the timeout handling in the 0.7 series (and even some further ones in
the 0.8 series), some specifically for TLS problems.

The 0.7.15 release should be stable and well-tested and is the currently
recommended version for production environments. You should be able to
build 0.7.15 for lenny without too much problems.

Hope this helps,

