On Wed, 25 May 2016, Gerrit Kühn wrote:
However, everything requiring my to enter a password appears to fail with some error message like this:

May 25 11:04:28 nslcd[64168]: [d9b7c3] <authc="gekueh"> 
uid=gekueh,cn=users,dc=aei,dc=mpg,dc=de: lookup failed: Invalid credentials

This means that the LDAP authentication step failed. You can run nslcd in debug mode for more details but one relatively common thing is that after an LDAP BIND operation (where the password is checked) nslcd performs a search operation to check if the BIND operation actually succeeded. There are (were) some LDAP servers that in some cases don't give an error on BIND.

The easiest solution is for your LDAP server to allow your users to search for their own entry.

There was some work under way to add a configuration option to allow skipping this extra search but I've been quite busy with other stuff the last few months so I'm afraid there is not much progress there.

