lists.arthurdejong.org
RSS feed

Re: [nssldap] lookup delay using nss_ldap with Active Directory

[Date Prev][Date Next] [Thread Prev][Thread Next]

Re: [nssldap] lookup delay using nss_ldap with Active Directory



Hi Jonathan,

>> Are you also using nscd? We have run into issues with nscd timing out,
>> then
>> the command like id will try the ldapsearch itself.
> 
> No, nscd is not being used anywhere in my environment, at least as far
> as I can
> tell:
> 
> $ /etc/init.d/nscd status
> nscd is stopped

You should definitly give nscd a try. Caching is essential. It makes a big
difference.

> Is it possible that it is an indexing issue with Active Directory? Have
> other people had to make modifications to the Active Directory Schema to
> index additional attributes, such as "uid", "member" or "objectclass"?

An index on uid, member, uidNumber, gidNumber would help.

Sincerly,
Klaus

Attachment: klaus_steinberger.vcf
Description: Vcard