Bug Fix Advisory nss_ldap bug fix update

Advisory: RHBA-2008:0231-2
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2008-05-27
Last updated on: 2008-05-27
Affected Products: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
OVAL: N/A

Details

An updated nss_ldap package that fixes various bugs is now available.

The nss_ldap package contains the nss_ldap and pam_ldap modules. The
nss_ldap module is a plug-in which allows applications to retrieve
information about users and groups from a directory server. The pam_ldap
module allows PAM-aware applications to use a directory server to verify
user passwords.

This updated package adds the following enhancements:

* when a system used a directory server for naming information, and
"nss_initgroups_ignoreusers root" was configured in "/etc/ldap.conf",
dbus-daemon-1 would hang. Running the "service messagebus start" command
did not start the service, and it did not fail, which would stop the boot
process if it was not cancelled.

* in master and slave server environments, with systems that were
configured to use a read-only directory server, if user log in attempts
were denied because their passwords had expired, and users attempted to
immediately change their passwords, the replication server returned an LDAP
referral, instructing the pam_ldap module to resissue its request to a
different server; however, the pam_ldap module failed to do so. In these
situations, an error such as the following occurred:

LDAP password information update failed: Can't contact LDAP server
Insufficient 'write' privilege to the 'userPassword' attribute of entry
[entry]

In this updated package, password changes are allowed when binding against
a slave server, which resolves this issue.

Users of nss_ldap are advised to upgrade to this updated package, which
resolves these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Desktop (v. 4)

SRPMS:
nss_ldap-226-24.el4_6.src.rpm
File outdated by:  RHSA-2008:0715
    c020b03f15462f768d4be2614609331a
 
IA-32:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
 
x86_64:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
nss_ldap-226-24.el4_6.x86_64.rpm
File outdated by:  RHSA-2008:0715
    e3fefb90a1e8c32d7c23535bccbb8e6e
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
nss_ldap-226-24.el4_6.src.rpm
File outdated by:  RHSA-2008:0715
    c020b03f15462f768d4be2614609331a
 
IA-32:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
 
IA-64:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
nss_ldap-226-24.el4_6.ia64.rpm
File outdated by:  RHSA-2008:0715
    21a5118b6faea7501764275a4ee02e2c
 
PPC:
nss_ldap-226-24.el4_6.ppc.rpm
File outdated by:  RHSA-2008:0715
    024edbd57a9fe644b61e6719f94245dd
nss_ldap-226-24.el4_6.ppc64.rpm
File outdated by:  RHSA-2008:0715
    0d3582df7d1b7c32e3126104f601ae3b
 
s390:
nss_ldap-226-24.el4_6.s390.rpm
File outdated by:  RHSA-2008:0715
    1b14ffeb91b39ec236a7d8e1db6f1f15
 
s390x:
nss_ldap-226-24.el4_6.s390.rpm
File outdated by:  RHSA-2008:0715
    1b14ffeb91b39ec236a7d8e1db6f1f15
nss_ldap-226-24.el4_6.s390x.rpm
File outdated by:  RHSA-2008:0715
    a98fdee1c2cfc7d7d73c78df6413dcaf
 
x86_64:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
nss_ldap-226-24.el4_6.x86_64.rpm
File outdated by:  RHSA-2008:0715
    e3fefb90a1e8c32d7c23535bccbb8e6e
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
nss_ldap-226-24.el4_6.src.rpm
File outdated by:  RHSA-2008:0715
    c020b03f15462f768d4be2614609331a
 
IA-32:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
 
IA-64:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
nss_ldap-226-24.el4_6.ia64.rpm
File outdated by:  RHSA-2008:0715
    21a5118b6faea7501764275a4ee02e2c
 
x86_64:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
nss_ldap-226-24.el4_6.x86_64.rpm
File outdated by:  RHSA-2008:0715
    e3fefb90a1e8c32d7c23535bccbb8e6e
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
nss_ldap-226-24.el4_6.src.rpm
File outdated by:  RHSA-2008:0715
    c020b03f15462f768d4be2614609331a
 
IA-32:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
 
IA-64:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
nss_ldap-226-24.el4_6.ia64.rpm
File outdated by:  RHSA-2008:0715
    21a5118b6faea7501764275a4ee02e2c
 
x86_64:
nss_ldap-226-24.el4_6.i386.rpm
File outdated by:  RHSA-2008:0715
    f893f2e8d4f56e85e22c35a9b4617c08
nss_ldap-226-24.el4_6.x86_64.rpm
File outdated by:  RHSA-2008:0715
    e3fefb90a1e8c32d7c23535bccbb8e6e
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

439215 - dbus-daemon-1 hangs when using the option nss_initgroups_ignoreusers in /etc/ldap.conf with the user root
439775 - [crm 1762608] nss-ldap-226-18: Insufficient 'write' privilege when changing password when using referrals



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/