Comment 84 for bug 423252

Revision history for this message
Howard Chu (hyc) wrote : Re: NSS using LDAP+SSL breaks setuid applications like su and sudo

That's unfortunate, I didn't realize libpam-ldapd was so incomplete. You can still use nssov for full pam support.

Your best option for an immediate fix is still the libgcrypt patch I posted. Without that basically all Karmic and Lucid nss-ldap+SSL installations are dead in the water. As a longer term step, the design of libgcrypt and gnutls needs revisiting. Midterm, migrate everyone to nssov.