Turns out the above doesn't work out too well, as the patch depends on getpwnam_r(), a glibc function which then ends up using libnss-ldap. Tried a few things, but it didn't help the hang.
A less intrusive patch will be to have an initscript run on shutdown which edits /etc/ldap.conf based on the value of nss_initgroups_minimum_uid.
Turns out the above doesn't work out too well, as the patch depends on getpwnam_r(), a glibc function which then ends up using libnss-ldap. Tried a few things, but it didn't help the hang.
A less intrusive patch will be to have an initscript run on shutdown which edits /etc/ldap.conf based on the value of nss_initgroups_ minimum_ uid.