Re: ldap.conf must be world readable for nss_ldap ?

On Thu, Sep 13, benning Markus wrote:

> I have a problem with nss_ldap.
> nss_ldap requires /etc/ldap.conf to be world readable
> but when it's world readable everyone can read the
> binddn and the bindpw in it.

Do not use bindpw and binddn with nss_ldap.
Better use a combination of pam_ldap and nss_ldap.
> I need the bindpw to be only readable by the root user.
> I tryed it with a ldap.conf with 600 permissions and
> nscd running as root, but it did not work.

Not all apps that MUST read ldap.conf run as root.

