Re: [exim] Exim, NSS, winbind...

Top Page
Delete this message
Reply to this message
Author: Chr. von Stuckrad
Date:  
To: exim-users
Subject: Re: [exim] Exim, NSS, winbind...
On Wed, 30 Jan 2019, Marco Gaiarin via Exim-users wrote:

> But some weeks ago i've done a general maintenance of my infrastructure, and
> i've discovered that exim refuse to deliver to some recipient because users
> are not known.
> …
> I need to do more tests, but before hitting my head on the wall, i'm asking
> here if there's some 'known' drawbacks of using exim with NSS/Winbind
> caching, or something like that.


I have not looked 'into' exim (sources), but something similar happened
here with the change to NSS. After the switch from using 'pam with ldap'
to 'pam + NSS with the same ldap', the simple line 'getent passwd'
(i.e. routines 'getpwent', 'setpwent', 'endpwent') did show *only*
the cached users!
So every program could find users 'explicitly' by asking for an uid or
user-name, but no more by 'getting all and then searching internally'.

So IF exim too does the latter, it will see only the 'once been logged in'
users (plus all the locals in /etc/passwd).

Stucki


-- 
Christoph von Stuckrad    * * | also XMPP = |Mail <stucki@???> \
Freie Universitaet Berlin |/_*| 'jabber' via|Tel(Mo.,Mi.):+49 30 838-75 459|
IT Mathematik & Informatik|\ *|stucki@jabber|  (Di,Do,Fr):+49 30 77 39 6600|
Takustr. 9 / 14195 Berlin * * |.fu-berlin.de|Fax(home):   +49 30 77 39 6601/