On Sun, May 29, 2016 at 07:02:07AM +0200, Petter Reinholdtsen wrote: > See debian-edu-config-git/cf/cf.ldapclient, it will purge it. It was > earlier believed to be unwanted on stationary machines, because they > should use the DNS info from LDAP, and because Kerberos seem to demand > that the client and server agree on DNS forward and reverse names to be > able to check passwords. After installing libnss-mds (jessie main+ws): --- a/nsswitch.conf 2016-05-29 09:46:42.312000000 +0200 +++ b/nsswitch.conf 2016-05-29 09:47:53.464000000 +0200 @@ -15,7 +15,7 @@ # shadow: compat ldap gshadow: files -hosts: files myhostname dns +hosts: files myhostname mdns4_minimal [NOTFOUND=return] dns networks: files ldap protocols: db files Not quite sure, but I suppose that dns will be used if mdns fails. Wolfgang
Attachment:
signature.asc
Description: Digital signature