You are not logged in.

#1 2019-11-24 20:17:03

MilanKnizek
Member
Registered: 2005-12-13
Posts: 88

[SOLVED] systemd-networkd: regular nss lookups for root.pacsave user

Hi,

I have osixia/openldap server configured on a separate machine in docker. On local machine with Arch Linux, I got sssd working so that I can query users from the ldap server and also log in on a console.

$ getent passwd testuser1
testuser1:*:1000:501:testuser1:/home/users/testuser1:/bin/bash
$ tail -F /var/log/sssd/sssd-nss.log
(Sun Nov 24 21:06:55 2019) [sssd[nss]] [get_client_cred] (0x0080): The following failure is expected to happen in case SELinux is disabled:
SELINUX_getpeercon failed [95][Operation not supported].
Please, consider enabling SELinux in your system.
(Sun Nov 24 21:06:55 2019) [sssd[nss]] [accept_fd_handler] (0x0400): Client connected!
(Sun Nov 24 21:06:55 2019) [sssd[nss]] [sss_cmd_get_version] (0x0200): Received client version [1].
(Sun Nov 24 21:06:55 2019) [sssd[nss]] [sss_cmd_get_version] (0x0200): Offered version [1].
(Sun Nov 24 21:06:55 2019) [sssd[nss]] [nss_getby_name] (0x0400): Input name: testuser1
(Sun Nov 24 21:06:55 2019) [sssd[nss]] [cache_req_send] (0x0400): CR #93: New request 'User by name'
(Sun Nov 24 21:06:55 2019) [sssd[nss]] [cache_req_process_input] (0x0400): CR #93: Parsing input name [testuser1]
(Sun Nov 24 21:06:55 2019) [sssd[nss]] [sss_parse_name_for_domains] (0x0200): name 'testuser1' matched without domain, user is testuser1
... cut on purpose ...

However, what triggered my attention is that sssd queries the ldap server each 60 seconds as follows:

(Sun Nov 24 20:52:01 2019) [sssd[nss]] [nss_getby_name] (0x0400): Input name: root.pacsave
(Sun Nov 24 20:52:01 2019) [sssd[nss]] [cache_req_send] (0x0400): CR #38: New request 'User by name'
(Sun Nov 24 20:52:01 2019) [sssd[nss]] [cache_req_process_input] (0x0400): CR #38: Parsing input name [root.pacsave]
(Sun Nov 24 20:52:01 2019) [sssd[nss]] [sss_parse_name_for_domains] (0x0200): name 'root.pacsave' matched without domain, user is root.pacsave
... cut on purpose ...

This fails, as there is no `root.pacsave` user anywhere. Compared to `getent passwd testuser1` lookup, there is less log lines for the `root.pacsave` user before the lookup. `journalctl -f` does not show any activity.

Any idea how to find out which process causes this nss lookup? (My best guess is that this has been happening always, it is only that sssd made it visible.)

Last edited by MilanKnizek (2019-11-26 19:14:56)


--
Milan Knizek
http://knizek.net

Offline

#2 2019-11-24 20:55:21

MilanKnizek
Member
Registered: 2005-12-13
Posts: 88

Re: [SOLVED] systemd-networkd: regular nss lookups for root.pacsave user

I have increased the debug level of [nss] in /etc/sssd/sssd.conf to 10 and can say that:

(Sun Nov 24 21:22:01 2019) [sssd[nss]] [get_client_cred] (0x4000): Client creds: euid[0] egid[0] pid[856].
...

the PID 856 is:

systemd+     586  0.0  0.0  33096  8912 ?        Ss   08:48   0:00 /usr/lib/systemd/systemd-networkd
 $ cat /etc/nsswitch.conf | grep sss
passwd: compat mymachines systemd sss
group: compat mymachines systemd sss
shadow: compat sss
sudoers: files sss

--
Milan Knizek
http://knizek.net

Offline

#3 2019-11-26 12:08:41

Shadow256
Member
Registered: 2009-05-14
Posts: 18

Re: [SOLVED] systemd-networkd: regular nss lookups for root.pacsave user

Hi,

did you check if there is a file named root.pacsave? I am thinking about e.g. cron.

Regards

Offline

#4 2019-11-26 19:14:22

MilanKnizek
Member
Registered: 2005-12-13
Posts: 88

Re: [SOLVED] systemd-networkd: regular nss lookups for root.pacsave user

Hi,

A good hit!

There was `root.pacsave` in /var/../cron folder. I deleted that one already before opening this forum topic, however I am not sure now if I also restarted cronie and/or systemd-networkd.

Nevertheless, after reboot today the problem is solved.

Thanks.


--
Milan Knizek
http://knizek.net

Offline

Board footer

Powered by FluxBB