IBM Support

IJ46694: LDAP USER LOGINS STOP WORKING APPLIES TO AIX 7200-05

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available.

Notify me when this APAR changes.

 

APAR status

  • Closed as program error.

Error description

  • **************************************************************
    * USERS AFFECTED:
    * Systems running the AIX 7200-05-06 Technology Level or
    * VIOS 3.1.4.x with any of the following filesets at or
    * between the given levels:
    * MIN          MAX          FILESET
    * 7.2.5.201    7.2.5.201    bos.rte.security
      **************************************************************
    * ERROR DESCRIPTION:
    * When reconnecting to an LDAP server, AIX and VIOS LPARs using
    * LDAP authentication for users can experience an issue where
    * the LDAP client daemon becomes unresponsive until it is
    * restarted. This unresponsiveness can result in LDAP
    * authenticated users being unable to login or existing LDAP
    * connections to stop working.
    *
    * After applying the fix, the secldapclntd daemon must be
    * restarted on the LDAP client with:
    * /usr/sbin/restart-secldapclntd
    *
    * Note that restarting the secldapclntd daemon without the fix
    * will also temporarily resolve the issue, but a fix is needed
    * on the LDAP client to avoid the issue reoccurring when
    * reconnecting to an LDAP server.
      **************************************************************
    * RECOMMENDATION:
    * Install APAR IJ46694.
    * Prior to fix availability, an interim fix is available from
    * https://aix.software.ibm.com/aix/ifixes/ij46694/
    * Installation of the ifix does not require a reboot.
      **************************************************************
    .
    PROBLEM_SUMMARY
      **************************************************************
    * USERS AFFECTED:
    * Systems running the AIX 7200-05-06 Technology Level or
    * VIOS 3.1.4.x with any of the following filesets at or
    * between the given levels:
    * MIN          MAX          FILESET
    * 7.2.5.201    7.2.5.201    bos.rte.security
      **************************************************************
    * ERROR DESCRIPTION:
    * When reconnecting to an LDAP server, AIX and VIOS LPARs using
    * LDAP authentication for users can experience an issue where
    * the LDAP client daemon becomes unresponsive until it is
    * restarted. This unresponsiveness can result in LDAP
    * authenticated users being unable to login or existing LDAP
    * connections to stop working.
    *
    * After applying the fix, the secldapclntd daemon must be
    * restarted on the LDAP client with:
    * /usr/sbin/restart-secldapclntd
    *
    * Note that restarting the secldapclntd daemon without the fix
    * will also temporarily resolve the issue, but a fix is needed
    * on the LDAP client to avoid the issue reoccurring when
    * reconnecting to an LDAP server.
      **************************************************************
    * RECOMMENDATION:
    * Install APAR IJ46694.
    * Prior to fix availability, an interim fix is available from
    * https://aix.software.ibm.com/aix/ifixes/ij46694/
    * Installation of the ifix does not require a reboot.
      **************************************************************
    

Local fix

  • LOCAL FIX:
    To resolve the issue temporarily, the secldapclntd daemon
    can be restarted on the LDAP client with:
    /usr/sbin/restart-secldapclntd
    

Problem summary

  •   **************************************************************
    * USERS AFFECTED:
    * Systems running the AIX 7200-05-06 Technology Level or
    * VIOS 3.1.4.x with any of the following filesets at or
    * between the given levels:
    * MIN          MAX          FILESET
    * 7.2.5.201    7.2.5.201    bos.rte.security
      **************************************************************
    * ERROR DESCRIPTION:
    * When reconnecting to an LDAP server, AIX and VIOS LPARs using
    * LDAP authentication for users can experience an issue where
    * the LDAP client daemon becomes unresponsive until it is
    * restarted. This unresponsiveness can result in LDAP
    * authenticated users being unable to login or existing LDAP
    * connections to stop working.
    *
    * After applying the fix, the secldapclntd daemon must be
    * restarted on the LDAP client with:
    * /usr/sbin/restart-secldapclntd
    *
    * Note that restarting the secldapclntd daemon without the fix
    * will also temporarily resolve the issue, but a fix is needed
    * on the LDAP client to avoid the issue reoccurring when
    * reconnecting to an LDAP server.
      **************************************************************
    * RECOMMENDATION:
    * Install APAR IJ46694.
    * Prior to fix availability, an interim fix is available from
    * https://aix.software.ibm.com/aix/ifixes/ij46694/
    * Installation of the ifix does not require a reboot.
      **************************************************************
    

Problem conclusion

  • During reconnect, we will correctly unbind from the old
    "saveld" instead of the "newld" from the new ldap connection.
    

Temporary fix

  •   *********
      * HIPER *
      *********
    

Comments

  • 7100-05 - use AIX APAR IJ45944
    7200-05 - use AIX APAR IJ46694
    7300-00 - use AIX APAR IJ44365
    7300-02 - use AIX APAR IJ47014
    

APAR Information

  • APAR number

    IJ46694

  • Reported component name

    AIX V7.2

  • Reported component ID

    5765CD200

  • Reported release

    720

  • Status

    CLOSED PER

  • HIPER

    YesHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2023-05-05

  • Closed date

    2023-05-23

  • Last modified date

    2024-01-12

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    IJ46727 IJ47014

Fix information

  • Fixed component name

    AIX V7.2

  • Fixed component ID

    5765CD200

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SG11S","label":"AIX 7.2 HIPERS- APARs and Fixes"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"720","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
12 January 2024