IBM Support

IJ46727: LDAP USER LOGINS STOP WORKING APPLIES TO AIX 7300-01

 

APAR status

  • Closed as program error.

Error description

  • **************************************************************
    * USERS AFFECTED:
     * Systems running the 7300-01 Technology Level with
     * any of the following filesets at or between the given levels:
     * MIN          MAX          FILESET
     * 7.3.1.1      7.3.1.1      bos.rte.security
      **************************************************************
     * ERROR DESCRIPTION:
     * When reconnecting to an LDAP server, AIX and VIOS LPARs using
     * LDAP authentication for users can experience an issue where
     * the LDAP client daemon becomes unresponsive until it is
     * restarted. This unresponsiveness can result in LDAP
     * authenticated users being unable to login or existing LDAP
     * connections to stop working.
     *
     * After applying the fix, the secldapclntd daemon must be
     * restarted on the LDAP client with:
     * /usr/sbin/restart-secldapclntd
     *
     * Note that restarting the secldapclntd daemon without the fix
     * will also temporarily resolve the issue, but a fix is needed
     * on the LDAP client to avoid the issue reoccurring when
     * reconnecting to an LDAP server.
    *
     * RECOMMENDATION:
     * Install APAR IJ46727.
     * Prior to fix availability, an interim fix is available from
     * https://aix.software.ibm.com/aix/ifixes/ij46694/
     * Installation of the ifix does not require a reboot.
    *
    .
    PROBLEM SUMMARY
      **************************************************************
     * USERS AFFECTED:
     * Systems running the 7300-01 Technology Level with
     * any of the following filesets at or between the given levels:
     * MIN          MAX          FILESET
     * 7.3.1.1      7.3.1.1      bos.rte.security
      **************************************************************
     * ERROR DESCRIPTION:
     * When reconnecting to an LDAP server, AIX and VIOS LPARs using
     * LDAP authentication for users can experience an issue where
     * the LDAP client daemon becomes unresponsive until it is
     * restarted. This unresponsiveness can result in LDAP
     * authenticated users being unable to login or existing LDAP
     * connections to stop working.
     *
     * After applying the fix, the secldapclntd daemon must be
     * restarted on the LDAP client with:
     * /usr/sbin/restart-secldapclntd
     *
     * Note that restarting the secldapclntd daemon without the fix
     * will also temporarily resolve the issue, but a fix is needed
     * on the LDAP client to avoid the issue reoccurring when
     * reconnecting to an LDAP server.
      **************************************************************
     * RECOMMENDATION:
     * Install APAR IJ46727.
     * Prior to fix availability, an interim fix is available from
     * https://aix.software.ibm.com/aix/ifixes/ij46694/
     * Installation of the ifix does not require a reboot.
      **************************************************************
    

Local fix

  • LOCAL FIX:
    To resolve the issue temporarily, the secldapclntd daemon
    can be restarted on the LDAP client with:
    /usr/sbin/restart-secldapclntd
    

Problem summary

  •   **************************************************************
     * USERS AFFECTED:
     * Systems running the 7300-01 Technology Level with
     * any of the following filesets at or between the given levels:
     * MIN          MAX          FILESET
     * 7.3.1.1      7.3.1.1      bos.rte.security
      **************************************************************
     * ERROR DESCRIPTION:
     * When reconnecting to an LDAP server, AIX and VIOS LPARs using
     * LDAP authentication for users can experience an issue where
     * the LDAP client daemon becomes unresponsive until it is
     * restarted. This unresponsiveness can result in LDAP
     * authenticated users being unable to login or existing LDAP
     * connections to stop working.
     *
     * After applying the fix, the secldapclntd daemon must be
     * restarted on the LDAP client with:
     * /usr/sbin/restart-secldapclntd
     *
     * Note that restarting the secldapclntd daemon without the fix
     * will also temporarily resolve the issue, but a fix is needed
     * on the LDAP client to avoid the issue reoccurring when
     * reconnecting to an LDAP server.
    

Problem conclusion

  • During reconnect, we will correctly unbind from the old
    "saveld" instead of the "newld" from the new ldap connection.
    

Temporary fix

  •   *********
      * HIPER *
      *********
    

Comments

APAR Information

  • APAR number

    IJ46727

  • Reported component name

    AIX V7.3

  • Reported component ID

    5765CD300

  • Reported release

    730

  • Status

    CLOSED PER

  • HIPER

    YesHIPER

  • Submitted date

    2023-05-09

  • Closed date

    2023-05-25

  • Last modified date

    2024-01-12

  • APAR is sysrouted FROM one or more of the following:

    IJ46694

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    AIX V7.3

  • Fixed component ID

    5765CD300

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SG11T","label":"AIX 7.3 HIPERS- APARs and Fixes"},"Platform":[{"code":"PF053","label":"Power Systems"}],"Version":"730","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
12 January 2024