User already exists error when user doesn’t exist on the system » Easy as Linux
问题描述
创建本地 admin 用户时系统提示该用户已存在,但本地用户文件中找不到该用户,需要排查 NSS 目录服务是否返回了同名账户。
目标
查出原因,并解决问题
设计
无
核心技术
google,经验
猜测1: 用户创建时关联的group存在,不能创建。
|
|
发现并不存在对应用户组
猜测2: 谷歌搜到方法: easyaslinux easyaslinux
使用 getent 命令 搜索用户信息
getent is a Linux command that helps the user to get the entries in a number of important text files called databases.
|
|
发现admin用户输出的信息跟普通用户有区别
密码栏(冒号为分隔符第二个),显示的结果是* ,一般是x,表示密码存在 /etc/shadow 文件里
Lets dig into Name Service Switch library config file. 查查nss的库文件
备注: The Name Service Switch (NSS) framework was designed to let administrators specify which files or directory services to query to obtain information. \
|
|
问题找到了,nss在ldap中搜到当前用户,(sss被当成一个ldap客户端配置相关信息)
|
|
SSSD 正在运行,NSS 会通过目录服务查询用户。
机器使用目录服务进行统一身份管理,SSSD 作为客户端也返回了同名 admin 用户,导致本地创建用户发生冲突。
动手实践
卸载后这台机器信息就能新增用户了,此时发现用户密码配置变了
|
|
此时表示用户不在是一个ldap用户了,他的密码配置文件又变成了 /etc/shadow
权限相关的问题也解决了
优化
找到问题的根源,现在有三个方式解决问题
-
Remove the user from ldap server.
-
Remove the ldap reference from the /etc/nsswitch.conf file so that NSS library dont look for the user in ldap server.
-
Keep the user in the ldap as it is, but create the same user in the system! Let me explain how we do it further.
-
删除ldap中的用户
-
从 /etc/nsswitch.conf 文件中删除 ldap 引用,这样 NSS 库就不会在 ldap 服务器中查找用户。
-
保持用户在 ldap 中的原样,但在系统中创建相同的用户!让我解释一下我们如何进一步做到这一点。
很明显,最好的解决方法是第三种:
使用luseradd命令
|
|
不需要停止ipa服务,不影响权限,完美解决问题