----been there, done that...add to bottom of /etc/ldap.conftimelimit 30bind_timelimit 30 bind_policy softnss_initgroups_ignoreusers root,ldapCraig