Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 65130 - oidentd can't lookup masqueraded connections with
Summary: oidentd can't lookup masqueraded connections with
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Christoph Mende (RETIRED)
Depends on:
Reported: 2004-09-23 13:20 UTC by James Slater
Modified: 2007-06-03 17:16 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description James Slater 2004-09-23 13:20:09 UTC
After upgrading to kernel, oidentd can no longer look up the details of masqueraded connections.

The recent change:

o [NETFILTER]: Change permissions of /proc/net/ip_conntrack to 0440

From 2.6.7 to 2.6.8 seems to be responsible. Changing to GROUP="root" in /etc/conf.d/oidentd works around the problem, as does changing the permissions on the ip_conntrack file. I'm unsure of what the best solution is though.

Reproducible: Always
Steps to Reproduce:
Comment 1 Christoph Mende (RETIRED) gentoo-dev 2007-05-31 22:39:02 UTC
oidentd-2.0.8 has the -m switch for masqueraded/NAT connections, please try with that option - also there's an oidentd_masq.conf supplied with the package that has some useful comments :>
Comment 2 James Slater 2007-06-03 16:57:45 UTC
Thanks Christoph.

I think I would have been using the -m option as everything was fine until I upgraded the kernel. I believe the change revolved around the permissions on /proc/net/ip_conntrack changing meaning that oidentd no longer had the ability to read the file to work its magic.

Having said that, to be honest I don't really remember too clearly and no longer use it. In the ~3 years since the bug was filed my memory has become a little hazy.

I'd be tempted to close this bug as no one else seems to have reported it. Perhaps I was doing something wrong after all.
Comment 3 Christoph Mende (RETIRED) gentoo-dev 2007-06-03 17:16:50 UTC
Ok, I'll close this as CANTFIX since I don't have any masquerading here to test it :)