about nsswitch

we have  passwd: compat
and in the end passwd_compat: ldap
its mean that the compat source is the ldap

equivalent à (sans file entry)

passwd: files ldap

     In this example, there are specific entries for  users  root
     and  fred to assure that they can login even when the system
     is running single-user. In addition, anyone  whose  password
     information  is  stored  on  an  LDAP server will be able to
     login with their usual password, shell, and home directory.
if we delete ldap entry we can't login with su 'ldap user'

