Re: ldap, kerberos and ssh-krb5

From: David Parutki (parutki_at_yahoo.com)
Date: 05/10/05

  • Next message: Clive Menzies: "smp kernel boots from Knoppix but not Sarge"
    Date: Mon, 9 May 2005 15:01:11 -0700 (PDT)
    To: debian-user@lists.debian.org
    
    

    Thanks to Mark for the debug hint.

    I did the debug thing for two users, one local to both
    client and server, and one in ldap.

    For the local user a few lines from the logs look
    like:

    Authorized to test1, krb5 principal test1@BOGUS.COM
    (krb5_kuserok)
    debug3: PAM: do_pam_account pam_acct_mgmt = 0
    Accepted gssapi-with-mic for test1 from
    ::ffff:192.168.1.3 port 48465 ssh2

    With the user in ldap, the call to pam_acct_mgmt fails
    with code 9.

    I then received a tip about the option UsePAM in
    sshd_config. After setting this to no, it works for
    both users.

    It seems I'm cutting of some potentially good methods
    by expunging PAM from the scene but perhaps this is
    the "right way" of doing it.

                    
    __________________________________
    Do you Yahoo!?
    Make Yahoo! your home page
    http://www.yahoo.com/r/hs

    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Clive Menzies: "smp kernel boots from Knoppix but not Sarge"

    Relevant Pages

    • Re: [SLE] LDAP Profile on Suse Server
      ... Can anyone let me know how to create ldap profiles in suse linux. ... I have a Suse Server version 8.0 which is a Ldap,DNS and samba server for our network. ... I guess I have to create/configure LDAP client profiles on an LDAP server to support Solaris. ... New and Improved Yahoo! ...
      (SuSE)
    • adding users
      ... I need to add a local user to a system that authenticates ... user in LDAP, or I would just add it there. ... Systems Administrator ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
      (Fedora)
    • Re: [SLE] LDAP Profile on Suse Server
      ... Can anyone let me know how to create ldap profiles in suse linux. ... I guess I have to create/configure LDAP client profiles on an LDAP server to support Solaris. ... New and Improved Yahoo! ...
      (SuSE)
    • Re: CreateUser with LDAP?
      ... >local computer via LDAP? ... You can't use LDAP to create local user accounts - LDAP is only for ... If you want to create a local user, you will need to use the WinNT ...
      (microsoft.public.dotnet.languages.csharp)
    • samba authentication problems
      ... I compiled samba with only "make install" and no options. ... "smbpasswd" I'm getting ldap errors. ... Failed to add entry for user linuxbox. ... Do you Yahoo!? ...
      (freebsd-questions)