oops: FC2 authentication with Active Directory

From: fedora list (fedoralist_at_parkerhouse.homeunix.org)
Date: 10/31/04

  • Next message: Leonard Isham: "Re: real time firewall log"
    Date: Sun, 31 Oct 2004 08:06:01 -0600
    To: <fedora-list@redhat.com>
    
    

    I realized that I sent this email as html. I'll try it again for those who use text email viewers.

    Is this a text only mail list?

    ________________________________________
    From: fedora-list-bounces@redhat.com [mailto:fedora-list-bounces@redhat.com] On Behalf Of fedora list
    Sent: Saturday, October 30, 2004 11:44 PM
    To: fedora-list@redhat.com
    Subject: FC2 authentication with Active Directory

    Setup:
    FC2 on a workstation will all updates.
    2 servers running Winblows server 2003 will all updates.

    Problem:
    I can't for the life of me figure out why I can't authenticate.  I see Kerberos authenticates successfully, but nss_ldap cannot connect to the LDAP server.  I guess it can't query LDAP to see what my UID is and fails on the uid < 100 for pam_unix.

    I modified the PAM files, ldap.conf, and krb5.conf files.
    Here are some excerpts from some log files.
    Secure:
    Oct 28 15:26:42 jparker-dfc2 login[3783]: pam_succeed_if: requirement "uid < 100" not met by user "jparker"
    Oct 28 15:27:06 jparker-dfc2 login[30256]: pam_succeed_if: requirement "uid < 100" not met by user "jparker"

    Messages:
    Oct 28 15:26:41 jparker-dfc2 login(pam_unix)[3783]: authentication failure; logname=LOGIN uid=0 euid=0 tty=tty1 ruser= rhost=  user=jparker
    Oct 28 15:26:42 jparker-dfc2 login[3783]: pam_krb5[3783]: authentication succeeds for 'jparker' (jparker@KBM1.LOC)
    Oct 28 15:26:42 jparker-dfc2 login[3783]: nss_ldap: could not search LDAP server - Operations error
    Oct 28 15:26:42 jparker-dfc2 login[3783]: nss_ldap: could not search LDAP server - Operations error
    Oct 28 15:26:42 jparker-dfc2 login[3783]: pam_ldap: ldap_search_s Operations error
    Oct 28 15:26:42 jparker-dfc2 pam_winbind[3783]: user 'jparker' granted acces
    Oct 28 15:26:42 jparker-dfc2 login[3783]: nss_ldap: could not search LDAP server - Operations error
    Oct 28 15:26:42 jparker-dfc2 login(pam_unix)[3783]: session opened for user jparker by LOGIN(uid=0)
    Oct 28 15:26:42 jparker-dfc2 login[3783]: Permission denied

    I'm looking for any and all suggestions.  Short of passwords and such, I'll post whatever you need.

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Leonard Isham: "Re: real time firewall log"

    Relevant Pages

    • RE: How to check UID of process on the other side of local TCP/UDP connection
      ... I'm not sure why you would want to create files to check UID. ... If you're wanting an "authentication" protocol, I think it is quite easy to ... the wire, pickup proper UID, spoof the server, serve up the UID) ... Client communicates with server via TCP or UDP. ...
      (Focus-Linux)
    • Re: Kerberos machine authentication - apparent authentication fail
      ... > until logon), the wireless connection can kick off when it is ready. ... > was confirmed in the server event logs with IAS (i set that up as the radius ... > as an ordinary user kicks in and takes over from the machine authentication. ... > while the network sorts itself out and a double click on a network link of ...
      (microsoft.public.windows.server.security)
    • Re: Basic Authentication + IIS 5 + Windows 2000 + Frontpage 2002 = failure?
      ... SYSTEM account. ... In IIS I took the virtual server that I was testing, ... Authentication premise. ... From a website perspective, I ...
      (microsoft.public.inetserver.iis.security)
    • Need help configuring Wireless Connection profile
      ... I have an SBS 2003 server and a Server 2003 member server set up using RADIUS ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 PEAP ... Certificate Services ...
      (microsoft.public.windowsxp.general)
    • Re: Remote Web Workplace Issues-Please help!
      ... Open the Server Management Console, ... client after Authentication" right. ... permissions, and Microsoft Windows user rights according to the KB 812614. ... Download the IIS Resource Kit tools from the following page: ...
      (microsoft.public.windows.server.sbs)