kdesktop_lock won't authenticate against AD



Hi,

My FC5 / KDE box is part of a Windows 2000 domain. I've configured it to
authenticate login credentials against Active Directory and it's working
well. However, when I lock the desktop (manually or via password protected
screen saver), I can not unlock it if the logged in user is an Active
Directory user.
kdesktop_lock fails with the following message:
"Cannot unlock the session because the authentication system feiled to work;
you must kill kdesktop_lock (pid_of_process) manually"

A local user can unlock the desktop without problems.

Any idea about what may be causing this?
Here is may pam configuration for kcheckpass (/etc/pam.d/kcheckpass):
#%PAM-1.0
auth sufficient pam_timestamp.so
auth include system-auth
account required pam_nologin.so
account include system-auth
password include system-auth
session include system-auth
session required pam_loginuid.so
session optional pam_timestamp.so
session optional pam_selinux.so
session optional pam_console.so

Also, /usr/bin/kcheckpass permisions are set as 4755.

Thanks,

Marcelo

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list



Relevant Pages

  • Re: kdesktop_lock wont authenticate against AD[Scanned]
    ... However, when I lock the desktop, I can not unlock it if the logged in user is an Active Directory user. ... "Cannot unlock the session because the authentication system feiled to work; ... account include system-auth ...
    (Fedora)
  • Re: kdesktop_lock wont authenticate against AD
    ... authenticate login credentials against Active Directory and it's working ... I can not unlock it if the logged in user is an Active ... auth sufficient pam_timestamp.so ... account include system-auth ...
    (Fedora)
  • Re: Delegate Account release
    ... messed this up with account disabled flag. ... Windows Server - Active Directory ... you can use the GUI tools or the command line tool UNLOCK to unlock the user accounts. ...
    (microsoft.public.windows.server.security)
  • Re: HOW TO UNLOCK ENCRIPTED FILES
    ... he can't unlock these files, some one knows if Active Directory or ohter ... Active Directory cannot help with encrypted files. ... If the files were in the user profile, and the profile is roaming, the files ...
    (microsoft.public.windows.server.active_directory)
  • HOW TO UNLOCK ENCRIPTED FILES
    ... Some user encripted office files y then the machine was fomated, ... he can't unlock these files, some one knows if Active Directory or ohter way ...
    (microsoft.public.windows.server.active_directory)