password change does not work: LDAP, sssd, nss or pam error?



Hi everyone,

last week I switched my small home network from NIS to OpenLDAP (I am running
Fedora 13 on all machines). Everything went fine except the ability to change
LDAP user passords.

When I try to change the password as a (LADP-) user on a client I get

#> passwd
Changing password for user vp.
Current Password:
New password:
Retype new password:
passwd: Authentication token manipulation error

On the client side I get in /var/log/secure:

Oct 6 12:18:06 thal passwd: pam_unix(passwd:chauthtok): user "vp" does not
exist in /etc/passwd
Oct 6 12:18:43 thal passwd: last message repeated 2 times
Oct 6 12:18:43 thal passwd: pam_sss(passwd:chauthtok): Password change failed
for user vp: 28 (Module is unknown)
Oct 6 12:18:43 thal passwd: gkr-pam: couldn't update the login keyring
password: no old password was entered

I am obviously missing something in the pam-configuration (or in the slapd-
conf or wherever...). I do not have a clue where to search for the error.

Could somebody help, please?

Cheers
Volker
--
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines



Relevant Pages

  • RESOLUTION: NIS user creation problem
    ... It turns out some of our machines have compat, ... delivering it to the intended recipient, you are hereby notified that you ... dissemination, distribution, or copying of this communication is strictly ... I added the new user to the passwd file with a known password hash. ...
    (SunManagers)
  • Re: Automating password change
    ... All the machines are set up differently from each other ... > use telnet, others I can rlogin or remsh, and still others I can ssh. ... it would not be practical to try to write a complex script ... > to write a simple script to wrap around passwd that would run on each ...
    (comp.unix.shell)
  • Re: Automating password change
    ... All the machines are set up differently from each other ... > use telnet, others I can rlogin or remsh, and still others I can ssh. ... it would not be practical to try to write a complex script ... > to write a simple script to wrap around passwd that would run on each ...
    (comp.unix.solaris)
  • RE: NIS passwords - UPDATE
    ... If I execute "getent passwd" it displays all the account info for my users, ... Linux machines was an issue for the Solaris machine, ... the passwd and shadow files used to build the NIS database onto the ... I have one Solaris 8 workstation in a network of Linux machines. ...
    (SunManagers)
  • Automating password change
    ... I have several hundred Sun and HP-UX machines on an Intranet that I need ... to change passwords on every month for my account and for an application ... it would not be practical to try to write a complex script ... If I choose Expect as the language to make the passwd ...
    (comp.unix.solaris)