[SLE] SUSE10, LDAP and disconnected login.
- From: Warren Howard <warren@xxxxxxxxxxxxxxx>
- Date: Wed, 15 Feb 2006 13:42:42 +0530
Hi,
I'm using SUSE 10.0 OSS as client workstations with a central LDAP
server for authentication. LDAP authentication for the SUSE 10
workstations is configured through YaST -> Network Services -> LDAP
Client. Where I select "use LDAP", enter the LDAP server address and
enter the LDAP base DN. Following this I also add
session required pam_mkhomedir.so skel=/etc/skel/ umask=0022
to the bottom of PAM configuration files login, xdm and sshd found in
/etc/pam.d. Then users who have valid LDAP credentials and the local
root superuser are able to login to the SUSE 10 workstation. This works
fine - no problems so far.
Trouble starts when I disconnect the network. The local root superuser
cannot login. The authentication is successful but the login session
times out after 60 seconds. I'm having trouble understanding why this
is happening because I'm having trouble understanding the SUSE design
for the login process. Specifically:
1. Why use pam_unix2.so? What are the advantages? It took me some time
to trace the config file (/etc/security/pam_unix2.conf) for this module,
when logically I expected to find all the necessary files for
configuring pam behavior under /etc/pam.d.
2. Why use the +:::::: notation in /etc/passwd for directing the system
to search for other authentication sources. What is the advantage to
this over using a "files ldap" entry in /etc/nsswitch.conf?
The login session timeout for root when the network is disconnected is
very similar to the problems I'm facing when configuring pam_ccreds for
disconnected login of LDAP users who have previously logged in
successfully. So I'm hoping that someone here could help me to
understand why the local root superuser cannot login when the network is
disconnected on a SUSE10 workstation that has been configured through
YaST (at install time) to use LDAP as an authentication source.
Thanks,
Warren.
--
Check the headers for your unsubscription address
For additional commands send e-mail to suse-linux-e-help@xxxxxxxx
Also check the archives at http://lists.suse.com
Please read the FAQs: suse-linux-e-faq@xxxxxxxx
- Prev by Date: [SLE] ethereal results, where to start?
- Next by Date: Re: [SLE] how do I set aspect ratio with dual head
- Previous by thread: [SLE] ethereal results, where to start?
- Next by thread: [SLE] Can I export directory tree with another mounted point in it ?
- Index(es):
Relevant Pages
|