<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP-UX PAM authentication/authorization... in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723417#M788331</link>
    <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Can you tell me if there is anything in the /var/adm/syslog/syslog file when this happens.&lt;BR /&gt;&lt;BR /&gt;This may be due to patching issues on the Windows or HP side. Is the AD server 2000 or 2003. Server 2003 requires a patch to work with Unix servers that use Kerebos 4 instead of 5.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Thu, 02 Feb 2006 15:32:55 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2006-02-02T15:32:55Z</dc:date>
    <item>
      <title>LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723416#M788330</link>
      <description>We are researching and testing the use of LDAP-UX with PAM/Kerberos to perform UNIX user account management with MS Active Directory.&lt;BR /&gt;&lt;BR /&gt;We have succeeded in installing all the current products necessary and are able to "authenticate" UNIX users from AD.&lt;BR /&gt;&lt;BR /&gt;Problem: unable to "authorize" UNIX users correctly.&lt;BR /&gt;&lt;BR /&gt;We have the following as the first entry in the account management section of /etc/pam.conf:&lt;BR /&gt;login auth required /usr/lib/security/libpam_authz.1 debug &lt;BR /&gt;&lt;BR /&gt;We also have the following entry in /etc/opt/ldapux/pam_authz.policy:&lt;BR /&gt;deny:unix_user:xxxxxxxx&lt;BR /&gt;&lt;BR /&gt;I expected user "xxxxxxxx" to be denied access to the system BUT the user was granted access and provided a command prompt.&lt;BR /&gt;&lt;BR /&gt;The debug.log shows the following:&lt;BR /&gt;Jan 20 15:57:48 sysname login: PAM_AUTHZ Entering pam_sm_authenticate ...&lt;BR /&gt;Jan 20 15:57:48 sysname login: PAM_AUTHZ pam_sm_authenticate(login, xxxxxxxx), flags = 0&lt;BR /&gt;Jan 20 15:57:48 sysname login: PAM_AUTHZ Entering check_authorization() ...&lt;BR /&gt;Jan 20 15:57:48 sysname login: PAM_AUTHZ pam_sm_authenticate returns (0)!&lt;BR /&gt;Jan 20 15:57:55 s1x011 login: PAM_AUTHZ Entering pam_sm_setcred ...&lt;BR /&gt;&lt;BR /&gt;It appears to me that the authorization function does not work correctly. Can anyone tell me why the PAM "authorization" function is allowing access when it should be denying it?</description>
      <pubDate>Thu, 02 Feb 2006 15:22:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723416#M788330</guid>
      <dc:creator>Steve Hinchman</dc:creator>
      <dc:date>2006-02-02T15:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723417#M788331</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Can you tell me if there is anything in the /var/adm/syslog/syslog file when this happens.&lt;BR /&gt;&lt;BR /&gt;This may be due to patching issues on the Windows or HP side. Is the AD server 2000 or 2003. Server 2003 requires a patch to work with Unix servers that use Kerebos 4 instead of 5.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 02 Feb 2006 15:32:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723417#M788331</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-02-02T15:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723418#M788332</link>
      <description>We are using the following Kerberos products on the HP test server:&lt;BR /&gt;# swlist -l fileset | grep -i kerberos&lt;BR /&gt;# KRB-Support                           B.11.11        Kerberos Support for HP-UX and DCE&lt;BR /&gt;# KRB5-Client                           B.11.11        Kerberos V5 Client Version 1.0&lt;BR /&gt;# KRBS-Support                          B.11.11.13     Kerberos Support v1.11&lt;BR /&gt;  KRBS-Support.KRBS-SUPP-MAN            B.11.11.13     Kerberos Support Man Pages&lt;BR /&gt;  KRBS-Support.KRBS-SUPP-NOTE           B.11.11.13     Kerberos Support Release Notes&lt;BR /&gt;  KRBS-Support.KRBS-SUPP-RUN            B.11.11.13     Kerberos Support Runtime&lt;BR /&gt;# PAM-Kerberos                          B.11.11.13     PAM-Kerberos Version 1.11&lt;BR /&gt;  PAM-Kerberos.PAM-KRB-DEMO             B.11.11.13     PAM-Kerberos Demonstration&lt;BR /&gt;  PAM-Kerberos.PAM-KRB-MAN              B.11.11.13     PAM-Kerberos Man Pages&lt;BR /&gt;  PAM-Kerberos.PAM-KRB-RUN              B.11.11.13     PAM-Kerberos Runtime&lt;BR /&gt;  PAM-Kerberos.PAM-KRB-SHLIB            B.11.11.13     PAM-Kerberos Shared Library&lt;BR /&gt;# krb5client                            C.1.3.5.03     Kerberos V5 Client Version 1.3.5.03&lt;BR /&gt;&lt;BR /&gt;and AD is running on Windows Server 2003.&lt;BR /&gt;&lt;BR /&gt;I got the following entries in syslog.log:&lt;BR /&gt;&lt;BR /&gt;Feb  2 16:52:04 xxxxxx inetd[17541]: telnet/tcp: Connection from yyyyyy (xxx.xxx&lt;BR /&gt;.xx.xxx) at Thu Feb  2 16:52:04 2006&lt;BR /&gt;Feb  2 16:52:04 xxxxxx telnetd[17541]: allowed connection from yyyyyy&lt;BR /&gt;Feb  2 16:52:14 xxxxxx login: [Authentication failed] Password not valid&lt;BR /&gt;Feb  2 16:52:14 xxxxxx login: user2netname: unknown nameservice ^I^I^I^I^Ifor pu&lt;BR /&gt;blickey info 'ldap'&lt;BR /&gt;Feb  2 16:52:14 xxxxxx login: Pam Creds are not available&lt;BR /&gt;Feb  2 16:52:15 xxxxxx sudo: uuuuuuu : TTY=pts/ta ; PWD=/home/uuuuuu ; USER=ro&lt;BR /&gt;ot ; COMMAND=/usr/local/bin/mypwexpiration&lt;BR /&gt;&lt;BR /&gt;Even though a "password not valid" message appears in the syslog, I am still allowed access to the system. ???&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Feb 2006 16:58:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723418#M788332</guid>
      <dc:creator>Steve Hinchman</dc:creator>
      <dc:date>2006-02-02T16:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723419#M788333</link>
      <description>Steve,&lt;BR /&gt;  You should use pam_authz in the account managment section of pam.conf, not authentication:&lt;BR /&gt;&lt;BR /&gt;login account required /usr/lib/security/libpam_authz.1&lt;BR /&gt;login account sufficient  /usr/lib/security/libpam_unix.1&lt;BR /&gt;login account required    /usr/lib/security/libpam_ldap.1&lt;BR /&gt;&lt;BR /&gt;if that doesn't fix it add debug to the pam_authz line and take a look at syslog.log&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Doug&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Feb 2006 17:26:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723419#M788333</guid>
      <dc:creator>Doug Lamoureux_2</dc:creator>
      <dc:date>2006-02-02T17:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723420#M788334</link>
      <description>Steven and Doug,&lt;BR /&gt;&lt;BR /&gt;Thanks for your help.  PAM authorization and authentication now works.  Now we are off to working through the rest of the issues of maintaining UNIX user accounts in AD.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Steve Hinchman</description>
      <pubDate>Fri, 03 Feb 2006 10:55:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723420#M788334</guid>
      <dc:creator>Steve Hinchman</dc:creator>
      <dc:date>2006-02-03T10:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723421#M788335</link>
      <description>Steve,&lt;BR /&gt;&lt;BR /&gt;Could you tell us whether you're running these systems trusted or not?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Jeff</description>
      <pubDate>Fri, 03 Feb 2006 11:29:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723421#M788335</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2006-02-03T11:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723422#M788336</link>
      <description>Jeff,&lt;BR /&gt;&lt;BR /&gt;Yes, we are running them "trusted".&lt;BR /&gt;&lt;BR /&gt;Steve</description>
      <pubDate>Fri, 03 Feb 2006 11:35:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723422#M788336</guid>
      <dc:creator>Steve Hinchman</dc:creator>
      <dc:date>2006-02-03T11:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723423#M788337</link>
      <description>OK - thanks.&lt;BR /&gt;One more question if you don't mind.&lt;BR /&gt;Have you tested PW expiration yet?&lt;BR /&gt;How about SSH with public keys as well?&lt;BR /&gt;We are having "issues" with the combination of these two.&lt;BR /&gt;We're finding if one's PW is expired AND they are using SSH keys - they still get in.&lt;BR /&gt;Sorry to jump into your thread, but we're looking for others that are "in this boat" as well.&lt;BR /&gt;&lt;BR /&gt;Rgds,&lt;BR /&gt;Jeff</description>
      <pubDate>Fri, 03 Feb 2006 11:48:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723423#M788337</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2006-02-03T11:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723424#M788338</link>
      <description>Jeff, &lt;BR /&gt;  If your using Netscape/Redhat or SunOne Directory Server this whitepaper should help:&lt;BR /&gt;  &lt;A href="http://www.docs.hp.com/en/6965/pam_authz_for_policy_wp_2_3.pdf" target="_blank"&gt;http://www.docs.hp.com/en/6965/pam_authz_for_policy_wp_2_3.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Doug&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Feb 2006 12:05:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723424#M788338</guid>
      <dc:creator>Doug Lamoureux_2</dc:creator>
      <dc:date>2006-02-03T12:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723425#M788339</link>
      <description>Thanks Doug.&lt;BR /&gt;Yes we already have that paper and are indeed using pam_authz.&lt;BR /&gt;Still trouble.&lt;BR /&gt;Oh well, we'll keep plugging at it.&lt;BR /&gt;&lt;BR /&gt;Again Thanks,&lt;BR /&gt;Jeff</description>
      <pubDate>Fri, 03 Feb 2006 12:09:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723425#M788339</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2006-02-03T12:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX PAM authentication/authorization...</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723426#M788340</link>
      <description>Jeff,&lt;BR /&gt;&lt;BR /&gt;Sorry, we haven't gotten that far yet, but I am putting it on my test case list.  I will let you know what are results are.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Steve</description>
      <pubDate>Fri, 03 Feb 2006 13:50:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-pam-authentication-authorization/m-p/3723426#M788340</guid>
      <dc:creator>Steve Hinchman</dc:creator>
      <dc:date>2006-02-03T13:50:03Z</dc:date>
    </item>
  </channel>
</rss>

