<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssh needs to be restarted to enable the pam stack changes in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450906#M37245</link>
    <description>Thanks SEP!&lt;BR /&gt;&lt;BR /&gt;For &amp;lt;&lt;MY concern="" is="" unnecessary="" server="" traffic="" at="" ldap="" server="" at="" step=""&gt;&amp;gt;&lt;BR /&gt;&lt;BR /&gt;I have concern why traffic is going on LDAP server even after removing ladp madoule from pam stack&lt;BR /&gt;&lt;BR /&gt;Can you please let me know issue is at pam configuration side or ssh side? It does make sense to look from ssh perspective in this case?&lt;BR /&gt;&lt;BR /&gt;Thanks ,&lt;BR /&gt;MKS&lt;/MY&gt;</description>
    <pubDate>Wed, 01 Jul 2009 11:54:44 GMT</pubDate>
    <dc:creator>monu_1</dc:creator>
    <dc:date>2009-07-01T11:54:44Z</dc:date>
    <item>
      <title>ssh needs to be restarted to enable the pam stack changes</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450904#M37243</link>
      <description>The pam stack is (a)pam_radius.so(b)pam_unix.so &lt;BR /&gt; &lt;BR /&gt;2. ssh to admin (user at radius server) &lt;BR /&gt;    Result: Successful as expected. &lt;BR /&gt; &lt;BR /&gt;3. The pam stack is (a) pam_ldap.so (b)pam_radius.so(c)pam_unix.so &lt;BR /&gt; &lt;BR /&gt;4. Restart ssh  &lt;BR /&gt; &lt;BR /&gt;5. ssh to admin &lt;BR /&gt;    Result: Successful as expected. Ldap server contacted &lt;BR /&gt; &lt;BR /&gt;6.The pam stack is (a)pam_radius.so(b)pam_unix.so &lt;BR /&gt; &lt;BR /&gt;7. ssh to admin &lt;BR /&gt;    Result: Successful as expected. LDAP server contacted &lt;BR /&gt; &lt;BR /&gt;8. Restart ssh( This is unexpected) &lt;BR /&gt; &lt;BR /&gt;9. ssh admin LDAp server not contacted &lt;BR /&gt;Result: Successful as expected. &lt;BR /&gt;-----&lt;BR /&gt;Removing ladp module from pam stack at step # 6 traffic is at LDAP server on ssh to admin (user at radius server) at step # 7. And after restart ssh at #8 it is not the case as expected. My concern is unnecessary server traffic at LDAP server at step # 7.&lt;BR /&gt;&lt;BR /&gt;Can anyone comment on this? Do we need to restart ssh on every step of removing and adding ldap module in pam stack?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;MKS&lt;BR /&gt;</description>
      <pubDate>Wed, 01 Jul 2009 10:22:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450904#M37243</guid>
      <dc:creator>monu_1</dc:creator>
      <dc:date>2009-07-01T10:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: ssh needs to be restarted to enable the pam stack changes</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450905#M37244</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;No you do not need to restart ssh at every step.&lt;BR /&gt;&lt;BR /&gt;I think you can safely do all the work on the pam stack and then restart ssh&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 01 Jul 2009 10:54:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450905#M37244</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-07-01T10:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: ssh needs to be restarted to enable the pam stack changes</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450906#M37245</link>
      <description>Thanks SEP!&lt;BR /&gt;&lt;BR /&gt;For &amp;lt;&lt;MY concern="" is="" unnecessary="" server="" traffic="" at="" ldap="" server="" at="" step=""&gt;&amp;gt;&lt;BR /&gt;&lt;BR /&gt;I have concern why traffic is going on LDAP server even after removing ladp madoule from pam stack&lt;BR /&gt;&lt;BR /&gt;Can you please let me know issue is at pam configuration side or ssh side? It does make sense to look from ssh perspective in this case?&lt;BR /&gt;&lt;BR /&gt;Thanks ,&lt;BR /&gt;MKS&lt;/MY&gt;</description>
      <pubDate>Wed, 01 Jul 2009 11:54:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450906#M37245</guid>
      <dc:creator>monu_1</dc:creator>
      <dc:date>2009-07-01T11:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: ssh needs to be restarted to enable the pam stack changes</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450907#M37246</link>
      <description>Shalom again,&lt;BR /&gt;&lt;BR /&gt;For &amp;lt;&lt;MY concern="" is="" unnecessary="" server="" traffic="" at="" ldap="" server="" at="" step=""&gt;&amp;gt;&lt;BR /&gt;&lt;BR /&gt;Valid concern. If you start getting user login problems during the change steps, restart sshd daemon.&lt;BR /&gt;&lt;BR /&gt;I have concern why traffic is going on LDAP server even after removing ladp madoule from pam stack&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Issue as I see it:&lt;BR /&gt;&lt;BR /&gt;As you make changes to the pam stack, your new user login process will be changing. Existing sessions should not be impacted unless you leave sshd down for a period of time.&lt;BR /&gt;&lt;BR /&gt;So if you make a change to the pam stack that somehow disables new logins, users will suddenly not be able to log in. &lt;BR /&gt;&lt;BR /&gt;pam stands for plugable authentication module, once you are authenticated it should not effect open sessions, changes here effect new authentications or logins.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;/MY&gt;</description>
      <pubDate>Wed, 01 Jul 2009 13:38:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ssh-needs-to-be-restarted-to-enable-the-pam-stack-changes/m-p/4450907#M37246</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-07-01T13:38:40Z</dc:date>
    </item>
  </channel>
</rss>

