Operating System - HP-UX
1752634 Members
5914 Online
108788 Solutions
New Discussion юеВ

Re: NIS password change issues

 
Helen French
Honored Contributor

Re: NIS password change issues

Hi,

Did you check 'man pam.conf' ? Can you post your /etc/pam.conf file ?

HTH,
Shiju
Life is a promise, fulfill it!
Sanjay_6
Honored Contributor

Re: NIS password change issues

Paul Mezzanini
Advisor

Re: NIS password change issues

Jeff:

I'm not sure if this is or is not an issue when the users are setting their first initial password. It won't let me change my password either so I don't think its an issue (I show up in `who`).

Shiju:

Its the standard hp-ux 11.i pam.conf file but I'll post it anyway. Its small enough that I think a direct cut/paste will work (vs attachment)

#
# PAM Configuration
#
# Account Management
#
dtaction account required /usr/lib/security/libpam_unix.1
dtlogin account required /usr/lib/security/libpam_unix.1
ftp account required /usr/lib/security/libpam_unix.1
login account required /usr/lib/security/libpam_unix.1
su account required /usr/lib/security/libpam_unix.1
OTHER account required /usr/lib/security/libpam_unix.1
#
# Authentication Management
#
dtaction auth required /usr/lib/security/libpam_unix.1
dtlogin auth required /usr/lib/security/libpam_unix.1
ftp auth required /usr/lib/security/libpam_unix.1
login auth required /usr/lib/security/libpam_unix.1
su auth required /usr/lib/security/libpam_unix.1
OTHER auth required /usr/lib/security/libpam_unix.1
#
# Password Management
#
dtaction password required /usr/lib/security/libpam_unix.1
dtlogin password required /usr/lib/security/libpam_unix.1
login password required /usr/lib/security/libpam_unix.1
passwd password required /usr/lib/security/libpam_unix.1
OTHER password required /usr/lib/security/libpam_unix.1
#
# Session Management
#
dtaction session required /usr/lib/security/libpam_unix.1
dtlogin session required /usr/lib/security/libpam_unix.1
login session required /usr/lib/security/libpam_unix.1
OTHER session required /usr/lib/security/libpam_unix.1


That is a cut/paste from the server. Interestingly enough the workstations seem to have a different pam.conf file from the server. Here is one from a workstation:

#
# PAM configuration
#
# Authentication management
#
login auth required /usr/lib/security/libpam_unix.1
su auth required /usr/lib/security/libpam_unix.1
dtlogin auth required /usr/lib/security/libpam_unix.1
dtaction auth required /usr/lib/security/libpam_unix.1
ftp auth required /usr/lib/security/libpam_unix.1
OTHER auth required /usr/lib/security/libpam_unix.1
#
# Account management
#
login account required /usr/lib/security/libpam_unix.1
su account required /usr/lib/security/libpam_unix.1
dtlogin account required /usr/lib/security/libpam_unix.1
dtaction account required /usr/lib/security/libpam_unix.1
ftp account required /usr/lib/security/libpam_unix.1
#
OTHER account required /usr/lib/security/libpam_unix.1
#
# Session management
#
login session required /usr/lib/security/libpam_unix.1
dtlogin session required /usr/lib/security/libpam_unix.1
dtaction session required /usr/lib/security/libpam_unix.1
OTHER session required /usr/lib/security/libpam_unix.1
#
# Password management
#
login password required /usr/lib/security/libpam_unix.1
passwd password required /usr/lib/security/libpam_unix.1
dtlogin password required /usr/lib/security/libpam_unix.1
dtaction password required /usr/lib/security/libpam_unix.1
OTHER password required /usr/lib/security/libpam_unix.1




I have no idea if that could cause any issues, but at least I finally found something promising :)

-paul
Paul Mezzanini
Advisor

Re: NIS password change issues

Sanjay:

That is how I've been changing passwords for my users. I'm in an academic environment and I need to change passwords for around 30 people at a time (whenever a class comes in for the first time).

As you can probably guess, thats not much fun. I would love for them to do it themselves (just like the previous quarters) :)

-paul
Sanjay_6
Honored Contributor

Re: NIS password change issues

Hi Paul,

Consider this patch,

http://us-support.external.hp.com/wpsl/bin/doc.pl/screen=wpslDisplayPatch/sid=e558db18020646469a?PACH_NAM=PHCO_25527&HW=s800&OS=11.00

You can also consider patching your system with some other latest patches.

Hope this helps.

Regds
Jeff Machols
Esteemed Contributor

Re: NIS password change issues

run the tty command at the promt and make sure you get a valid tty. if you don't that could be why the who isn't working. If you can't do a who | grep TTY (tty that shows up from the tty command) then you will not be able to run the passwd command
Ajay Sishodia
Frequent Advisor

Re: NIS password change issues

Paul,

what OS version is your master NIS server? Also on the master can you make changes to password map and do a 'make'? see if it pushs the new map out with the change(s).

regards
Ajay
Paul Mezzanini
Advisor

Re: NIS password change issues

Sanjay:

I'll see if that patch does anything.

I've been trying to keep up with all the patches and I think I'm doing a not-so-bad job.

Ajay:

I can make changes on the master and implement/push them sucessfully

Servers are j5000 boxes, clients are either B1000 or C240
everything runs 11.i

Jeff:

tty is valid (/dev/pts/1 for the box I just checked)
Sanjay_6
Honored Contributor

Re: NIS password change issues

Hi Paul,

Was this working earlier ?. If so, do you remeber any changes that you might have made since the last time it worked and now ?.

Regds
Ajay Sishodia
Frequent Advisor

Re: NIS password change issues

Paul,

Did you try stoping/starting nis server and client on the nis master??

# /sbin/init.d/nis.client stop
# /sbin/init.d/nis.master stop

# /sbin/init.d/nis.master start
# /sbin/init.d/nis.client start


Assuming all your clients point to a slave server.

Ajay