- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Get hpux user info into AD for ldap
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-03-2009 10:30 AM
тАО02-03-2009 10:30 AM
sshd[6585]: PAM_LDAP auth-bind got HP_LDAP_NOTFOUND
sshd[6585]: PAM_LDAP auth-bind failed!
sshd[6585]: PAM_LDAP pam_sm_authenticate: set bind status (13)
sshd[6585]: PAM_LDAP 2nd auth_bind returns 13
sshd[6585]: PAM_LDAP pam_sm_authenticate: returning 13
I know the proxy bind if functioning properally and am convinced that the accounts that were in already in ad need to have the unix information attached to them, just can not figure out how to get this done. The current accounts in ad can not be removed due to already having other credintals attached to them.
Has anyone seen this, fixed this, or know how to fix this?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-03-2009 10:37 AM
тАО02-03-2009 10:37 AM
Re: Get hpux user info into AD for ldap
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-03-2009 10:42 AM
тАО02-03-2009 10:42 AM
Re: Get hpux user info into AD for ldap
ldapux 4.15.01
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-04-2009 05:39 AM
тАО02-04-2009 05:39 AM
Re: Get hpux user info into AD for ldap
Please let me know if anyone has a method that works, I have tried many combinations of the ldap and ldapug commands with no success.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-04-2009 02:36 PM
тАО02-04-2009 02:36 PM
SolutionDo you have Windows 2003 R2 or 2008. Or do you have an older version? W 2K3 R2 and later include the posix schema by default. If you have an earlier version of Windows Server, you can install the MS SFU schema. Based on your comments about the migration "test" accounts working, it appears you do have the schema. So this should be a non-issue.
So there should be a couple of ways to do ammend existing accounts with Unix information. First, you can use ADSI edit on the AD server. ADSI edit allows you to add any attribute to any entry, as long as it is allowed by the objectclasses used in the entry. So you can add the uidNumber (or msSFU30uidNumber) attribute and the other Unix attributes directly to the user account. It also includes a tab in the users and groups properties editor that is dedicated to editing posix attributes. The second option is to use version B.04.15 or later of LDAP-UX. These versions of LDAP-UX include user and group management commands that allow you to edit Unix user and group entries. If you look at /opt/ldapux/bin/ldapugmod, you'll see it has a specific option (-O) that is specifically for the purpose of adding Unix account or group information to an account or group that doesn't already have this information.
Hope that helps!
Bob
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-06-2009 08:35 AM
тАО02-06-2009 08:35 AM
Re: Get hpux user info into AD for ldap
I just finished a whitepaper called "Unified Login for HP CIFS Server, HP-UX,, and Windows 2003R2", where I show screen shots on how to set up Windows and HP-UX to store and retrieve POSIX IDs on the AD. Since I just finished it yesterday, it is not posted for external-HP access yet. If you want a copy, then email me - Eric Roseme at HP with all the dots and stuff.
Eric Roseme
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-06-2009 12:33 PM
тАО02-06-2009 12:33 PM