- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: SSH and AD Authentication
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-03-2007 11:53 PM
07-03-2007 11:53 PM
SSH and AD Authentication
When I connect via SSH and check syslog I get the following :-
Jul 4 12:44:14 upgrade sshd[12137]: Server listening on :: port 22.
Jul 4 12:44:14 upgrade sshd[12137]: Server listening on 0.0.0.0 port 22.
Jul 4 12:44:35 upgrade sshd[12138]: [Can not retrieve authentication info] Password not valid
Jul 4 12:44:37 upgrade sshd[12138]: error: PAM: Can not retrieve authentication info for user1 from 10.7.152.245
In the sshd_config I have set the following :-
UsePAM yes
PasswordAuthentication no
And my pam.conf is as follows :-
login auth required libpam_hpsec.so.1
login auth sufficient libpam_unix.so.1
login auth required libpam_krb5.so.1 try_first_pass
su auth required libpam_hpsec.so.1
su auth sufficient libpam_unix.so.1
su auth required libpam_krb5.so.1 try_first_pass
dtlogin auth required libpam_hpsec.so.1
dtlogin auth sufficient libpam_unix.so.1
dtlogin auth required libpam_krb5.so.1 try_first_pass
dtaction auth required libpam_hpsec.so.1
dtaction auth sufficient libpam_unix.so.1
dtaction auth required libpam_krb5.so.1 try_first_pass
ftp auth required libpam_hpsec.so.1
ftp auth sufficient libpam_unix.so.1
ftp auth required libpam_krb5.so.1 try_first_pass
rcomds auth required libpam_hpsec.so.1
rcomds auth sufficient libpam_unix.so.1
rcomds auth required libpam_krb5.so.1 try_first_pass
sshd auth required libpam_hpsec.so.1
sshd auth sufficient libpam_unix.so.1
sshd auth required libpam_krb5.so.1 try_first_pass
OTHER auth sufficient libpam_unix.so.1
OTHER auth required libpam_krb5.so.1 try_first_pass
#
# Account management
#
login account required libpam_hpsec.so.1
login account sufficient libpam_unix.so.1
login account required libpam_krb5.so.1
su account required libpam_hpsec.so.1
su account sufficient libpam_unix.so.1
su account required libpam_krb5.so.1
dtlogin account required libpam_hpsec.so.1
dtlogin account sufficient libpam_unix.so.1
dtlogin account required libpam_krb5.so.1
dtaction account required libpam_hpsec.so.1
dtaction account sufficient libpam_unix.so.1
dtaction account required libpam_krb5.so.1
ftp account required libpam_hpsec.so.1
ftp account sufficient libpam_unix.so.1
ftp account required libpam_krb5.so.1
rcomds account required libpam_hpsec.so.1
rcomds account sufficient libpam_unix.so.1
rcomds account required libpam_krb5.so.1
sshd account required libpam_hpsec.so.1
sshd account sufficient libpam_unix.so.1
sshd account required libpam_krb5.so.1
OTHER account sufficient libpam_unix.so.1
OTHER account required libpam_krb5.so.1
#
# Session management
#
login session required libpam_hpsec.so.1
login session sufficient libpam_unix.so.1
login session required libpam_krb5.so.1
dtlogin session required libpam_hpsec.so.1
dtlogin session sufficient libpam_unix.so.1
dtlogin session required libpam_krb5.so.1
ftp session required libpam_hpsec.so.1 bypass_limit_login bypass_umask bypass_nologin
ftp session sufficient libpam_unix.so.1
ftp session required libpam_krb5.so.1
rcomds session required libpam_hpsec.so.1 bypass_limit_login
rcomds session sufficient libpam_unix.so.1
rcomds session required libpam_krb5.so.1
sshd session required libpam_hpsec.so.1
sshd session sufficient libpam_unix.so.1
sshd session required libpam_krb5.so.1
OTHER session sufficient libpam_unix.so.1
OTHER session required libpam_krb5.so.1
#
# Password management
#
login password required libpam_hpsec.so.1
login password sufficient libpam_unix.so.1
login password required libpam_krb5.so.1 try_first_pass
passwd password required libpam_hpsec.so.1
passwd password sufficient libpam_unix.so.1
passwd password required libpam_krb5.so.1 try_first_pass
dtlogin password required libpam_hpsec.so.1
dtlogin password sufficient libpam_unix.so.1
dtlogin password required libpam_krb5.so.1 try_first_pass
sshd password required libpam_hpsec.so.1
sshd password sufficient libpam_unix.so.1
sshd password required libpam_krb5.so.1 try_first_pass
OTHER password sufficient libpam_unix.so.1
OTHER password required libpam_krb5.so.1 try_first_pass
This is on HPUX11iv2 with the following packages :-
# swlist | grep KRB
KRB5CLIENT D.1.3.5.06 Kerberos V5 Client Version 1.3.5.06
#
# swlist | grep Secure
T1471AA A.04.00.003 HP-UX Secure Shell
Any ideas please ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-04-2007 12:02 AM
07-04-2007 12:02 AM
Re: SSH and AD Authentication
/etc/nsswtich.conf Does it have ldap or ads for authentication?
http://www.docs.hp.com/en/J4269-90074/
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-04-2007 12:22 AM
07-04-2007 12:22 AM
Re: SSH and AD Authentication
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-04-2007 12:39 AM
07-04-2007 12:39 AM
Re: SSH and AD Authentication
Jul 4 13:34:34 upgrade sshd[2989]: load_modules: can not open module /usr/lib/security/pa20_64/libpam_krb5.so.1
Jul 4 13:34:34 upgrade sshd[2989]: error: PAM: Shared object load failure for user1 from 10.7.152.245
after installing :-
T1471AA_A.04.50.004_HP-UX_B.11.23_IA+PA.depot
# swlist | grep -i "secure shell"
T1471AA A.04.50.004 HP-UX Secure Shell
:(
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-04-2007 01:46 AM
07-04-2007 01:46 AM
Re: SSH and AD Authentication
The document I provided covers ADS as well.
This document may be more appropriate but addresses the issue of LDAP as well.
http://docs.hp.com/en/J4269-90049/ch02s05.html
Some windows services use LDAP. Anyway there are good tools on HP-UX to help with this.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-04-2007 06:01 AM
07-04-2007 06:01 AM
Re: SSH and AD Authentication
"Jul 4 13:34:34 upgrade sshd[2989]: load_modules: can not open module /usr/lib/security/pa20_64/libpam_krb5.so.1"
Check for presense of that file - libpam_krb5.so.1
or permissions.
For troubleshooting and installing refer to this doc http://docs.hp.com/en/J4269-90049/index.html
regards,
ivan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-04-2007 06:10 AM
07-04-2007 06:10 AM