- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- sshd+pam kerberos+winbind
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-06-2007 10:12 AM
12-06-2007 10:12 AM
sshd+pam kerberos+winbind
#
#
# Authentication management
#
login auth required libpam_hpsec.so.1
login auth sufficient libpam_krb5.so.1
login auth required libpam_unix.so.1 try_first_pass
su auth required libpam_hpsec.so.1
su auth sufficient libpam_krb5.so.1
su auth required libpam_unix.so.1 try_first_pass
dtlogin auth required libpam_hpsec.so.1
dtlogin auth sufficient libpam_krb5.so.1
dtlogin auth required libpam_unix.so.1 try_first_pass
dtaction auth required libpam_hpsec.so.1
dtaction auth sufficient libpam_krb5.so.1
dtaction auth required libpam_unix.so.1 try_first_pass
ftp auth required libpam_hpsec.so.1
ftp auth sufficient libpam_krb5.so.1
ftp auth required libpam_unix.so.1 try_first_pass
sshd auth required libpam_hpsec.so.1
sshd auth required libpam_krb5.so.1
sshd auth required libpam_unix.so.1 try_first_pass
OTHER auth required libpam_unix.so.1
#
# Account management
#
login account required libpam_hpsec.so.1
login account sufficient libpam_krb5.so.1
login account required libpam_unix.so.1
su account required libpam_hpsec.so.1
su account sufficient libpam_krb5.so.1
su account required libpam_unix.so.1
dtlogin account required libpam_hpsec.so.1
dtlogin account sufficient libpam_krb5.so.1
dtlogin account required libpam_unix.so.1
dtaction account required libpam_hpsec.so.1
dtaction account sufficient libpam_krb5.so.1
dtaction account required libpam_unix.so.1
ftp account required libpam_hpsec.so.1
ftp account sufficient libpam_krb5.so.1
ftp account required libpam_unix.so.1
sshd account required libpam_hpsec.so.1
sshd account sufficient libpam_krb5.so.1
sshd account required libpam_unix.so.1
OTHER account required libpam_unix.so.1
#
# Session management
#
login session required libpam_hpsec.so.1
login session required libpam_krb5.so.1
login session required libpam_unix.so.1
dtlogin session required libpam_hpsec.so.1
dtlogin session sufficient libpam_krb5.so.1
dtlogin session required libpam_unix.so.1
dtaction session required libpam_hpsec.so.1
dtaction session sufficient libpam_krb5.so.1
dtaction session required libpam_unix.so.1
sshd account required libpam_hpsec.so.1
sshd account sufficient libpam_krb5.so.1
sshd account required libpam_unix.so.1
OTHER session required libpam_unix.so.1
#
# Password management
#
login password required libpam_hpsec.so.1
login password sufficient libpam_krb5.so.1
login password required libpam_unix.so.1
passwd password required libpam_hpsec.so.1
passwd password sufficient libpam_krb5.so.1
passwd password required libpam_unix.so.1
dtlogin password required libpam_hpsec.so.1
dtlogin password sufficient libpam_krb5.so.1
dtlogin password required libpam_unix.so.1
dtaction password required libpam_hpsec.so.1
dtaction password sufficient libpam_krb5.so.1
dtaction password required libpam_unix.so.1
sshd account required libpam_hpsec.so.1
sshd account sufficient libpam_krb5.so.1
sshd account required libpam_unix.so.1
OTHER password required libpam_unix.so.1
It's probably overkill, but I was trying anything at this point. When I try to login via ssh to the box I get the following errors:
Dec 6 12:04:12 mihp0093 sshd[2276]: Invalid user cwcamp from 172.20.16.214
Dec 6 12:04:12 mihp0093 sshd[2276]: Failed none for invalid user cwcamp from 172.20.16.214 port 65278 ssh2
Dec 6 12:04:16 mihp0093 sshd[2276]: [Authentication failed] Password not valid
Dec 6 12:04:18 mihp0093 sshd[2276]: error: PAM: No account present for user for illegal user cwcampfrom siisysman.corp.smith.com
Dec 6 12:04:18 mihp0093 sshd[2276]: Failed keyboard-interactive/pam for invalid user cwcamp from 172.20.16.214 port 65278 ssh2
Any ideas? Has anyone got this to work? I see a couple of post, but nothing stating they got ssh to work. I am also including a link to a powerpoint that I found, but hasn't helped with this issue.
http://www.sambaxp.com/files/SambaXP2007-PDF/McCall-SambaXP%20presentation-4.7.2007.ppt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-07-2007 09:31 PM
12-07-2007 09:31 PM
Re: sshd+pam kerberos+winbind
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2007 04:50 PM
12-09-2007 04:50 PM
Re: sshd+pam kerberos+winbind
"Dec 6 12:04:12 mihp0093 sshd[2276]: Invalid user cwcamp from 172.20.16.214"
Check if you have the same user on both sides.
"Dec 6 12:04:12 mihp0093 sshd[2276]: Failed none for invalid user cwcamp from 172.20.16.214 port 65278 ssh2"
Check if you have the same user on both sides.
"Dec 6 12:04:16 mihp0093 sshd[2276]: [Authentication failed] Password not valid
Dec 6 12:04:18 mihp0093 sshd[2276]: error: PAM: No account present for user for illegal user cwcampfrom siisysman.corp.smith.com"
if the account is there check if you have the ssh relation setup.
Dec 6 12:04:18 mihp0093 sshd[2276]: Failed keyboard-interactive/pam for invalid user cwcamp from 172.20.16.214 port 65278 ssh2
you are implemeting some thing which is NOT that widely done..My wild guess is that kerbersos is doing the auth only and ssh still restrict to its on rules.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-10-2007 06:40 AM
12-10-2007 06:40 AM
Re: sshd+pam kerberos+winbind
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-10-2007 12:25 PM
12-10-2007 12:25 PM
Re: sshd+pam kerberos+winbind
I would run "pamkrbval" tool to test the basic setup and use "-c" argument for CIFS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-10-2007 12:30 PM
12-10-2007 12:30 PM
Re: sshd+pam kerberos+winbind
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-10-2007 12:44 PM
12-10-2007 12:44 PM
Re: sshd+pam kerberos+winbind
I hope you have had checked the user credentials using klist?
http://www.docs.hp.com/en/T1417-90006/index.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-29-2008 04:05 AM
04-29-2008 04:05 AM
Re: sshd+pam kerberos+winbind
have the same issue. Do you have a solution?
thank you
regards
Maurice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-29-2008 04:11 AM
04-29-2008 04:11 AM
Re: sshd+pam kerberos+winbind
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-29-2008 04:11 AM
04-29-2008 04:11 AM