Re: Samba4, PamLDAP and Hylafax Auth [SOLVED]

Marcel Ebbrecht <[email protected]> Tue, 10 May 2016 20:53:37 +0200
Newsgroups gmane.comp.telephony.fax.hylafax.user
Organization e² consulting UG (haftungsbeschränkt)
Message-ID <[email protected]>
Hi Lee, LPH, List

It's working :)

^username@:UID:SOMECRAP:OTHERCRAP
(eg: ^marshall@:11231:sfvqw453:w3gv3w5t)

and

auth            sufficient              pam_ldap.so debug
account         sufficient              pam_ldap.so debug
password        sufficient              pam_ldap.so debug

and working pam_ldap, it works :) :) :)


/etc/nslcd.conf
# /etc/nslcd.conf
# nslcd configuration file. See nslcd.conf(5)
# for details.

# The user and group nslcd should run as.
uid nslcd
gid nslcd

# The location at which the LDAP server(s) should be reachable.
uri ldaps://dc1.ldap.lan

# The search base that will be used for all queries.
base DC=ldap,DC=lan

# The LDAP protocol version to use.
ldap_version 3

# The DN to bind with for normal lookups.
binddn CN=Oberkrasseradmin,DC=ldap,DC=lan
bindpw 98h7098o7juu98ui

filter  passwd  (objectClass=user)
filter  group   (objectClass=group)

map     passwd  uid                sAMAccountName
map     passwd  homeDirectory      unixHomeDirectory
map     passwd  gecos              displayName
map     passwd  gidNumber          primaryGroupID

ssl on
tls_reqcert never
scope sub
tls_cacertfile /etc/ssl/certs/ca.crt




Am 28.01.2016 um 00:16 schrieb Lee Howard:
> On 01/27/2016 06:28 AM, Marcel Ebbrecht wrote:
>> I'm still working on Samba4 Auth with Hylafax. Anyone git a hint what
>> this means?
>>
>> Setup: Samba4, pam-ldapd/nslcd, Hylafax 6.06 on Debian Jessie
>> Howto:
>> http://www.hylafax.org/content/Handbook:Advanced_Server_Configuration:PAM_Authentication
>>
>>
>> "Jan 27 15:23:33 voip1 HylaFAX[24798]: pam_authenticate failed in
>> pamCheck with 0x6: Permission denied"
>>
>> permission denied on what ?!
>
> It means what it says: pam_authenticate did not function due to a
> "Permission denied" error.
>
> That's all that we know from HylaFAX's vantage.  PAM is telling hfaxd
> that it doesn't have permission to run pam_authenticate.
>
> This is possibly some kind of security feature within PAM or SElinux
> or something similar.
>
> If you can turn-up your PAM logging and look at that ... hopefully
> you'd get more information.
>
> Thanks,
>
> Lee.

-- 
Marcel Ebbrecht <[email protected]>
e2 consulting UG (haftungsbeschraenkt)

Geschaeftssitz:
Rheinlanddamm 201
D-44139 Dortmund

Telefon: +49 231 99778310
Telefax: +49 231 99778381
Mobil: +49 160 90345852
Jabber: [email protected]
Internet: https://www.dortmundit.de

Handelsregister Dortmund HRB 24666
Geschaeftsfuehrer: Marcel Ebbrecht
Steuernummer: 314/5723/1889
USTID: DE283203942

PKI: https://ssl.dortmundit.de:18016

AGB: http://agb.dortmundit.de

Diese E-Mail und moegliche Anhaenge enthalten vertrauliche Informationen, die rechtlich besonders geschuetzt sein koennen. Wenn Sie nicht der beabsichtigte Empfaenger bzw. Adressat dieser E-mail sind und diese E-Mail etwa aufgrund eines technischen Fehlers oder eines Versehens erhalten haben, informieren Sie uns bitte sofort und loeschen Sie anschliessend die E-Mail. Das unbefugte Kopieren dieser E-Mail, etwaiger Anhaenge sowie die unbefugte Weitergabe der enthaltenen Informationen an Dritte ist nicht gestattet.

This e-mail message together with its attachments, if any, is confidential and may contain information subject to legal privilege (e.g. attorney-client-privilege). If you are not the intended recipient or have received this e-mail in error, please inform us immediately and delete this message. Any unauthorised copying of this message (and attachments) or unauthorised distribution of the information contained herein is prohibited.

Go Green! Print this email only when necessary.