Repair of ldap pam xdm login after disk crash

Peter Fodrek <[email protected]> Thu, 2 Feb 2017 15:45:01 +0100
Newsgroups gmane.linux.pam
Message-ID <CAEVagPt5BsJbNi7X4+tH-xYB6VbCvbq28-Pd=qTrLkVcRz6_pA@mail.gmail.com>
--===============8557410546890963991==
Content-Type: multipart/alternative; boundary=001a1147f990c7f3ba05478d35d9

--001a1147f990c7f3ba05478d35d9
Content-Type: text/plain; charset=UTF-8

Dear PAM experts,

I am not to find out cause of problem during repair system with originaly
placed

/boot
/home
/opt
/srv
/tmp
/usr/src
and
/var

directories on crashed RAID controller bus.

I was able to recover system to boot and other things to work exceot one

PAM based xdm, ssh login using remote  LDAPS server and It worked before
RAID crash

My state if art is

that

ldapsearch works well in both cases binded to rxisting user or annonymous
user as well

but

pamtester  ldap  fodrek authenticate  open_session


pamtester  nss  fodrek authenticate  open_session

as well as

pamtester  sss fodrek authenticate  open_session

results in same output

dap_msgfree
pamtester: successfully authenticated
(rdconf1.c:154): You do not exist? fodrek? Success.
(pam_mount.c:598): error expanding configuration
ldap_unbind
ldap_free_connection 1 1
ldap_send_unbind
ber_flush2: 7 bytes to sd 4
  0000:  30 05 02 01 05 42 00                               0....B.

tls_write: want=36, written=36
  0000:  ....          PS.v
ldap_write: want=7, written=7
  0000: ....B.
tls_write: want=31, written=31
  0000:  .....
      ...i.9....F..;A
ldap_free_connection: actually freed
tls_write: want=31 error=Bad file descriptor

pamtester: Insufficient credentials to access authentication data

If I do not place open_session in the command last line of output is missing

same ctedential missing output is for acct_mgmt
and  chauthtook and authenticate are only operations that works.


Is there anybody who us able to send me any recommendation, what am I to
check
to get  PAM to work here,please?

LDAP server is external server

usage of

pam-auth-update --force

only allow me to get system into logging with unix authentofication method
but automatic logout  after several seconds
when  I disable  AFS session mamagement on Ubuntu 16.10 system

But I am not able to log in using LDAP account in thos case,too.


Originally there were system configured to use both PAM for log and SASL
for Subversion repository access control.


Thank you for any answer

I look forward hearing from you

Yours faithfully


Peter Fodrek

--001a1147f990c7f3ba05478d35d9
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div dir=3D"auto">Dear PAM experts,</div><div dir=3D"auto=
"><br></div><div dir=3D"auto">I am not to find out cause of problem during =
repair system with originaly placed</div><div dir=3D"auto"><br></div><div d=
ir=3D"auto">/boot</div><div dir=3D"auto">/home</div><div dir=3D"auto">/opt<=
/div><div dir=3D"auto">/srv</div><div dir=3D"auto">/tmp</div><div dir=3D"au=
to">/usr/src</div><div dir=3D"auto">and</div><div dir=3D"auto">/var=C2=A0</=
div><div dir=3D"auto"><br></div><div dir=3D"auto">directories on crashed RA=
ID controller bus.</div><div dir=3D"auto"><br></div><div dir=3D"auto">I was=
 able to recover system to boot and other things to work exceot one=C2=A0</=
div><div dir=3D"auto"><br></div><div dir=3D"auto">PAM based xdm, ssh login =
using remote =C2=A0LDAPS server and It worked before RAID crash</div><div d=
ir=3D"auto"><br></div><div dir=3D"auto">My state if art is</div><div dir=3D=
"auto"><br></div><div dir=3D"auto">that=C2=A0</div><div dir=3D"auto"><br></=
div><div dir=3D"auto">ldapsearch works well in both cases binded to rxistin=
g user or annonymous user as well</div><div dir=3D"auto"><br></div><div dir=
=3D"auto">but=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"auto">pamt=
ester =C2=A0ldap =C2=A0fodrek authenticate =C2=A0open_session</div><div dir=
=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto">pamtester=
 =C2=A0nss =C2=A0fodrek authenticate =C2=A0open_session</div><div dir=3D"au=
to"><br></div><div dir=3D"auto">as well as</div><div dir=3D"auto"><br></div=
><div dir=3D"auto">pamtester =C2=A0sss fodrek authenticate =C2=A0open_sessi=
on</div><div dir=3D"auto"><br></div><div dir=3D"auto">results in same outpu=
t</div><div dir=3D"auto"><br></div><div dir=3D"auto">dap_msgfree</div><div =
dir=3D"auto">pamtester: successfully authenticated</div><div dir=3D"auto">(=
rdconf1.c:154): You do not exist? fodrek? Success.</div><div dir=3D"auto">(=
pam_mount.c:598): error expanding configuration</div><div dir=3D"auto">ldap=
_unbind</div><div dir=3D"auto">ldap_free_connection 1 1</div><div dir=3D"au=
to">ldap_send_unbind</div><div dir=3D"auto">ber_flush2: 7 bytes to sd 4</di=
v><div dir=3D"auto">=C2=A0 0000: =C2=A030 05 02 01 05 42 00 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 0....B. =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=C2=A0</div><di=
v dir=3D"auto">tls_write: want=3D36, written=3D36</div><div dir=3D"auto">=
=C2=A0 0000: =C2=A0.... =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0PS.v =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=C2=A0</div><div dir=3D"auto">ldap_write: wa=
nt=3D7, written=3D7</div><div dir=3D"auto">=C2=A0 0000: ....B. =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0=C2=A0</div><div dir=3D"auto">tls_write: want=3D31,=
 written=3D31</div><div dir=3D"auto">=C2=A0 0000: =C2=A0.....</div><div dir=
=3D"auto">=C2=A0 =C2=A0 =C2=A0 ...i.9....F..;A =C2=A0=C2=A0</div><div dir=
=3D"auto">ldap_free_connection: actually freed</div><div dir=3D"auto">tls_w=
rite: want=3D31 error=3DBad file descriptor</div><div dir=3D"auto"><br></di=
v><div dir=3D"auto">pamtester: Insufficient credentials to access authentic=
ation data</div><div dir=3D"auto"><br></div><div dir=3D"auto">If I do not p=
lace open_session in the command last line of output is missing</div><div d=
ir=3D"auto"><br></div><div dir=3D"auto">same ctedential missing output is f=
or acct_mgmt</div><div dir=3D"auto">and =C2=A0chauthtook and authenticate a=
re only operations that works.</div><div dir=3D"auto"><br></div><div dir=3D=
"auto"><br></div><div dir=3D"auto">Is there anybody who us able to send me =
any recommendation, what am I to check</div><div dir=3D"auto">to get =C2=A0=
PAM to work here,please?</div><div dir=3D"auto"><br></div><div dir=3D"auto"=
>LDAP server is external server=C2=A0</div><div dir=3D"auto"><br></div><div=
 dir=3D"auto">usage of</div><div dir=3D"auto"><br></div><div dir=3D"auto">p=
am-auth-update --force=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"a=
uto">only allow me to get system into logging with unix authentofication me=
thod but automatic logout =C2=A0after several seconds=C2=A0</div><div dir=
=3D"auto">when =C2=A0I disable =C2=A0AFS session mamagement on Ubuntu 16.10=
 system</div><div dir=3D"auto"><br></div><div dir=3D"auto">But I am not abl=
e to log in using LDAP account in thos case,too.</div><div dir=3D"auto"><br=
></div><div dir=3D"auto"><br></div><div dir=3D"auto">Originally there were =
system configured to use both PAM for log and SASL for Subversion repositor=
y access control.</div><div dir=3D"auto"><br></div><div dir=3D"auto"><br></=
div><div dir=3D"auto">Thank you for any answer</div><div dir=3D"auto"><br><=
/div><div dir=3D"auto">I look forward hearing from you</div><div dir=3D"aut=
o"><br></div><div dir=3D"auto">Yours faithfully</div><div dir=3D"auto"><br>=
</div><div dir=3D"auto"><br></div><div dir=3D"auto">Peter Fodrek=C2=A0</div=
><div dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto">=
<br></div><div dir=3D"auto"><br></div><div dir=3D"auto"><br></div></div>

--001a1147f990c7f3ba05478d35d9--


--===============8557410546890963991==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Pam-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/pam-list
--===============8557410546890963991==--