Re: User login issue

Mike Gabriel <[email protected]>
Newsgroups gmane.linux.skolelinux.devel,gmane.linux.debian.devel.education
Organization DAS-NETZWERKTEAM
Message-ID <20240106124524.Horde.G18YAIueQfukuC5J1ANKS-i@mail.das-netzwerkteam.de>
Hi Roman,

On  Sa 06 Jan 2024 12:16:31 CET, roman.meier wrote:

> I can create a new user but the behavior is the same: I cannot login  
> on the server. Login into GOsa2 works fine.

This very likely means that your Kerberos layer / service stack is broken.

Do you have libpam-krb5 installed on TJENER? (That would be an easy solution).

Does the new user object in LDAP have krb* LDAP attributes?

If you launch kadmin.local and then enter "list_principals": do any  
Kerberos principals (users and/or hosts and/or services) get shown? Do  
the user accounts that fail login get listed by this?

If the new LDAP users don't get listed, try "add_princ -policy users  
<uid>" and try login from another tty.

If the new LDAP users get listed, try to set their password using "cpw <uid>".

Please also let me/us know what versions of Debian Edu you have  
installed (11 or 12)? If 12, have you upgraded to latest package  
versions? There was a bug in Debian Edu 12's debian-edu-config that  
only got resolved recently:

```
debian-edu-config (2.12.41~deb12u1) bookworm; urgency=medium

   * Upload to bookworm.

  -- Mike Gabriel <[email protected]>  Sun, 03 Dec 2023 08:45:42 +0100

debian-edu-config (2.12.41) unstable; urgency=medium

   [ Guido Berhoerster ]
   * gosa-sync: Decode the user password which GOsa substitutes base64 encoded.
     This fixes a bug where the user password could not be set or changed.
     (related to #1052159).

  -- Mike Gabriel <[email protected]>  Fri, 01 Dec 2023 21:44:38 +0100
```

This fix in d-e-c goes together with a fix in gosa:

```
gosa (2.8~git20230203.10abe45+dfsg-1+deb12u2) bookworm; urgency=medium

   [ Daniel Teichmann ]
   * debian/patches:
     [...]
     + Add 1044_fix-class-ldap-serialization.patch which fixes a few bugs
       regarding serialization. This especially fixes setting LDAP userPassword
       attribute types via GOsa². (Closes: #1052159).
     + Add 1045_fix-posixaccount-shadowExpire.patch which fixes shadowExpire
       always being set to 0. (User can't login then). (Closes: #1053806).

   [ Guido Berhoerster ]
   * debian/patches:
     [...]

   [ Mike Gabriel ]
   * debian/patches:
     [...]

  -- Mike Gabriel <[email protected]>  Sun, 03 Dec 2023 08:16:31 +0100

If you Debian Edu 12, simply upgrading d-e-c and gosa to the  
referenced versions should help.

Mike
```
-- 

DAS-NETZWERKTEAM
c\o Technik- und Ökologiezentrum Eckernförde
Mike Gabriel, Marienthaler Str. 17, 24340 Eckernförde
mobile: +49 (1520) 1976 148
landline: +49 (4351) 850 8940

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: [email protected], http://das-netzwerkteam.de
signature.asc (application/pgp-signature, 851 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIzBAABCgAdFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAmWZS2IACgkQmvRrMCV3
GzEcQQ/+IqEtOyhdOdCU85UD2EIfX1j5KYmv9aKkNHsLyJ7IcxR1mXjijz9hCyop
rEbqRp0zqcHIvzyjf4quJyDClxau43ki/wM1zfwU80ZkZfsQ7uIhkiThh6LjCl9F
BrCM/jyNPT3iQl9ukrfh/69L0/FmTuvOJ/FU3gleQBR6p7hgcHfR/yA1zhX3uPbP
K7IZ7ntXGMyHqICWa28YU3oSGJ7sVlgkhkvuCwgYCNSaY+qi4wvJraOTSpJNXN4R
hNc9TBwFQuNe4Si0LeyRQOc8Lp+QASMuoyPzQ7jE73aztlymtECNgglZlixe5oRt
6Ec+OtzWS/ur7G+pdQwcE+jqrCs3U42pu15Eczm+Sfeko+ldIBRt3iX6QB71YHKP
IQIlfCniaPesva/uVplQYEL0hCpzZnO0YXfQvpIv9lz6LJnDTgZ26hgFTqlTc+Oe
WGOirZdMrPc7eyq/ueQSf00cQFM929bgsXJda/P1Dus3sGJ2QeCR4XWsEShhlmY0
I2lZ8EJoxJ3F4huktTV7jUKy0AYSRHusMxl/ZyIeWNd8s1WAQpkEOkFsb+NSfX2t
EJJSCIbCcljxuWnY7z1u4ZuPmlMXJYBDzB6DD1qN20Aa/CP0HQ/TVroE4Dg9pF/m
1LeT9yO1vUroMZa/1jIs57lgDeQLX5jPGtNV26lzFtEZK5jwVHs=
=Mtkq
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.