Using passwd with LDAP
Staffan Thomén <[email protected]>
| Newsgroups | gmane.os.netbsd.help |
|---|---|
| Message-ID | <[email protected]> |
Hi, I've set up ldap authentication on my NetBSD 3.1 system parallell to my local users, everything works, login, ssh, su except passwd. As it is, only root is able to change the password of an ldap user (note: it is NOT set in the local passwd database). If the ldap user tries to run passwd they're asked for the old password, and upon entry they get; Unable to change auth token: permission denied Now I have tested this out, and the LDAP account that I use for managing the affairs of nss and pam are able to edit the requisite fields. There is no difference other than that root is asked for the old password if I disbale the usage of rootbinddn. Also the user (self) is able to write to their own password field. It seems to me that there is some--possibly archaic--quirk in the password system that is blocking the user from changing their password; and so I ask for enlightenment :-) There is quite alot of configuration files here, instead of spamming everything here I'll let you request anything you feel is pertinent. Yours, Staffan
PGP.sig
(application/pgp-signature, 186 B) - not displayed