Bluehost.com Web Hosting $6.95

[Samba] pam_winbind module and "account" use

This is a discussion on [Samba] pam_winbind module and "account" use within the Samba forums, part of the Networking and Network Related category; Someone on the pam mailing list suggested I try my question here. In our pam.d/imap we have: account ...


Go Back   Usenet Forums > Networking and Network Related > Samba

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-18-2008
D G Teed
 
Posts: n/a
Default [Samba] pam_winbind module and "account" use

Someone on the pam mailing list suggested I try my
question here.

In our pam.d/imap we have:

account required pam_permit.so
auth sufficient pam_winbind.so try_first_pass

Authentication for imap works fine with this.

If we switch to :

account sufficient pam_winbind.so

for the first line, then logins using their AD password fail.

We also have a non-AD ldap authentication server,
and have found that these line works fine for ldap
(no pam_permit):

account sufficient pam_ldap.so
auth sufficient pam_ldap.so try_first_pass

We would like to implement a pam_groupdn within ldap,
and so that would require using account on both:

account sufficient pam_winbind.so
account sufficient pam_ldap.so

However we can't use the above with pam_winbind failing.

ssh uses /etc/pam.d/system-auth in Redhat, and Redhat has this
account related clump:

account required pam_unix.so broken_shadow
account sufficient pam_localuser.so
account sufficient pam_succeed_if.so uid < 500 quiet
account [default=bad success=ok user_unknown=ignore] pam_ldap.so
account [default=bad success=ok user_unknown=ignore] pam_krb5.so
account [default=bad success=ok user_unknown=ignore] pam_winbind.so
account required pam_permit.so

ssh logins using winbind authentication are working well with the
above account clump in place.

Perhaps I don't understand the meaning of the account section. Wouldn't
the above always succeed due to the pam_permit line?

We are at samba-client-3.0.25b , pam-0.99.6.2-3.26 and
pam_smb-1.1.7-7.2.1

--Donald
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/listinfo/samba

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 09:25 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0