Portál AbcLinuxu, 10. května 2025 02:00

Dotaz: Problém s PAMem

11.2.2010 14:55 filbar | skóre: 36 | blog: Denicek_programatora | Ostrava
Problém s PAMem
Přečteno: 152×
Odpovědět | Admin
Na stroji s Gentoo mám problém s přihlášením pomocí sshd, PAM a Kerberosu u uživatelů, kteří nejsou uvedeni v /etc/passwd:
Feb 11 14:51:00 joomladev2 sshd[17172]: Authorized to sbartmanova, krb5 principal sbartmanova@JOOMLADEV.DYNDNS.ORG (krb5_kuserok)
Feb 11 14:51:00 joomladev2 sshd[17172]: debug3: mm_answer_gss_userok: sending result 1
Feb 11 14:51:00 joomladev2 sshd[17172]: debug3: mm_request_send entering: type 42
Feb 11 14:51:00 joomladev2 sshd[17172]: debug3: mm_request_receive_expect entering: type 50
Feb 11 14:51:00 joomladev2 sshd[17172]: debug3: mm_request_receive entering
Feb 11 14:51:00 joomladev2 sshd[17172]: debug1: do_pam_account: called
Feb 11 14:51:00 joomladev2 sshd[17172]: debug3: PAM: do_pam_account pam_acct_mgmt = 6 (Permission denied)
Feb 11 14:51:00 joomladev2 sshd[17172]: debug3: mm_request_send entering: type 51
Feb 11 14:51:00 joomladev2 sshd[17172]: Failed gssapi-with-mic for sbartmanova from 10.0.0.5 port 60917 ssh2
Feb 11 14:51:00 joomladev2 sshd[17172]: debug3: mm_request_receive entering
Feb 11 14:51:00 joomladev2 sshd[17172]: debug1: do_cleanup
Feb 11 14:51:00 joomladev2 sshd[17172]: debug1: PAM: cleanup
Feb 11 14:51:00 joomladev2 sshd[17172]: debug3: PAM: sshpam_thread_cleanup enterin
Obsah pam souborů je následující:
cat /etc/pam.d/sshd 
auth       include      system-remote-login
account    include      system-remote-login
password   include      system-remote-login
session    include      system-remote-login
 cat /etc/pam.d/system-remote-login 
auth            include         system-login
account         include         system-login
password        include         system-login
session         include         system-login
 cat /etc/pam.d/system-login 
auth            required        pam_tally.so onerr=succeed
auth            required        pam_shells.so 
auth            required        pam_nologin.so 
auth            include         system-auth
 
#account                required        pam_access.so 
account         required        pam_nologin.so 
account         include         system-auth
account         required        pam_tally.so onerr=succeed 
 
password        include         system-auth
 
session         required        pam_env.so 
session         optional        pam_lastlog.so 
session         include         system-auth
session         optional        pam_ck_connector.so nox11
session         optional        pam_motd.so motd=/etc/motd
session         optional        pam_mail.so
 cat /etc/pam.d/system-auth
#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth        required      pam_env.so
auth        sufficient    pam_unix.so nullok try_first_pass
auth        requisite     pam_succeed_if.so uid >= 500 quiet
auth        sufficient    pam_krb5.so use_first_pass
auth        required      pam_deny.so

account     required      pam_unix.so broken_shadow
account     sufficient    pam_localuser.so
account     sufficient    pam_succeed_if.so uid < 500 quiet
account     [default=bad success=ok user_unknown=ignore] pam_krb5.so
account     required      pam_permit.so

password    requisite     pam_cracklib.so difok=2 minlen=8 dcredit=2 ocredit=2 retry=3
password    sufficient    pam_unix.so sha512 shadow nullok try_first_pass use_authtok
password    sufficient    pam_krb5.so use_authtok
password    required      pam_deny.so

session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
session    optional    pam_mktemp.so
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so
session     optional      pam_krb5.so
Nevíte, kde mám chybu?

Předem děkuji za vaše rady.
Nástroje: Začni sledovat (1) ?Zašle upozornění na váš email při vložení nového komentáře.

Na otázku zatím nikdo bohužel neodpověděl.

Založit nové vláknoNahoru

Tiskni Sdílej: Linkuj Jaggni to Vybrali.sme.sk Google Del.icio.us Facebook

ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.