The KRB5ALDAP compound load module is giving me fits. Everything looks like it should be working, but no.
Goal: Integrate AIX host with Active Directory using a KRB5ALDAP compound load module so that users can be created in AD and used in AIX, with unix attributes (registry values) being pulled from AD. Eliminate the need to manage user accounts on a per-server basis.
Issue: User attributes are visible with lsuser and returned with ldapsearch. Kerberos authentication shows successful at the domain controller, but a "permission denied" or "invalid login or password" message is displayed. Files can be chown-ed to the user accounts, but SU fails.
I attached a doc with the pertinent configs and troubleshooting steps. Since making that doc, I have also chased the enctype (switched to solely RC4) and the KVNO (tried 2, 3, 4). But no love.
I am getting the following error message when trying to login to the client:
while verifying tgt
If I move the /etc/krb5.keytab out of /etc, it works fine. This is HP-UX v23
Does anyone have any ideas? (1 Reply)
I'm having troubles setting up a client(with Ubuntu 8.10) for a ldap+samba server. I can't authenticate through the client with gdm, the messages I have in /etc/auth.log at the client is
Dec 4 14:21:56 myuser-mydesktop gdm: nss_ldap: failed to bind to LDAP server ldap://192.168.0.1: Invalid... (5 Replies)
Good day
I am trying to configure Kerberos and LDAP authentication on AIX 5.3 with Windows 2003 R2 but something is not quite right.
When I ran kinit username I get a ticket and I can display it using klist.
When the user login I can see the ticket request on Windows 2003, but the user... (1 Reply)
Hello, I asked this question in the AIX subforum but never received an answer, probably because the AIX forum is not that heavily trafficked. Anyway, here it is..
I have never had any issues like this when compiling applications from source. When I try to compile samba-3.5.0pre2, configure runs... (9 Replies)
Hi, FYI, I'm new in Solaris
I'm trying to use Kerberos on authenticating LDAP Client with the Active Directory on Windows Server 2003 on both Solaris 10 5/08 and Solaris 10 9/10 by referring to the pdf file kerberos_s10.pdf available at sun official site.
... (0 Replies)
I've configured an AIX 5.3 client to use our Windows AD for user authentication via Kerberos.
When I try to ssh to the server using the AD credentials, I eventually get access but not after getting prompted for a password 3 times (which doesn't work) followed by an accepted login on the 4th... (3 Replies)
I have been able to configure on an AIX 5.2 ldap.cfg so service starts correctly.
but when I try to log on with a windows user after entering the password login hangs and get no response.
I have set it up on Aix 5.3 with no problem but in Aix 5.2 I have not been able to log in.
ldap.cfg... (1 Reply)
Hi all,
I have installed samba 3.6.22 on AIX 7.1 and join a windows AD with success.
All seem to work fine, I have configured smb.conf, methods.cfg, kerberos, user .... the following command work fine wbinfo -u, wbinfo -g, wbinfo -i, wbinfo -s, wbinfo -S, lsuser, id...
The unique... (20 Replies)
Has anyone attempted to define GPO / HBAC policies in Windows Server 2012 that could be respected by Kerberos/LDAP on AIX?
I'm looking to associate servers to groups so that when a user part of a group tries to login to a host not associated with that group, it would be denied. This would allow... (3 Replies)
Discussion started by: Devyn
3 Replies
LEARN ABOUT OSF1
dxaccounts
dxaccounts(8) System Manager's Manual dxaccounts(8)NAME
dxaccounts - Graphical interface for account administration
SYNOPSIS
/usr/bin/X11/dxaccounts
DESCRIPTION
The Account Manager application, dxaccounts, helps you manage user accounts on your Tru64 UNIX system. It operates on both base security
level systems and enhanced security (C2) level systems.
The Account Manager application lets you manage both the local and Network Information Service (NIS) UNIX account databases. NIS is used in
order to centrally manage user accounts in a network environment. NIS lets participating systems share a common set of passwd and group
files. NIS uses a client-server model.
When the Advanced Server for Tru64 UNIX product is installed, the Account Manager application allows you to perform domain user account
management for PC users.
To start Account Manager from the CDE desktop:Choose the Application Manager from the CDE front panel. Choose the System_Admin group.
Choose the DailyAdmin group. Click on the Account Manager icon.
Online help is available for the dxaccounts application. To get help, click on any Help button or use the Help pull-down menu.
Account Manager replaces the XSysAdmin(8) and XIsso(8) applications.
RESTRICTIONS
You must have root privileges to modify system files with this application. If dxaccounts is run without root permission, you may view but
not modify account information.
In order to make changes to the NIS databases, you must run Account Manager on the machine designated as the NIS server.
FILES
Defaults that are shared by the graphical user and command-line interfaces System and account defaults (enhanced security only) Group
information for local groups Account information for local user accounts List of shells on the system Group information for NIS groups (on
an NIS master) Account information for NIS user accounts (on an NIS master) Protected password authentication database files (enhanced
security only) Protected password database (enhanced security only) Protected password database (enhanced security only) Account Manager
application Account Manager help volume Account Manager help volume for enhanced security Directory containing Account Manager application
icons Application defaults file that sets the default values for the X resources Account Manager message catalog Default directory for user
account initial files
SEE ALSO
Commands: auditmask(8), authck(8), groupadd(8), groupdel(8), groupmod(8), login(1), nis_intro(7), passwd(1), secsetup(8), useradd(8),
userdel(8), usermod(8), XIsso(8), XSysAdmin(8)
Functions: acceptable_password(3), getprpwent(3), getpwent(3)
Files: authcap(4), default(4), group(4), passwd(4)
Manuals: System Administration, Advanced Server for UNIX Installation and Administration, Advanced Server for UNIX Concepts and Plan-
ning</docbook>
dxaccounts(8)