i have done al steps of the HowTo "Authenticate AIX users from MSActive Directory", found in this forum, but it still does not work. The test with kinit USERNAME works fine. But if i try to login i get the "UNKNOWN_USER" error in the debug.log.All steps to change auth-methode are done. chgauthent, chuser, ...
I also have these lines in my /etc/methods.cfg, although I'm not sure what they do...
Code:
NIS:
program = /usr/lib/security/NIS
program_64 = /usr/lib/security/NIS_64
DCE:
program = /usr/lib/security/DCE
I also have both registry and SYSTEM set to "KRB5files"
Code:
hostname:/:$ lsuser -a registry SYSTEM user
user registry=KRB5files SYSTEM=KRB5files
hostname:/:$
---------- Post updated at 10:27 AM ---------- Previous update was at 10:22 AM ----------
I think I had to update those two lines, default_tkt_enctypes & default_tgs_enctypes, because the Windows team upgraded their servers to a later version of Windows.
I want to know, why the lsuser shows me registry=files even i have set registry to KRB5files with chuser.
I see in the /etc/security/user files that both values (registry and system) are set to KRB5files.
I find out, that this is a problem display problem which us known by IBM auf the lsuser command.
Code:
root@HOST[!]/etc/krb5>>grep -p kbtest /etc/security/user
kbtest:
admin = false
registry = KRB5files
SYSTEM = "KRB5files"
root@HOST[!]/etc/krb5>>lsuser -a registry kbtest
kbtest registry=files
---------- Post updated at 09:06 AM ---------- Previous update was at 08:45 AM ----------
Hi,
i have done the changes in the krb5.conf with no success.
Same entry in syslog.log
Code:
Jul 26 09:01:52 HOST auth|security:info syslog: pts/4: failed login attempt for UNKNOWN_USER from remote.host
kinit kbuser -> Works fine. The authentication by kinit is done with the DC.
Is it possible, that we have to configure our Kerberos-Service at the Windows DC ???
Last edited by Scott; 07-27-2012 at 04:55 AM..
Reason: Code tags
It may be something with your registry=files. Mine has KRB5files in both outputs:
Code:
hostname:/:$ grep -p user /etc/security/user | egrep "admin|registry|SYSTEM"
admin = true
auth1 = SYSTEM
registry = KRB5files
SYSTEM = "KRB5files"
hostname:/:$ lsuser -a registry SYSTEM user
user registry=KRB5files SYSTEM=KRB5files
hostname:/:$
---------- Post updated at 03:40 PM ---------- Previous update was at 03:32 PM ----------
Try to change the user back to a local user (registry=files SYSTEM=compat), set a random password, clear the password flag (pwdadm -c kah00na), then change the user back to KRB5files. Try to authenticate again using your Windows password... not the random password.
Code:
hostname:/:$ chuser registry=files SYSTEM=compat kah00na
hostname:/:$ passwd kah00na
Changing password for "kah00na"
kah00na's New password:
Enter the new password again:
hostname:/:$ pwdadm -q kah00na
kah00na:
lastupdate = 1343335112
flags = ADMCHG
hostname:/:$ pwdadm -c kah00na
hostname:/:$ pwdadm -q kah00na
kah00na:
lastupdate = 1343335112
hostname:/:$ chuser registry=KRB5Files SYSTEM=KRB5files kah00na
hostname:/:$
---------- Post updated at 03:47 PM ---------- Previous update was at 03:40 PM ----------
hi to all
i've done that steps, but i was not completely successful:
sudo pkg install group/feature/storage-server
sudo svcadm enable stmf
sudo zfs create -V 1g rpool/LUN1
sudo stmfadm create-lu /dev/zvol/rdsk/rpool/LUN1
sudo stmfadm list-lu ... (4 Replies)
Hi,
since the upgrade to Gnome 3.6 (now i have 3.8) the authentication over LDAP stops working. The whole machine does not start anymore. The machine boot, but no gdm and no X. I can login, with root, but then the tty hangs. When i look at ttyF12 i see a lot of systemd service the runs random,... (1 Reply)
Hi,
im new to Solaris (10) and need some help please.
Situation: Actually is there a Linux (SLES11) OpenLDAP-Server and authentification of Linux-Maschines works pretty sweet. Now i want to put the SOL10 (Sparc) boxes in....
Problem: User Authentification via OpenLDAP on Sol10 doesn´t work... (3 Replies)
HI,
I use redhat 5.7 .
I configure sendmail as client and deliver the email to the external SMTP server(10.1.1.176) .
The smtp server need SMTP AUTH in order to send email with SMTP.
I configure and follow this link .
Sendmail as SMTP Authentication | Free Linux Tutorials
I try to send... (1 Reply)
Good day
I am trying to configure Kerberos and LDAP authentication on AIX 5.3 with Windows 2003 R2 but something is not quite right.
When I ran kinit username I get a ticket and I can display it using klist.
When the user login I can see the ticket request on Windows 2003, but the user... (1 Reply)
Very strange one, we've got a recently build server (Sol10 via JET flash).
Bascially you can ssh to it fine, but telnet will allow entry of username, but will then feed in a carriage return on the passwd field, this also happens on any auth type command, ie passwd on a user account will also... (4 Replies)
:( hi all ,
i have installed netscape console on my local pc to connect to webmail server using LDAP .
when i try to login from my console i get an error
"Http Exception:
Response: Http/1.1 500 Server Error Status 500"
i was told that i need to add my IP to the local.conf file. ... (1 Reply)
While not technically a unix question, I was hoping for some help from you all-
I've got an Apache 1.3.x server, and I am using basic auth from the pam_auth module and winbind on the back of that. What I get is a relaly sleek authentication for my Windos domain users, however, as they are wont... (1 Reply)