i have done al steps of the HowTo "Authenticate AIX users from MSActive Directory", found in this forum, but it still does not work. The test with kinit USERNAME works fine. But if i try to login i get the "UNKNOWN_USER" error in the debug.log.All steps to change auth-methode are done. chgauthent, chuser, ...
I have done all the steps from the thread(HowTo) "Authenticate AIX users from MSActive Directory.
And somthing mor from other descriptions (IBM,...)
Here are my configuration:
krb5.conf
methods.cfg
Maybe here is a problem? Why registry=files ?
Imported key with ktpass and ktutil
AUTH with kinit works.
But not with telnet (debug.log):
If i set the user kbtest back to local AUTH then i can loggin.
I have also done a trace with tcpdump on port 88 and i see that during the loggin with kerberos AUTH the communication with the DC.
Hope anybody can help me.
Regards,
Thomas
Last edited by Scott; 07-27-2012 at 04:54 AM..
Reason: Code tags
Update your /etc/krb5.conf "[libdefaults]" section with these lines:
I also have these lines in my /etc/methods.cfg, although I'm not sure what they do...
I also have both registry and SYSTEM set to "KRB5files" ---------- Post updated at 10:27 AM ---------- Previous update was at 10:22 AM ----------
I think I had to update those two lines, default_tkt_enctypes & default_tgs_enctypes, because the Windows team upgraded their servers to a later version of Windows.
It may be something with your registry=files. Mine has KRB5files in both outputs: ---------- Post updated at 03:40 PM ---------- Previous update was at 03:32 PM ----------
Try to change the user back to a local user (registry=files SYSTEM=compat), set a random password, clear the password flag (pwdadm -c kah00na), then change the user back to KRB5files. Try to authenticate again using your Windows password... not the random password. ---------- Post updated at 03:47 PM ---------- Previous update was at 03:40 PM ----------
hi to all
i've done that steps, but i was not completely successful:
sudo pkg install group/feature/storage-server
sudo svcadm enable stmf
sudo zfs create -V 1g rpool/LUN1
sudo stmfadm create-lu /dev/zvol/rdsk/rpool/LUN1
sudo stmfadm list-lu ... (4 Replies)
Hi,
since the upgrade to Gnome 3.6 (now i have 3.8) the authentication over LDAP stops working. The whole machine does not start anymore. The machine boot, but no gdm and no X. I can login, with root, but then the tty hangs. When i look at ttyF12 i see a lot of systemd service the runs random,... (1 Reply)
Hi,
im new to Solaris (10) and need some help please.
Situation: Actually is there a Linux (SLES11) OpenLDAP-Server and authentification of Linux-Maschines works pretty sweet. Now i want to put the SOL10 (Sparc) boxes in....
Problem: User Authentification via OpenLDAP on Sol10 doesn´t work... (3 Replies)
HI,
I use redhat 5.7 .
I configure sendmail as client and deliver the email to the external SMTP server(10.1.1.176) .
The smtp server need SMTP AUTH in order to send email with SMTP.
I configure and follow this link .
Sendmail as SMTP Authentication | Free Linux Tutorials
I try to send... (1 Reply)
Good day
I am trying to configure Kerberos and LDAP authentication on AIX 5.3 with Windows 2003 R2 but something is not quite right.
When I ran kinit username I get a ticket and I can display it using klist.
When the user login I can see the ticket request on Windows 2003, but the user... (1 Reply)
Very strange one, we've got a recently build server (Sol10 via JET flash).
Bascially you can ssh to it fine, but telnet will allow entry of username, but will then feed in a carriage return on the passwd field, this also happens on any auth type command, ie passwd on a user account will also... (4 Replies)
:( hi all ,
i have installed netscape console on my local pc to connect to webmail server using LDAP .
when i try to login from my console i get an error
"Http Exception:
Response: Http/1.1 500 Server Error Status 500"
i was told that i need to add my IP to the local.conf file. ... (1 Reply)
While not technically a unix question, I was hoping for some help from you all-
I've got an Apache 1.3.x server, and I am using basic auth from the pam_auth module and winbind on the back of that. What I get is a relaly sleek authentication for my Windos domain users, however, as they are wont... (1 Reply)