public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] SSH, PAM, and LDAP
@ 2003-04-21 23:48 Mark Bainter
  2003-04-22 12:56 ` Ryan Henry [mailing list]
  2003-04-22 22:07 ` Grant Goodyear
  0 siblings, 2 replies; 6+ messages in thread
From: Mark Bainter @ 2003-04-21 23:48 UTC (permalink / raw
  To: gentoo-dev

Ok, I have recently gotten LDAP working for most of the stuff I want it to do,
and proceeded to move authentication to it.  In doing so I have discovered that
OpenSSH does not play nice with PAM + LDAP.  

>From what I have gathered from preliminary google digging is that the
priviledge seperation rewrite broke PAM pretty severely.  None of the password
expiry stuff works anymore, and neither does the create home dirs option.

I've already tried simply disabling the PrivSep stuff, but the problem goes
deeper than that, so it doesn't help.  Everything else (telnet/ftp/etc) works
fine, it's only ssh that's giving me fits.

I'm sure I'm not the only one with a setup like this.  If someone else
on the list is running in a configuration of this nature and has gotten
ssh working, I'd appreciate a pointer to the information that got you past
this.

Thanks.

-- 
Treat root like a loaded gun. Don't pull it out unless you mean to use it.
If you mean to use it make sure you have a clear target and put it right
back in the holster as soon as you're done.

--
gentoo-dev@gentoo.org mailing list


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-04-23  1:51 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-04-21 23:48 [gentoo-dev] SSH, PAM, and LDAP Mark Bainter
2003-04-22 12:56 ` Ryan Henry [mailing list]
2003-04-22 13:59   ` Mark Bainter
2003-04-22 22:07 ` Grant Goodyear
2003-04-23  1:16   ` Mark Bainter
     [not found]   ` <1051050155.20764.4.camel@tux>
2003-04-23  1:51     ` Grant Goodyear

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox