From: Mark Bainter <mark-gt@cymry.org>
To: gentoo-dev@gentoo.org
Subject: [gentoo-dev] SSH, PAM, and LDAP
Date: Mon, 21 Apr 2003 18:48:08 -0500 [thread overview]
Message-ID: <20030421234808.GG2114@firinn.org> (raw)
Ok, I have recently gotten LDAP working for most of the stuff I want it to do,
and proceeded to move authentication to it. In doing so I have discovered that
OpenSSH does not play nice with PAM + LDAP.
>From what I have gathered from preliminary google digging is that the
priviledge seperation rewrite broke PAM pretty severely. None of the password
expiry stuff works anymore, and neither does the create home dirs option.
I've already tried simply disabling the PrivSep stuff, but the problem goes
deeper than that, so it doesn't help. Everything else (telnet/ftp/etc) works
fine, it's only ssh that's giving me fits.
I'm sure I'm not the only one with a setup like this. If someone else
on the list is running in a configuration of this nature and has gotten
ssh working, I'd appreciate a pointer to the information that got you past
this.
Thanks.
--
Treat root like a loaded gun. Don't pull it out unless you mean to use it.
If you mean to use it make sure you have a clear target and put it right
back in the holster as soon as you're done.
--
gentoo-dev@gentoo.org mailing list
next reply other threads:[~2003-04-21 23:48 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-04-21 23:48 Mark Bainter [this message]
2003-04-22 12:56 ` [gentoo-dev] SSH, PAM, and LDAP Ryan Henry [mailing list]
2003-04-22 13:59 ` Mark Bainter
2003-04-22 22:07 ` Grant Goodyear
2003-04-23 1:16 ` Mark Bainter
[not found] ` <1051050155.20764.4.camel@tux>
2003-04-23 1:51 ` Grant Goodyear
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20030421234808.GG2114@firinn.org \
--to=mark-gt@cymry.org \
--cc=gentoo-dev@gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox