Re: [Hampshire] LDAP, Debian, PAM?

Top Page
Author: Hugo Mills
Date:  
To: lug, Hampshire LUG Discussion List
Subject: Re: [Hampshire] LDAP, Debian, PAM?

Reply to this message
gpg: failed to create temporary file '/var/lib/lurker/.#lk0x57fc5100.hantslug.org.uk.27234': Permission denied
gpg: keyblock resource '/var/lib/lurker/pubring.gpg': Permission denied
gpg: Signature made Wed Oct 29 15:04:47 2008 GMT
gpg: using DSA key 20ACB3BE515C238D
gpg: Can't check signature: No public key
On Wed, Oct 29, 2008 at 02:21:14PM -0000, Vic wrote:
>
> OK - here's a *total* guess. But you prroblem looks similar to one I faced
> last week trying to get authentication against AD:
>
> > Oct 29 12:31:15 hactar su[3325]: (pam_unix) check pass; user unknown
> > Oct 29 12:31:15 hactar su[3325]: (pam_unix) authentication failure;
> > logname= uid=1000 euid=0 tty=pts/1 ruser=hrm rhost=
>
> Do you have to map local user account names to directory names? It seems
> to have a uid but no login name...


I'm using uid=test,ou=People,dc=... for the directory names. The
entries under ou=People,dc=... all have a uid: property which is the
login name, and uidNumber: property.

My pam_ldap.conf file contains the following:

# The user ID attribute (defaults to uid)
#pam_login_attribute uid

Hugo.

-- 
=== Hugo Mills: hugo@... carfax.org.uk | darksatanic.net | lug.org.uk ===
  PGP key: 515C238D from wwwkeys.eu.pgp.net or http://www.carfax.org.uk
   --- "It was half way to Rivendell when the drugs began to take ---    
              hold" - Hunter S Tolkien,  "Fear and Loathing              
                              in Barad D?r"