15 msgUNSUBSCRIBE
4 msgtartini (one of the security mirrors) unreliable
1 msgInvalid signature for Releases packages
3 msgCVE-2006-0225, scponly shell command possible
2 msgproblem with unsubscribe
1 msgRE: [SECURITY] [DSA 967-1] New elog packages fi...
1 msgRe: neighbour
1 msgOnly 2 Weeks Required r05Cxx
1 msgWe will not receive your email
1 msgÏàäåíèå öåí!
1 msgQuery
1 msgThorsten Weber ist abwesend.
1 msgloreen Rosa
2 msgStrange outbound connections
1 msgRe: providence
6 msgnmap -sT and open ports from a friends
1 msgRe: [SECURITY] [DSA 963-1] New mydns packages f...
1 msgRe: forget

Password authentication with LDAP and SSH
\ Jonas Liljenfeldt (1 Feb 2006)
. \ Geoff Crompton (1 Feb 2006)
. . \ aflorent (1 Mar 2006)
. . . \ Martijn Marsman (2 Mar 2006)
. . . . \ Nicolas François (3 Mar 2006)
. \ Sergio Talens-Oliag (1 Mar 2006)
. \ Marcos S. Trazzini (3 Mar 2006)

6 msgWeird message in my apache error log
Subject:Password authentication with LDAP and SSH
Group:Debian-security
From:Jonas Liljenfeldt
Date:1 Feb 2006


 

Hello all,

I run Debian Sarge and I have a problem with my SSH server (in
combination with password authentication and LDAP). It doesn't work
well with password authentication when I try to login as a LDAP user
but it works well for users in /etc/passwd. If I try to login as a LDAP
user via SSH and keyboard interactive as autentication mechanism it
works good.

In /var/log/auth.log this message appears when a LDAP user tries to
login with password authentication:

Feb 1 06:54:28 hostname sshd[4691]: Failed password for username
from ::ffff:127.0.0.1 port 53071 ssh2

In /etc/nsswith I have:

passwd: files ldap
group: files ldap
shadow: files ldap
hosts: files dns
networks: files
protocols: db files
services: db files
#services compat ldap
ethers: db files
rpc: db files
netgroup: nis


The SSH server is told to use PAM (UsePAM yes) and accept password
authentication (PasswordAuthentication yes). The SSH server also reports
that it accepts password authentication.

In /etc/pam.d/pam_ldap.conf I have tried with some different values for
the "pam_password" parameter (like the algoritm used in LDAP for a test
user's password). Still no success. Are there are any usual mistakes
for that configuration file?

I once tried to add a LDAP user in /etc/passwd and /etc/shadow too and
then it worked. I gave the LDAP user the same password as another user
in /etc/shadow and logged in. It is of course not a nice solution to
syncronize the LDAP database with /etc/passwd and /etc/shadow though...

Any answers are appreciated.



© 2004-2008 readlist.com