LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 06-03-2011, 02:53 AM   #1
vijith.pa@gmail.com
LQ Newbie
 
Registered: Feb 2009
Posts: 26

Rep: Reputation: 0
Authentication Failure in LDAP after the Modification of ldap to ldaps url


Hi Guyz,

I Configured LDAP Server on ubuntu Server 10.04 ,(using url ldap) and Client also it's working fine ,After that i changed to ssl encryption and create certificate in server side ,Now it's not authenticating from server it's shows Incorrect Password ,but i can login though terminal if i am root user ,then it not ask any password it's logon to ldap user.

after i changed to ldap server to ssl encryption and made one changes in client side uri ldaps://ip-address/ ( /etc/ldap.conf)

anyone pls tell what was the problem for it's occurs? am waiting for ur reply?
 
Old 06-03-2011, 04:28 AM   #2
blue_print
Member
 
Registered: May 2010
Location: In world
Distribution: RHEL, CentOS, Ubuntu
Posts: 275
Blog Entries: 3

Rep: Reputation: 50
Are you able to connect the LDAP server (through LDAPS URL) from your client machine? Try using
Code:
getent passwd
. It may get hung up if any issues with the certificate.
 
Old 06-03-2011, 04:32 AM   #3
blue_print
Member
 
Registered: May 2010
Location: In world
Distribution: RHEL, CentOS, Ubuntu
Posts: 275
Blog Entries: 3

Rep: Reputation: 50
Please add the following in /etc/ldap.conf" in client machine and try,
Code:
TLS_REQCERT allow
 
Old 06-03-2011, 05:30 AM   #4
vijith.pa@gmail.com
LQ Newbie
 
Registered: Feb 2009
Posts: 26

Original Poster
Rep: Reputation: 0
Thank u ..

am tried with getent passwd command in client it will shows all ldap users like
sree:x:10002:10000:Sree Kumar:/home/sree:/bin/bash
renjith:x:10003:10001:Renjith Kumar:/home/renjith:/bin/bash
hari:x:10005:10000:Hari Kumar:/home/hari:/bin/bash


this (TLS_REQCERT allow) i added my ldap.conf in client side then also same problem

client log auth.log
Jun 3 15:56:10 ldap su[1929]: pam_ldap: ldap_simple_bind Can't contact LDAP server
Jun 3 15:56:10 ldap su[1929]: pam_ldap: reconnecting to LDAP server...
Jun 3 15:56:10 ldap su[1929]: pam_ldap: ldap_simple_bind Can't contact LDAP server
Jun 3 15:56:12 ldap su[1929]: pam_authenticate: Authentication failure
Jun 3 15:56:12 ldap su[1929]: FAILED su for hari by sysadm
Jun 3 15:56:12 ldap su[1929]: - /dev/pts/1 sysadm:hari


while accessing user from graphical auth.log
Jun 3 16:09:09 ldap gdm-session-worker[1531]: pam_succeed_if(gdm:auth): requirement "user ingroup nopasswdlogin" not met by user "hari"
Jun 3 16:09:12 ldap gdm-session-worker[1531]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost= user=hari


Any Solution for this ?

Last edited by vijith.pa@gmail.com; 06-03-2011 at 05:40 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Authentication Failure After Lock Screen in LDAP? (Ubuntu 10.04) vijith.pa@gmail.com Linux - Newbie 0 06-01-2011 12:42 AM
[SOLVED] Apache authentication: allow LDAP group OR user named guest, but not all LDAP users AlucardZero Linux - Server 1 05-25-2011 03:21 PM
secure ldap connectivity and store certificate and url tanveer Linux - Server 4 11-08-2009 12:22 PM
Contacting LDAP server fails under load when using LDAPS (ssl) kingbolete Linux - Server 0 09-05-2008 10:16 AM
ldap authentication box_l Mandriva 0 03-22-2004 03:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 05:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration