LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-22-2009, 03:46 PM   #1
sydney-troz
Member
 
Registered: Feb 2007
Distribution: Kubuntu, it's obese barely-usable sibling, Ubuntu
Posts: 142

Rep: Reputation: 15
Ubuntu GDM ignores passwords for local users


I have PAM configured to allow Novell logins using ncpfs and the pam_ncp_auth.so module. However, I recently discovered that, for local users (I have a local account for administration), I can enter any password, or no password at all, and it allows the login. Sudo still behaves normally, and /var/log/auth.log shows nothing other than gdm having trouble unlocking a keyring (because I'm not entering the correct password, no doubt). The only thing I added/changed to the PAM config is in common_auth, I changed pam_unix.so to sufficient (instead of required).

I know I haven't provided a huge amount of info about the system, but I went through the same procedure on a test system beforehand and never ran into these problems. Any ideas?
 
Old 01-23-2009, 09:47 AM   #2
sydney-troz
Member
 
Registered: Feb 2007
Distribution: Kubuntu, it's obese barely-usable sibling, Ubuntu
Posts: 142

Original Poster
Rep: Reputation: 15
Ok, well, I feel like an idiot: I don't know why this didn't show up on my test machine, but the reason local passwords were ignored was that the "sufficient" control-flag will ignore failed modules. The reason I configured it this way was because I was under the impression that just changing common-auth would make it simpler for any other services to use Novell to authenticate.

So to fix it, I changed common-auth to "auth required pam_unix.so nullok secure", and added a custom sufficient line to the gdm service. After the pam_ncp_auth.so module, I then included an "auth required pam_deny.so".

So much for an elegant solution >_<
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Samba - Not Updating Local User Passwords in /Etc/Shadow JeffC1 Linux - Software 0 09-07-2008 08:29 PM
Users without passwords ahmedb72 Solaris / OpenSolaris 1 08-22-2007 05:05 AM
Struggling to setup a Debian/etch desktop: LDAP users and LOCAL users jferrando Linux - Networking 1 05-05-2006 03:44 PM
Sync MySQL passwords with local account passwords? turbine216 Linux - Software 2 02-18-2005 03:15 AM
Samba and local passwords Qauzzix Linux - Networking 1 08-17-2004 01:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration