LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-28-2013, 09:45 PM   #1
mjm295
LQ Newbie
 
Registered: Feb 2010
Posts: 9

Rep: Reputation: 0
authenticating against AD - PAM issue?


Hi

We have a setup on 50+ servers that works fine. I have ducplicated the set up to a number of new servers and "some" of them have big issues authenticating against AD.

If I login as a local user, then
Code:
 "su - AD.USER"
I can login OK allbeit slow.

If I ssh directly from my PC and login as the AD USER, it takes ages and eventually times out.

I see this issue:
as soon as I hit enter after typing the password this appears in the secure log:
Quote:
su: pam_unix(su-l:auth): authentication failure; logname=root uid=999 euid=0 tty=pts/0 ruser=LOCALUSER rhost= user=AD.USER

OR pam_unix(sshd:auth) for ssh from PC
This appears for both ssh from PC and su from another local account.

So as I mentioned, the ssh from PC times out.

But the su - from a local account is successful, and this is what gets logged:

Quote:
May 29 12:36:11 HOSTNAME su: pam_krb5[5383]: error reading keytab 'FILE:/etc/krb5.keytab'
May 29 12:36:41 HOSTNAME su: pam_krb5[5383]: TGT verified
May 29 12:36:41 HOSTNAME su: pam_krb5[5383]: authentication succeeds for 'AD.USER' (AD.USER@AD.DOMAIN)
May 29 12:36:41 HOSTNAME su: pam_unix(su-l:session): session opened for user AD.USER by root(uid=999)
The timestamp for the error reading keytab is 95 seconds after the pam auth error.

I have other servers that also give the auth - authentication error, but they drop to the krb5 part straight away (without the 95 second delay) and AD users can log in fine.

So, question is - where is the delay coming from?
 
Old 05-29-2013, 04:44 PM   #2
custangro
Senior Member
 
Registered: Nov 2006
Location: California
Distribution: Fedora , CentOS , RHEL
Posts: 1,979
Blog Entries: 1

Rep: Reputation: 209Reputation: 209Reputation: 209
What OS is the Linux System?

--C
 
Old 05-29-2013, 05:50 PM   #3
mjm295
LQ Newbie
 
Registered: Feb 2010
Posts: 9

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by custangro View Post
What OS is the Linux System?

--C
RedHat 6.3
 
Old 05-30-2013, 12:02 PM   #4
custangro
Senior Member
 
Registered: Nov 2006
Location: California
Distribution: Fedora , CentOS , RHEL
Posts: 1,979
Blog Entries: 1

Rep: Reputation: 209Reputation: 209Reputation: 209
What method are you using?

SSSD? Windbind?

--C
 
Old 05-30-2013, 11:28 PM   #5
mjm295
LQ Newbie
 
Registered: Feb 2010
Posts: 9

Original Poster
Rep: Reputation: 0
winbind + kerberos

interestingly - we moved the boxes to the same zone as the AD server in the firewall. and the delays all go away. So something funky could be happening in the firewall. its got the network boys stumped.

we tried an any/any rule from the original zone and the issue is still there.

So it's with the firewall guy for now...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Authenticating over PAM/NIS with php ichrispa Linux - Security 0 03-20-2011 09:49 PM
fedora 11 gui logon not authenticating (not root) pam authentication to kde masterDL Fedora 2 04-04-2010 10:31 PM
Ubuntu 8.04 / LDAP / NSS / PAM - not sharing shadow password hence not authenticating fuzzyworm Linux - Server 5 01-01-2009 03:29 PM
how to stop pam from authenticating su slug420 Linux - Security 2 08-13-2004 07:55 AM
ProFTPd. Authenticating using /etc/passwd instead of PAM wenberg Linux - Software 2 01-04-2004 10:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration