LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-17-2008, 01:10 PM   #1
martinhb
LQ Newbie
 
Registered: Nov 2008
Posts: 5

Rep: Reputation: 0
Suppressing incorrect login messages


I am running Red Hat Enterprise Linux 4 using OpenLDAP 2.3 for authentication. As part of a security audit we have been asked to suppress any incorrect login information. Our system boots up to a command line login prompt and if an incorrect username is entered then an error message to that effect is displayed and if an incorrect password is entered then a message stating that password is incorrect is displayed. I am not even sure where I should be looking to solve this. I have tried the OpenLDAP documentation and PAM documentation with no luck. What I am trying to achieve is fot the system to report "login incorrect" whether the username or password is incorrect.

Thanks Martin
 
Old 11-17-2008, 03:27 PM   #2
irishbitte
Senior Member
 
Registered: Oct 2007
Location: Brighton, UK
Distribution: Ubuntu Hardy, Ubuntu Jaunty, Eeebuntu, Debian, SME-Server
Posts: 1,213
Blog Entries: 1

Rep: Reputation: 88
This does not come from LDAP! I'm not sure where it is setup in RHEL, but it's within the individual machine.
 
Old 11-17-2008, 08:36 PM   #3
estabroo
Senior Member
 
Registered: Jun 2008
Distribution: debian, ubuntu, sidux
Posts: 1,126
Blog Entries: 2

Rep: Reputation: 124Reputation: 124
Is it coming from the login program itself? If you get the source for it that message is in passwd.c and the Login incorrect one is in login.c otherwise it probably is from pam getting passed back, so probably still supressible in login (take a look at the PAM_FAIL_CHECK macro)
 
Old 11-18-2008, 02:56 AM   #4
martinhb
LQ Newbie
 
Registered: Nov 2008
Posts: 5

Original Poster
Rep: Reputation: 0
I have an old system that also runs RHEL 4 but is using OpenLDAP 2.2 and the only error messages at the login prompt are "Login incorrect". On the system with OpenLDAP 2.3 running, the error messages are as follows:

Incorrect username -

login (pam_unix)[4531]: check pass; user unknown
Login incorrect

Incorrect password -

login: pam_ldap: error trying to bind as user "uid=test, ou=People, dc=example, dc=co.uk" (invalid credentials)
Login incorrect

In the OpenLDAP config files I have tried to play with the ppolicy_use_lockout value in my slapd.conf by having it in and by removing it with no difference to the error messages. That is the only variable that appears to have anything to do with error messages in OpenLDAP. I still suspect my problem is somewhere in PAM but cannot find anything documented.

Martin
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Need help suppressing last login info geekdad Linux - Server 6 06-04-2008 05:08 PM
Need help suppressing last login info geekdad Linux - Server 1 06-04-2008 04:01 PM
Suppressing error messages in BASH Shell swiftguy121 Linux - Software 4 05-25-2007 08:59 PM
Suppressing linking messages on AIX montylee AIX 2 07-06-2005 06:17 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration