LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 03-15-2013, 04:12 AM   #1
mikmik
LQ Newbie
 
Registered: Apr 2012
Posts: 9

Rep: Reputation: Disabled
Angry Problem with ldap client gets me crazy


Hi,

I'm trying to setup a debian 6 to authenticate users against an ldap server. I have another machine (also debian 6) with apparently the same config and packages, and it works (I didn't configure this machine).
I'm running out of ideas.
The principal clue is this line in /var/log/auth:

pam_ldap: ldap_simple_bind Can't contact LDAP server
pam_ldap: reconnecting to LDAP server...
ldap_simple_bind Can't contact LDAP server
sshd[2122]: pam_unix(sshd:auth): authentication failure;...

This seems to be a network or connection problem, but the 'getent passwd' command works perfectly and returns the user list at ldap server. Also, performing an ldapsearch works perfectly. Very weird.
The libnss-ldap.conf, libnss-ldap.secret and /etc/pam.d/* files are the same that the machine that is working fine.
The logs at the ldap server are very very longs and gets me confused. I don't see anything relevant.

I don't understand this.

Any help/idea is really appreciated.

Regards.
 
Old 03-15-2013, 04:26 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
I'd guess the server is just not defined correctly in the ldap config file. I don't know how debian configures this tbh, but on rhel6+ ldap details for information is in a separate file to pam details. Run a tcpdump when logging in to see the tcp data flow... "tcpdump -vn -i eth0 port 389"
 
Old 03-15-2013, 04:29 AM   #3
mikmik
LQ Newbie
 
Registered: Apr 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
thanks for the reply. I did that test. I can see data flow with tcpdump. Also, the getent and ldapsearch works fine
 
Old 03-15-2013, 04:49 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
OK, so if it IS connecting, then capture the traffic and look at it in wireshark (add the options "-s0 -w somefile.cap" to store all data to a file) It will probably be very clear what the issue is as the ldap protocol level, even if you don't understand LDAP, wireshark decodes and describes things very well.
 
Old 03-15-2013, 05:05 AM   #5
mikmik
LQ Newbie
 
Registered: Apr 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
shit. My foult. It's solved. When I tried to login, I saw traffic with tcpdump, so I supposed that there were no connectivity issues. But that flow was only to get uid or something similar, not for auth. The /etc/pam_ldap.conf was not configured properly, so the auth was not working. That's why getent and ldapsearch worked, but not auth step.

Thank you very much for your time.

Regards.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
A problem for LDAP client configuration on CENT 6.0 X64 windbadboy Linux - Server 1 05-31-2012 09:33 AM
LDAP client Authentication problem tuxb Fedora 3 09-29-2011 08:09 AM
openoffice problem in ldap client ramkannan Linux - Server 3 08-20-2010 09:20 AM
ldap client ubuntu 8.04 password unchanged problem. fahadaziz Linux - Server 9 04-20-2010 12:59 PM
how to setup open ldap server and solaris 10 as ldap client maheshlad Linux - Software 1 10-10-2009 12:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 10:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration