LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 09-17-2015, 10:40 AM   #1
ESvenVA
LQ Newbie
 
Registered: Sep 2015
Posts: 1

Rep: Reputation: Disabled
Question RedHat 6.6 - problem with AD account authentication


Hello, I have been searching for an answer to this, and have come up short. Perhaps the smart people of this forum can assist.

RedHat v6.6 (modified + security lock down, so not the off-the-shelf COTS version)
VMWare v5.5
LikeWise v7.0

Problem - Authentication issue using AD account, local accounts work fine. I can not get consistent authentication across the system with an AD account. For example, ssh, sudo, etc...

Symptoms- I CAN SSH login to the system from my domain PC logged in as "user1" using MobaXterm and the default setting for user id. This will pass my domain login session directly to the RH VM no problem.

I CAN run the LikeWise commands "lw-get-status, lw-find-user-by-name" and get the appropriate responses from the domain. This would seem to indicate it is properly communicating with the Domain, and able to query the AD.

I CAN NOT SSH login to the system using SSH client or PuTTy. Both complain about authentication cipher mismatch, so I don't really care about PuTTy, but we do use SSH client for Windows quite a bit. These may not be relevant, but I mention it anyway.

I CAN NOT sudo as "user1" to another user. (IE root "sudo su -". It will prompt for the password, and the password I enter will NOT be accepted.

I also CAN NOT SSH from 1 system to another using an AD account. This works fine with local accounts. I get messages in the /var/log/secure log file like this:

"SSH"
Sep 17 13:38:00 db01dev sshd[18794]: pam_unix(sshd:session): session opened for user user1 by (uid=0)
Sep 17 13:38:01 db01dev sshd[18802]: Failed password for user1 from 10.10.10.201 port 53117 ssh2
Sep 17 13:38:03 db01dev unix_chkpwd[18829]: check pass; user unknown
Sep 17 13:38:03 db01dev unix_chkpwd[18829]: password check failed for user (user1)
Sep 17 13:38:05 db01dev sshd[18802]: error: PAM: Permission denied for user1 from domain_pc-08.company.dev
Sep 17 13:38:05 db01dev sshd[18803]: Received disconnect from 10.10.10.201: 11: No more authentication methods available

"SUDO"
Sep 17 13:45:13 db01dev unix_chkpwd[18899]: check pass; user unknown
Sep 17 13:45:13 db01dev unix_chkpwd[18899]: password check failed for user (user1)
Sep 17 13:45:13 db01dev sudo: pam_unix(sudo:auth): authentication failure; logname=user1 uid=32xxxxxx euid=0 tty=/dev/pts/0 ruser=user1 rhost= user=user1
Sep 17 13:50:15 db01dev sudo: [lsass-pam] [moduleam_lsass]LsaPamGetCurrentPassword failed [error code: 49919]
Sep 17 13:50:15 db01dev sudo: [lsass-pam] [moduleam_lsass]pam_sm_authenticate error [login:user1][error code:49919]
Sep 17 13:50:18 db01dev sudo: user1: user NOT in sudoers ; TTY=pts/0 ; PWD=/home/company/user1; USER=root ; COMMAND=/bin/su -

This "feels" like it has something to do with /etc/pam.d/* files, but what? You can login and authenticate, but other functions/programs do not!? Any useful suggestions would be appreciated. I apologize if this is not the correct forum, and I will re-post in another if needed.
 
Old 09-20-2015, 01:02 AM   #2
thyrsus
LQ Newbie
 
Registered: May 2006
Posts: 7

Rep: Reputation: 5
What's the origin of pam_lsass? In any case, we don't see it mentioned in the ssh authentication failure, which means that it wasn't tried, or pam has been told that unix_chkpasswd is requisite, and doesn't try further authentication methods. It would help if you posted the relevant /etc/pam.d files here (which likely includes system-auth) - and please put them in [CODE] markers; that should avoid emoticons obscuring the content
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LDAP authentication without local account viveksnv Linux - Security 2 10-12-2009 07:39 PM
Kerberos Authentication without Local Account? zachet Linux - Newbie 1 07-15-2009 02:23 PM
Cyrus Imap authentication problem on RedHat Linux 8.0 vijay_ratnakaran Linux - Software 0 08-29-2005 08:19 PM
RedHat AS 3, NIS client authentication problem tells Red Hat 3 10-11-2004 04:51 PM
Apache system account authentication the_gorf *BSD 0 06-30-2004 07:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 07:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration