Sudo over tls/ssl connection

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



This client is RHEL 5 -- I tried various different configs including the one
you paste below.

What I did find out eventually, is that sudo on rhel 5 is compiled with
libldap support, this was not the case in rhel 4.5 -- so I recompiled and
re-installed the rpm to exclude libldap support and it now it works fine.

Thanks,
Greg

On 8/1/07, Josh Kelley <joshkel at gmail.com> wrote:
>
> On 7/31/07, Greg Hetrick <greg.hetrick at gmail.com> wrote:
> > I am having a problem with sudo when I am running in a TSL/SSL
> connection, I
> > am able to ssh into the client and verified that the connection is
> secure,
> > but once logged in to the client machine I am unable to use sudo.
> >
> > I am seeing multiple re-tries in the access logs that appear to close,:
> >
> > When I do the same thing without a TLS/SSL connection sudo works fine.
> >
> > and eventually, I get
> >
> > sudo: uid 1000 does not exist in the passwd file!
>
> Based on the symptoms and logs, this sounds more like a client problem
> than a problem with FDS.  What OS / distro are you running?  What does
> your /etc/ldap.conf look like?  Recent versions of Fedora, for
> example, are fairly strict in how /etc/ldap.conf is configured.  The
> following configuration works for me, although it could probably be
> improved:
>
> uri ldaps://ldap1.example.com/ ldaps://ldap2.example.com/
> ssl on
> tls_cacertfile /etc/pki/tls/certs/ca-localauthority.crt
> host ldap1.example.com ldap2.example.com
>
> Josh Kelley
>
> --
> Fedora-directory-users mailing list
> Fedora-directory-users at redhat.com
> https://www.redhat.com/mailman/listinfo/fedora-directory-users
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.fedoraproject.org/pipermail/389-users/attachments/20070801/76956e49/attachment.html 


[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux