ssh login fail

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


Steven Jones wrote:
> looking in the wrong place would be my guess, based on the err=32 in the
> previous logs you posted.
> I seem to have been able to stop the err=32 by reconfiguring ldap.conf a
> bit and cleaning out FDS and I assume putting the user in the right
> place but still no login.
> [11/Sep/2007:16:21:47 +1200] conn=30 fd=78 slot=78 connection from
> to
> [11/Sep/2007:16:21:47 +1200] conn=30 op=0 BIND dn="" method=128
> version=3
> [11/Sep/2007:16:21:47 +1200] conn=30 op=0 RESULT err=0 tag=97 nentries=0
> etime=0 dn=""
> [11/Sep/2007:16:21:47 +1200] conn=30 op=1 SRCH
> base="ou=People,dc=vuw,dc=ac,dc=nz" scope=2
> filter="(&(objectClass=posixAccount)(uid=jonesst1))" attrs=ALL
> [11/Sep/2007:16:21:47 +1200] conn=30 op=1 RESULT err=0 tag=101
> nentries=0 etime=0
The clue here is that err=0 but nentries=0.  This to me indicates some 
sort of ACI problem.  If you ran the setup program, and you specified 
dc=vuw,dc=ac,dc=nz as your suffix, setup should have added an ACI which 
would allow this search to return entries.  This, coupled with the fact 
that you cannot view these entries using the console (assuming you meant 
while logged in as the admin user), suggests that you added this data 
after setup and that you did not specify dc=vuw,dc=ac,dc=nz as your 
suffix.  If you want to see what the suggested ACIs are, you should be 
able to view the ACIs that were added to the suffix that you did specify 
when you ran setup.  The console will show you the ACIs.  If you want to 
see what they are without using the console, you can use ldapsearch e.g.

ldapsearch -x -D "cn=directory manager" -w password -b 
"dc=vuw,dc=ac,dc=nz" "aci=*" aci

> [11/Sep/2007:16:21:47 +1200] conn=30 op=2 BIND dn="" method=128
> version=3
> [11/Sep/2007:16:21:47 +1200] conn=30 op=2 RESULT err=0 tag=97 nentries=0
> etime=0 dn=""
> [11/Sep/2007:16:21:47 +1200] conn=30 op=3 SRCH
> base="ou=People,dc=vuw,dc=ac,dc=nz" scope=2
> filter="(&(objectClass=posixAccount)(uid=jonesst1))" attrs=ALL
> [11/Sep/2007:16:21:47 +1200] conn=30 op=3 RESULT err=0 tag=101
> nentries=0 etime=0
> [11/Sep/2007:16:21:51 +1200] conn=30 op=4 BIND dn="" method=128
> version=3
> [11/Sep/2007:16:21:51 +1200] conn=30 op=4 RESULT err=0 tag=97 nentries=0
> etime=0 dn=""
> [11/Sep/2007:16:21:51 +1200] conn=30 op=5 SRCH
> base="ou=People,dc=vuw,dc=ac,dc=nz" scope=2
> filter="(&(objectClass=posixAccount)(uid=jonesst1))" attrs=ALL
> [11/Sep/2007:16:21:51 +1200] conn=30 op=5 RESULT err=0 tag=101
> nentries=0 etime=0
> [11/Sep/2007:16:21:51 +1200] conn=30 op=6 BIND dn="" method=128
> version=3
> [11/Sep/2007:16:21:51 +1200] conn=30 op=6 RESULT err=0 tag=97 nentries=0
> etime=0 dn=""
> [11/Sep/2007:16:21:51 +1200] conn=30 op=7 SRCH
> base="ou=People,dc=vuw,dc=ac,dc=nz" scope=2
> filter="(&(objectClass=posixAccount)(uid=jonesst1))" attrs=ALL
> [11/Sep/2007:16:21:51 +1200] conn=30 op=7 RESULT err=0 tag=101
> nentries=0 etime=0
> [11/Sep/2007:16:21:56 +1200] conn=30 op=8 BIND dn="" method=128
> version=3
> [11/Sep/2007:16:21:56 +1200] conn=30 op=8 RESULT err=0 tag=97 nentries=0
> etime=0 dn=""
> [11/Sep/2007:16:21:56 +1200] conn=30 op=9 SRCH
> base="ou=People,dc=vuw,dc=ac,dc=nz" scope=2
> filter="(&(objectClass=posixAccount)(uid=jonesst1))" attrs=ALL
> [11/Sep/2007:16:21:56 +1200] conn=30 op=9 RESULT err=0 tag=101
> nentries=0 etime=0
> [11/Sep/2007:16:21:56 +1200] conn=30 op=10 BIND dn="" method=128
> version=3
> [11/Sep/2007:16:21:56 +1200] conn=30 op=10 RESULT err=0 tag=97
> nentries=0 etime=0 dn=""
> [11/Sep/2007:16:21:56 +1200] conn=30 op=11 SRCH
> base="ou=People,dc=vuw,dc=ac,dc=nz" scope=2
> filter="(&(objectClass=posixAccount)(uid=jonesst1))" attrs=ALL
> [11/Sep/2007:16:21:56 +1200] conn=30 op=11 RESULT err=0 tag=101
> nentries=0 etime=0
> [11/Sep/2007:16:21:58 +1200] conn=30 op=13 UNBIND
> [11/Sep/2007:16:21:58 +1200] conn=30 op=13 fd=78 closed - U1
> [11/Sep/2007:16:22:46 +1200] conn=31 fd=78 slot=78 connection from
> to
> [11/Sep/2007:16:22:46 +1200] conn=31 op=0 BIND
> dn="uid=jonesst1,ou=People,dc=vuw,dc=ac,dc=nz" method=128 version=3
> [11/Sep/2007:16:22:46 +1200] conn=31 op=0 RESULT err=0 tag=97 nentries=0
> etime=0 dn="uid=jonesst1,ou=people,dc=vuw,dc=ac,dc=nz"
> [11/Sep/2007:16:22:46 +1200] conn=31 op=1 SRCH base="" scope=0
> filter="(objectClass=*)" attrs=ALL
> [11/Sep/2007:16:22:46 +1200] conn=31 op=1 RESULT err=0 tag=101
> nentries=1 etime=0
> [11/Sep/2007:16:22:46 +1200] conn=31 op=2 UNBIND
> [11/Sep/2007:16:22:46 +1200] conn=31 op=2 fd=78 closed - U1
> [11/Sep/2007:16:22:52 +1200] conn=32 fd=78 slot=78 connection from
> to
> [11/Sep/2007:16:22:52 +1200] conn=32 op=0 BIND dn="" method=128
> version=3
> [11/Sep/2007:16:22:52 +1200] conn=32 op=0 RESULT err=0 tag=97 nentries=0
> etime=0 dn=""
> [11/Sep/2007:16:22:52 +1200] conn=32 op=1 SRCH
> base="uid=jonesst1,ou=People,dc=vuw,dc=ac,dc=nz" scope=2
> filter="(objectClass=*)" attrs=ALL
> [11/Sep/2007:16:22:52 +1200] conn=32 op=1 RESULT err=0 tag=101
> nentries=1 etime=0
> [11/Sep/2007:16:22:52 +1200] conn=32 op=2 UNBIND
> [11/Sep/2007:16:22:52 +1200] conn=32 op=2 fd=78 closed - U1
> --
> Fedora-directory-users mailing list
> Fedora-directory-users at

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3245 bytes
Desc: S/MIME Cryptographic Signature
Url : 

[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux