Migrating to LDAP authentication

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Sean!

On Fri, 12 Feb 2010, Sean Carolan wrote:

> > Is "invalid user" all you're seeing in the log? Generally, at least with
> > OpenSSH, if the user is being denied because it's not in a valid group,
> > the logs will say so. They'll also generally tell you if it's because it
> > couldn't find the user at all (often with exactly what it did to try to
> > find the user).
> 
> Here's what I'm seeing:
> 
> Feb 12 16:02:49 watcher sshd[953]: User scarolan from 10.2.3.102 not
> allowed because none of user's groups are listed in AllowGroups
> 
> I have UsePAM turned on, and getent group shows me in the "operations"
> group.  I wonder why sshd is not seeing that I'm in the operations
> group?

You don't also have the "operations" group defined in LDAP by any
chance, do you?

If you're going to start mixing local and LDAP stuff that way, you're
going to run into some fun-to-debug strangeness if you're not careful
about them all being identical.

I'm guessing you've also defined the group in LDAP either with different
members or a different GID, or that you've done the same with the user.


[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux