FYI and OT: PAM Weirdness

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi
I have seen an interesting problem which I thought would be useful for anyone on the list to know. I ran into it ones to many so sharing my solutions to spare others the suffering. :D

If you have certificates in /etc/pki/tls/certs on a CentOS 5.5 box and one of the certificates has root:root 600 permissions it will break LDAP login if you use certificates.

What happens is that as the client libs try to find the correct certificate it cycles through all of the certificates (as shown by strace) finds the correct certificates but also find an unreadable certificate and then refuses to connect to the LDAP server for some tasks.  You can login but you will see something like the following:

Last login: Wed Feb  9 09:56:32 2011 from 10.5.11.44
id: cannot find name for user ID xxxx
id: cannot find name for group ID xxxx
id: cannot find name for user ID xxxx
[I have no name!@testbox ~]$

You will also see the following in /var/log/messages
Feb  9 09:53:01 testserver nscd: nss_ldap: reconnecting to LDAP server (sleeping 1 seconds)...
Feb  9 09:53:02 testserver nscd: nss_ldap: could not search LDAP server - Server is unavailable


Arguably the file permissions should never be 600, but also arguable the PAM and or other libs should not be so sensitive to fail on only one file being wrong.

Regards

________________________________________________________________________
In order to protect our email recipients, Betfair Group use SkyScan from 
MessageLabs to scan all Incoming and Outgoing mail for viruses.

________________________________________________________________________


[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux