Re: Question re: {KERBEROS} syntax

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Title: Re: Question re: {KERBEROS} syntax
Just as a followup, if the pam entries appear at the end of the dse.ldif file, the server starts without warning, but that’s it.. Once stopped, the dse.ldif is rearranged, the pam entry moves up, and the error persists on subsequent starts..

Regardless, when I manually start it with the entry at the bottom of the ldif, I still can not get the system to use the aliasedobjectname instead of the rdn..

Tom

On 7/26/06 11:20 AM, "Tom Ryan" <tomryan@xxxxxxxxxxxxxxxxxx> wrote:

It happens to all of us...

I am still having a couple of issues though (for everyone else listening :)

I changed pamMapMethod to Entry
I then set pamIDAttr to aliasedObjectName (out of laziness for now)

When I start the slapd with this, I get this..

pam_passthru-plugin - Warning: The following suffixes listed in pamExcludeSuffix or pamIncludeSuffix are not present in this server: o=NetscapeRoot

But, the admin server will still start just fine..

Regardless, the system does not appear to try to use the aliasedobjectname for the user to pass to pam.. (I have KRBPRINC@xxxxxxxxx in aliasedobjectname)..

Any ideas?

Tom

Ps.. If I leave it as RDN, I get no error on startup about suffix and as long as my bind dn matches my krb princ in the default realm, it works.. So I’m halfway there?
--
Fedora-directory-users mailing list
Fedora-directory-users@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-directory-users

[Index of Archives]     [Fedora Directory Users]     [Fedora Directory Devel]     [Fedora Announce]     [Fedora Legacy Announce]     [Kernel]     [Fedora Legacy]     [Share Photos]     [Fedora Desktop]     [PAM]     [Red Hat Watch]     [Red Hat Development]     [Big List of Linux Books]     [Gimp]     [Yosemite News]

  Powered by Linux