> Edward was suggesting a problem with the 'login' pam service, not system-auth, but I don't agree with his solution - I can't see how adding an explicit include of pam_ldap.so here for the account type is going to help, as by default this just defers to system-auth anyway. > > Edward, are you able to offer any more insight into how this can help? Thanks, Tom. I can provide log files or other data to troubleshoot this. It's rather perplexing, we aren't trying to do anything really out of the ordinary. This is a rather straightforward stock installation of CentOS5 on the client, and CentOS5 with 389-ds on the server. -- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users