Re: [SSSD-users] authconfig and moving from ldap to sssd on redhat6 boxes

2013-10-22 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

On 10/21/2013 11:29 AM, Olivier OLG wrote:
> Hello there,
> 
> two observations about using authconfig to switch from ldap to sssd
> on redhat6 :
> 
> 1- why does authconfig stops sssd when it's launched with 
> "--enablesssd --enablesssdauth" flags (rather than restarting the
> service) ?
> 
> 2- I also use "--disableldap --disableldapauth --enablepamaccess" 
> flags and it appears that authconfig has updated properly all files
> in /etc/pam.d/* except for /etc/pam.d/sudo :
> 
> # grep ldap /etc/pam.d/sudo authsufficientpam_ldap.so
> use_first_pass account [default=bad success=ok
> user_unknown=ignore] pam_ldap.so passwordsufficient
> pam_ldap.so use_authtok session optional  pam_ldap.so
> 
> Nothing critical in all that (to me at least), since I found
> workarounds, however may be this should be fixed with next
> authconfig versions ?
> 

While we work closely with authconfig, they are in fact a different
upstream. Bugs in authconfig should be reported at
https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora&component=authconfig

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.15 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlJmbuQACgkQeiVVYja6o6NocACfbV2aAJ2Mpsu39W7RgVKRN+i9
u4EAoJijBNflnJDEF6LnoD2+9cnUPsmq
=0BCc
-END PGP SIGNATURE-
___
sssd-users mailing list
sssd-users@lists.fedorahosted.org
https://lists.fedorahosted.org/mailman/listinfo/sssd-users


[SSSD-users] authconfig and moving from ldap to sssd on redhat6 boxes

2013-10-22 Thread Olivier OLG
Hello there,

two observations about using authconfig to switch from ldap to
sssd on redhat6 :

1- why does authconfig stops sssd when it's launched with
  "--enablesssd --enablesssdauth" flags (rather than restarting
   the service) ?

2- I also use "--disableldap --disableldapauth --enablepamaccess"
flags and it appears that authconfig has updated properly all
files in /etc/pam.d/* except for /etc/pam.d/sudo :

# grep ldap /etc/pam.d/sudo
authsufficientpam_ldap.so use_first_pass
account [default=bad success=ok user_unknown=ignore] pam_ldap.so
passwordsufficientpam_ldap.so use_authtok
session optional  pam_ldap.so

Nothing critical in all that (to me at least), since I found workarounds,
however may be this should be fixed with next authconfig versions ?

Best regards

---
Olivier
___
sssd-users mailing list
sssd-users@lists.fedorahosted.org
https://lists.fedorahosted.org/mailman/listinfo/sssd-users