Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Andy Speagle
On Tue, 2009-08-25 at 13:02 -0500, Jeffrey Watts wrote: > Did you put "debug 1" in /etc/ldap.conf? That file is sourced by both > nss_ldap and pam_ldap. > > Jeffrey. > > On Tue, Aug 25, 2009 at 11:56 AM, Andy Speagle > wrote: > > Thanks... any thoughts on where to go from here?

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Jeffrey Watts
Did you put "debug 1" in /etc/ldap.conf? That file is sourced by both nss_ldap and pam_ldap. Jeffrey. On Tue, Aug 25, 2009 at 11:56 AM, Andy Speagle wrote: > > Thanks... any thoughts on where to go from here? I can't seem to get > any verbose logging from PAM... despite appending "debug" to th

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Andy Speagle
On Tue, 2009-08-25 at 12:03 -0500, Brandon Perkins wrote: > Wow, you're starting to get me stumped! Next thing I'm curious about > is > your version of jpam: > > rpm -q --queryformat "%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n" jpam # rpm -q --queryformat "%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n" j

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Brandon Perkins
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andy Speagle wrote: > On Tue, 2009-08-25 at 11:28 -0500, Brandon Perkins wrote: >> So, this doesn't look right to me, I'd expect something more along the >> lines of: >> >> #%PAM-1.0 >> auth requiredpam_env.so >> auth s

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Andy Speagle
On Tue, 2009-08-25 at 11:28 -0500, Brandon Perkins wrote: > So, this doesn't look right to me, I'd expect something more along the > lines of: > > #%PAM-1.0 > auth requiredpam_env.so > auth sufficient pam_ldap.so no_user_check > auth requiredp

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Brandon Perkins
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andy Speagle wrote: >> 1) Can you authenticate the user using LDAP for a different daemon, >> like >> SSH successfully? If not, take another look at your authconfig. > > Yes, LDAP logins for SSH authentication works well... > >> 2) Paste your /et

RE: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Wojtak, Greg
@redhat.com Subject: Re: [Spacewalk-list] Spacewalk & pam_ldap > 1) Can you authenticate the user using LDAP for a different daemon, > like SSH successfully? If not, take another look at your authconfig. Yes, LDAP logins for SSH authentication works well... > 2) Paste your /

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-24 Thread Jeffrey Watts
Do you have debug set in your ldap.conf? If not, set it > 0 and you'll get more output. Jeffrey. On Mon, Aug 24, 2009 at 3:56 PM, Andy Speagle wrote: > > After a restart, it still is a no-go for me... sadly. In addition, I'm > not getting ANY output in /var/log/messages regarding authenticatio

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-24 Thread Andy Speagle
> 1) Can you authenticate the user using LDAP for a different daemon, > like > SSH successfully? If not, take another look at your authconfig. Yes, LDAP logins for SSH authentication works well... > 2) Paste your /etc/pam.d/rhn-satellite file so we can take a look at > it. # cat /etc/pam.d/spa

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-24 Thread Brandon Perkins
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andy Speagle wrote: > Hi Team, > > I can't seem to get anywhere configuring Spacewalk to use the PAM > facilities for authenticating users. The few Satellite config docs and > web posts I've seen seem to indicate this is very straight-forward, but

[Spacewalk-list] Spacewalk & pam_ldap

2009-08-24 Thread Andy Speagle
Hi Team, I can't seem to get anywhere configuring Spacewalk to use the PAM facilities for authenticating users. The few Satellite config docs and web posts I've seen seem to indicate this is very straight-forward, but I guess I can't seem to get the magic just right. Can anyone point me in the r