Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Andy Speagle
On Tue, 2009-08-25 at 13:02 -0500, Jeffrey Watts wrote: > Did you put "debug 1" in /etc/ldap.conf? That file is sourced by both > nss_ldap and pam_ldap. > > Jeffrey. > > On Tue, Aug 25, 2009 at 11:56 AM, Andy Speagle > wrote: > > Thanks... any thoughts on where to go from here?

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Jeffrey Watts
Did you put "debug 1" in /etc/ldap.conf? That file is sourced by both nss_ldap and pam_ldap. Jeffrey. On Tue, Aug 25, 2009 at 11:56 AM, Andy Speagle wrote: > > Thanks... any thoughts on where to go from here? I can't seem to get > any verbose logging from PAM... despite appending "debug" to th

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Andy Speagle
On Tue, 2009-08-25 at 12:03 -0500, Brandon Perkins wrote: > Wow, you're starting to get me stumped! Next thing I'm curious about > is > your version of jpam: > > rpm -q --queryformat "%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n" jpam # rpm -q --queryformat "%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n" j

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Brandon Perkins
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andy Speagle wrote: > On Tue, 2009-08-25 at 11:28 -0500, Brandon Perkins wrote: >> So, this doesn't look right to me, I'd expect something more along the >> lines of: >> >> #%PAM-1.0 >> auth requiredpam_env.so >> auth s

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Andy Speagle
On Tue, 2009-08-25 at 11:28 -0500, Brandon Perkins wrote: > So, this doesn't look right to me, I'd expect something more along the > lines of: > > #%PAM-1.0 > auth requiredpam_env.so > auth sufficient pam_ldap.so no_user_check > auth requiredp

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Brandon Perkins
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andy Speagle wrote: >> 1) Can you authenticate the user using LDAP for a different daemon, >> like >> SSH successfully? If not, take another look at your authconfig. > > Yes, LDAP logins for SSH authentication works well... > >> 2) Paste your /et

RE: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-25 Thread Wojtak, Greg
@redhat.com Subject: Re: [Spacewalk-list] Spacewalk & pam_ldap > 1) Can you authenticate the user using LDAP for a different daemon, > like SSH successfully? If not, take another look at your authconfig. Yes, LDAP logins for SSH authentication works well... > 2) Paste your /

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-24 Thread Jeffrey Watts
Do you have debug set in your ldap.conf? If not, set it > 0 and you'll get more output. Jeffrey. On Mon, Aug 24, 2009 at 3:56 PM, Andy Speagle wrote: > > After a restart, it still is a no-go for me... sadly. In addition, I'm > not getting ANY output in /var/log/messages regarding authenticatio

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-24 Thread Andy Speagle
> 1) Can you authenticate the user using LDAP for a different daemon, > like > SSH successfully? If not, take another look at your authconfig. Yes, LDAP logins for SSH authentication works well... > 2) Paste your /etc/pam.d/rhn-satellite file so we can take a look at > it. # cat /etc/pam.d/spa

Re: [Spacewalk-list] Spacewalk & pam_ldap

2009-08-24 Thread Brandon Perkins
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andy Speagle wrote: > Hi Team, > > I can't seem to get anywhere configuring Spacewalk to use the PAM > facilities for authenticating users. The few Satellite config docs and > web posts I've seen seem to indicate this is very straight-forward, but