[SSSD-users] Trying to use sssd to connect to large AD service - secondary groups not loading

2016-08-09 Thread Robert Sturrock
Hi All. I'm struggling a bit trying to get sssd (client is RHEL7.2, so using sssd-1.13.0-40.el7_2.1.x86_64) to connect to a large institutional AD (100k+ users, each user belonging to dozens or even hundreds of groups). I'm following the instructions here: https://access.redhat.com/docum

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Lukas Slebodnik
On (09/08/16 20:24), Thomas Beaudry wrote: >Hi, > >Here are the requested log files. > I cannot see any atachments. Neither in mail client nor in archive https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.org/message/JPHV4FJZZWN2MINTWX4N2WLLHI2NI6TN/ If they were removed by

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Thomas Beaudry
Hi, Here are the requested log files. Thanks, Thomas From: Lukas Slebodnik Sent: Tuesday, August 9, 2016 4:08 PM To: End-user discussions about the System Security Services Daemon Subject: [SSSD-users] Re: SSSD-PAM failure On (09/08/16 19:42), Thomas Bea

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Lukas Slebodnik
On (09/08/16 19:42), Thomas Beaudry wrote: >OK well I had debug_level under [sssd] and not [pam] in my sssd.conf file. >Here is my output > The troubledhooting guide says: Keep in mind that enabling debug_level in the [sssd] section only enables debugging of the sssd process itself, not a

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Stephen Gallagher
On 08/09/2016 03:42 PM, Thomas Beaudry wrote: > (Tue Aug 9 15:39:32 2016) [sssd[pam]] [pam_dp_send_req] (0x0100): Sending > request with the following data: > (Tue Aug 9 15:39:32 2016) [sssd[pam]] [pam_print_data] (0x0100): command: > SSS_PAM_AUTHENTICATE > (Tue Aug 9 15:39:32 2016) [sssd[pam]

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Thomas Beaudry
OK well I had debug_level under [sssd] and not [pam] in my sssd.conf file. Here is my output (Tue Aug 9 15:39:22 2016) [sssd[pam]] [server_setup] (0x0400): CONFDB: /var/lib/sss/db/config.ldb (Tue Aug 9 15:39:22 2016) [sssd[pam]] [confdb_get_domain_internal] (0x0400): No enumeration for [co

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Lukas Slebodnik
On (09/08/16 19:19), Thomas Beaudry wrote: >Hi Lukas, > >>I would recommend to look into >>/var/log/sssd/sssd_$domain.log >>and /var/log/sssd/*_child.log > >All of those files are empty > Let me quote our wiki[1] "To enable debugging persistently across SSSD service restarts, put the directive debu

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Thomas Beaudry
Hi Lukas, >I would recommend to look into >/var/log/sssd/sssd_$domain.log >and /var/log/sssd/*_child.log All of those files are empty > Which distribution do you use and how did you configure pam-stack? Ubuntu 16.04, here is my PAM config in the sssd.conf [pam] reconnection_retries = 3 I did

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Lukas Slebodnik
On (09/08/16 19:04), Thomas Beaudry wrote: >Hi, Lukas > >Sorry I gave this output since the wiki stated "If the user info can be >retrieved, but authentication fails, the first place to look into is >/var/log/secure or the system journal" > >So you want me to post the sssd.log in /var/log/sssd/s

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Thomas Beaudry
Hi, Lukas Sorry I gave this output since the wiki stated "If the user info can be retrieved, but authentication fails, the first place to look into is /var/log/secure or the system journal" So you want me to post the sssd.log in /var/log/sssd/sssd? Yes I saw that my PAM stack is starting with

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Thomas Beaudry
Hi, Lukas Sorry I gave this output since the wiki stated "If the user info can be retrieved, but authentication fails, the first place to look into is /var/log/secure or the system journal" So you want me to post the sssd.log in /var/log/sssd/sssd? Yes I saw that my PAM stack is starting with

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread Lukas Slebodnik
On (09/08/16 18:19), thomas.beau...@concordia.ca wrote: >Hi, thanks for responding, I thought that a response would have come to my >email, instead of here. Sorry for the delay. I set the debug level to 9. >Here is the log: > >Aug 9 14:17:01 tbeaudry CRON[2826]: pam_unix(cron:session): sessio

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread thomas . beaudry
Thanks for the suggestion Lucas. I actually found the troubleshooting guide already, it is how i figured out I had a PAM error :) ___ sssd-users mailing list sssd-users@lists.fedorahosted.org https://lists.fedorahosted.org/admin/lists/sssd-users@lists.f

[SSSD-users] Re: SSSD-PAM failure

2016-08-09 Thread thomas . beaudry
Hi, thanks for responding, I thought that a response would have come to my email, instead of here. Sorry for the delay. I set the debug level to 9. Here is the log: Aug 9 14:17:01 tbeaudry CRON[2826]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 9 14:17:01 tbeaudry C