Re: [Swan] IPSec+XAUTH Multiple Clients behind same NAT not working

2014-08-22 Thread Paul Wouters
On Fri, 22 Aug 2014, Pontus Wiberg wrote: Finally my XAUTH configuration is working, however now I find myself stuck on a NAT issue. I moved to Libreswan largely because of the rightaddresspool options and because using XAUTH should support having multiple clients behind the same NAT. Now I ca

Re: [Swan] XAUTH: PAM auth chain failed with '7' on CentOS 7

2014-08-22 Thread Remy van Elst
On 08/22/14 16:57, Paul Wouters wrote: > On Fri, 22 Aug 2014, Remy van Elst wrote: > >>> chpasswd(8) can do that, but the pam method in pluto doesn't run >>> anything >>> through crypt (it will leave the password verification to the pam >>> stack), >>> and crypt would support the SHA512 type. Is

Re: [Swan] XAUTH: PAM auth chain failed with '7' on CentOS 7

2014-08-22 Thread Remy van Elst
On 08/22/14 16:44, Matt Rogers wrote: > On 08/22, Remy van Elst wrote: >> >> >> On 08/22/14 16:30, Matt Rogers wrote: >>> On 08/22, Remy van Elst wrote: How would I apply this to system/PAM authentication? The passwords in the shadow file are SHA512 ($6$...) >>> chpasswd(8) can do

Re: [Swan] XAUTH: PAM auth chain failed with '7' on CentOS 7

2014-08-22 Thread Paul Wouters
On Fri, 22 Aug 2014, Remy van Elst wrote: chpasswd(8) can do that, but the pam method in pluto doesn't run anything through crypt (it will leave the password verification to the pam stack), and crypt would support the SHA512 type. Is your system-auth configuration much different than the RHEL/Ce

Re: [Swan] XAUTH: PAM auth chain failed with '7' on CentOS 7

2014-08-22 Thread Matt Rogers
On 08/22, Remy van Elst wrote: > > > On 08/22/14 16:30, Matt Rogers wrote: > > On 08/22, Remy van Elst wrote: > >> How would I apply this to system/PAM authentication? The passwords in > >> the shadow file are SHA512 ($6$...) > >> > > chpasswd(8) can do that, but the pam method in pluto doesn't r

Re: [Swan] XAUTH: PAM auth chain failed with '7' on CentOS 7

2014-08-22 Thread Remy van Elst
On 08/22/14 16:30, Matt Rogers wrote: > On 08/22, Remy van Elst wrote: >> How would I apply this to system/PAM authentication? The passwords in >> the shadow file are SHA512 ($6$...) >> > chpasswd(8) can do that, but the pam method in pluto doesn't run anything > through crypt (it will leave the

Re: [Swan] XAUTH: PAM auth chain failed with '7' on CentOS 7

2014-08-22 Thread Matt Rogers
On 08/22, Remy van Elst wrote: > How would I apply this to system/PAM authentication? The passwords in > the shadow file are SHA512 ($6$...) > chpasswd(8) can do that, but the pam method in pluto doesn't run anything through crypt (it will leave the password verification to the pam stack), and cry

[Swan] IPSec+XAUTH Multiple Clients behind same NAT not working

2014-08-22 Thread Pontus Wiberg
Finally my XAUTH configuration is working, however now I find myself stuck on a NAT issue. I moved to Libreswan largely because of the rightaddresspool options and because using XAUTH should support having multiple clients behind the same NAT. Now I can't get that to work though, I have two clients

Re: [Swan] XAUTH: PAM auth chain failed with '7' on CentOS 7

2014-08-22 Thread Remy van Elst
How would I apply this to system/PAM authentication? The passwords in the shadow file are SHA512 ($6$...) On 08/21/14 21:15, Matt Rogers wrote: > On 08/21, Pontus Wiberg wrote: >> FYI did a new setup on a Ubuntu server with no additional software but >> Libreswan and the requirements, a clean se

Re: [Swan] XAUTH: PAM auth chain failed with '7' on CentOS 7

2014-08-22 Thread Pontus Wiberg
Seems really odd, I tried it on RHEL as well with the same issue.. passwd file is indeed marked correctly - I changed to using crypt() passwords and it worked immediately! Thanks, I guess crypt should be fine for XAUTH, and this way I can at least finish my setup for now. If anything is needed from