Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #241183 > unrolled thread

OpenLdap

Started byGokan Atmaca <linux.gokan@gmail.com>
First post2021-10-11 14:40 +0200
Last post2021-10-12 18:40 +0200
Articles 5 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  OpenLdap Gokan Atmaca <linux.gokan@gmail.com> - 2021-10-11 14:40 +0200
    Re: OpenLdap Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-10-12 01:10 +0200
    Re: OpenLdap Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-10-12 01:10 +0200
      Re: OpenLdap Henning Follmann <hfollmann@itcfollmann.com> - 2021-10-12 16:10 +0200
        Re: OpenLdap Gokan Atmaca <linux.gokan@gmail.com> - 2021-10-12 18:40 +0200

#241183 — OpenLdap

FromGokan Atmaca <linux.gokan@gmail.com>
Date2021-10-11 14:40 +0200
SubjectOpenLdap
Message-ID<D72L1-2ec-27@gated-at.bofh.it>
Hello

I am using openldap. I configured a different server as ldap client.
When I say "id user", the information comes. I have two organized
units. "people" and "groups". my test environment.  But I can't login.
What could be causing the problem?

Example:
$ id gokhan (ldap_user)
uid=10000(gokhan) gid=2000(ob) groups=2000(ob)

Thanks.


-- 
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀

[toc] | [next] | [standalone]


#241220

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2021-10-12 01:10 +0200
Message-ID<D7cAF-8os-3@gated-at.bofh.it>
In reply to#241183

[Multipart message — attachments visible in raw view] — view raw

On Mon, Oct 11, 2021, 6:04 PM Nicholas Geovanis <nickgeovanis@gmail.com>
wrote:

>
>
> On Mon, Oct 11, 2021, 7:31 AM Gokan Atmaca <linux.gokan@gmail.com> wrote:
>
>> Hello
>>
>> I am using openldap. I configured a different server as ldap client.
>> When I say "id user", the information comes. I have two organized
>> units. "people" and "groups". my test environment.  But I can't login.
>> What could be causing the problem?
>>
>
> The immediate reason for the failure should be found in the sshd logs in
> /var. But the trick with LDAP for login authentication is this:
>
> (1) Make sure the services file is stepping thru the authentication
> databases in the order you believe is correct.
>

I wrote "services file".
I actually meant PAM configuration.


Example:
>> $ id gokhan (ldap_user)
>> uid=10000(gokhan) gid=2000(ob) groups=2000(ob)
>>
>> Thanks.
>>
>>
>> --
>> ⢀⣴⠾⠻⢶⣦⠀
>> ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
>> ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
>> ⠈⠳⣄⠀⠀⠀⠀
>>
>>

[toc] | [prev] | [next] | [standalone]


#241221

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2021-10-12 01:10 +0200
Message-ID<D7cAF-8os-5@gated-at.bofh.it>
In reply to#241183

[Multipart message — attachments visible in raw view] — view raw

On Mon, Oct 11, 2021, 7:31 AM Gokan Atmaca <linux.gokan@gmail.com> wrote:

> Hello
>
> I am using openldap. I configured a different server as ldap client.
> When I say "id user", the information comes. I have two organized
> units. "people" and "groups". my test environment.  But I can't login.
> What could be causing the problem?
>

The immediate reason for the failure should be found in the sshd logs in
/var. But the trick with LDAP for login authentication is this:

(1) Make sure the services file is stepping thru the authentication
databases in the order you believe is correct.
(2) make sure name resolution is doing what you think it's doing.
(3) Make sure that clock time is synchronized across all servers involved
in that login and authentication.


Example:
> $ id gokhan (ldap_user)
> uid=10000(gokhan) gid=2000(ob) groups=2000(ob)
>
> Thanks.
>
>
> --
> ⢀⣴⠾⠻⢶⣦⠀
> ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
> ⠈⠳⣄⠀⠀⠀⠀
>
>

[toc] | [prev] | [next] | [standalone]


#241239

FromHenning Follmann <hfollmann@itcfollmann.com>
Date2021-10-12 16:10 +0200
Message-ID<D7qDE-Oo-9@gated-at.bofh.it>
In reply to#241221
On Mon, Oct 11, 2021 at 06:04:08PM -0500, Nicholas Geovanis wrote:
> On Mon, Oct 11, 2021, 7:31 AM Gokan Atmaca <linux.gokan@gmail.com> wrote:
> 
> > Hello
> >
> > I am using openldap. I configured a different server as ldap client.
> > When I say "id user", the information comes. I have two organized
> > units. "people" and "groups". my test environment.  But I can't login.
> > What could be causing the problem?
> >
> 
> The immediate reason for the failure should be found in the sshd logs in
> /var. But the trick with LDAP for login authentication is this:

why should this be in the sshd logs?

Is he/she even try to ssh into that machine and using openldap as a
passwort store? Or a local login, httpd, email...

He/she might even try to just login into ldap, from the post
it is not clear what he/she is actually trying.

> 
> (1) Make sure the services file is stepping thru the authentication
> databases in the order you believe is correct.
> (2) make sure name resolution is doing what you think it's doing.
> (3) Make sure that clock time is synchronized across all servers involved
> in that login and authentication.
> 
> 
> Example:
> > $ id gokhan (ldap_user)
> > uid=10000(gokhan) gid=2000(ob) groups=2000(ob)
> >
> > Thanks.
> >
> >
> > --
> > ⢀⣴⠾⠻⢶⣦⠀
> > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
> > ⠈⠳⣄⠀⠀⠀⠀
> >
> >

-- 
Henning Follmann           | hfollmann@itcfollmann.com

[toc] | [prev] | [next] | [standalone]


#241249

FromGokan Atmaca <linux.gokan@gmail.com>
Date2021-10-12 18:40 +0200
Message-ID<D7sYN-25h-1@gated-at.bofh.it>
In reply to#241239
> > The immediate reason for the failure should be found in the sshd logs in
> > /var. But the trick with LDAP for login authentication is this:

I'm probably making a mistake. I will try again from the beginning.
I'll pass the information.

Thanks.


On Tue, Oct 12, 2021 at 5:04 PM Henning Follmann
<hfollmann@itcfollmann.com> wrote:
>
> On Mon, Oct 11, 2021 at 06:04:08PM -0500, Nicholas Geovanis wrote:
> > On Mon, Oct 11, 2021, 7:31 AM Gokan Atmaca <linux.gokan@gmail.com> wrote:
> >
> > > Hello
> > >
> > > I am using openldap. I configured a different server as ldap client.
> > > When I say "id user", the information comes. I have two organized
> > > units. "people" and "groups". my test environment.  But I can't login.
> > > What could be causing the problem?
> > >
> >
> > The immediate reason for the failure should be found in the sshd logs in
> > /var. But the trick with LDAP for login authentication is this:
>
> why should this be in the sshd logs?
>
> Is he/she even try to ssh into that machine and using openldap as a
> passwort store? Or a local login, httpd, email...
>
> He/she might even try to just login into ldap, from the post
> it is not clear what he/she is actually trying.
>
> >
> > (1) Make sure the services file is stepping thru the authentication
> > databases in the order you believe is correct.
> > (2) make sure name resolution is doing what you think it's doing.
> > (3) Make sure that clock time is synchronized across all servers involved
> > in that login and authentication.
> >
> >
> > Example:
> > > $ id gokhan (ldap_user)
> > > uid=10000(gokhan) gid=2000(ob) groups=2000(ob)
> > >
> > > Thanks.
> > >
> > >
> > > --
> > > ⢀⣴⠾⠻⢶⣦⠀
> > > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> > > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
> > > ⠈⠳⣄⠀⠀⠀⠀
> > >
> > >
>
> --
> Henning Follmann           | hfollmann@itcfollmann.com
>

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web