Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #241183 > unrolled thread
| Started by | Gokan Atmaca <linux.gokan@gmail.com> |
|---|---|
| First post | 2021-10-11 14:40 +0200 |
| Last post | 2021-10-12 18:40 +0200 |
| Articles | 5 — 3 participants |
Back to article view | Back to linux.debian.user
OpenLdap Gokan Atmaca <linux.gokan@gmail.com> - 2021-10-11 14:40 +0200
Re: OpenLdap Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-10-12 01:10 +0200
Re: OpenLdap Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-10-12 01:10 +0200
Re: OpenLdap Henning Follmann <hfollmann@itcfollmann.com> - 2021-10-12 16:10 +0200
Re: OpenLdap Gokan Atmaca <linux.gokan@gmail.com> - 2021-10-12 18:40 +0200
| From | Gokan Atmaca <linux.gokan@gmail.com> |
|---|---|
| Date | 2021-10-11 14:40 +0200 |
| Subject | OpenLdap |
| Message-ID | <D72L1-2ec-27@gated-at.bofh.it> |
Hello I am using openldap. I configured a different server as ldap client. When I say "id user", the information comes. I have two organized units. "people" and "groups". my test environment. But I can't login. What could be causing the problem? Example: $ id gokhan (ldap_user) uid=10000(gokhan) gid=2000(ob) groups=2000(ob) Thanks. -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org ⠈⠳⣄⠀⠀⠀⠀
[toc] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2021-10-12 01:10 +0200 |
| Message-ID | <D7cAF-8os-3@gated-at.bofh.it> |
| In reply to | #241183 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Oct 11, 2021, 6:04 PM Nicholas Geovanis <nickgeovanis@gmail.com> wrote: > > > On Mon, Oct 11, 2021, 7:31 AM Gokan Atmaca <linux.gokan@gmail.com> wrote: > >> Hello >> >> I am using openldap. I configured a different server as ldap client. >> When I say "id user", the information comes. I have two organized >> units. "people" and "groups". my test environment. But I can't login. >> What could be causing the problem? >> > > The immediate reason for the failure should be found in the sshd logs in > /var. But the trick with LDAP for login authentication is this: > > (1) Make sure the services file is stepping thru the authentication > databases in the order you believe is correct. > I wrote "services file". I actually meant PAM configuration. Example: >> $ id gokhan (ldap_user) >> uid=10000(gokhan) gid=2000(ob) groups=2000(ob) >> >> Thanks. >> >> >> -- >> ⢀⣴⠾⠻⢶⣦⠀ >> ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system >> ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org >> ⠈⠳⣄⠀⠀⠀⠀ >> >>
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2021-10-12 01:10 +0200 |
| Message-ID | <D7cAF-8os-5@gated-at.bofh.it> |
| In reply to | #241183 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Oct 11, 2021, 7:31 AM Gokan Atmaca <linux.gokan@gmail.com> wrote: > Hello > > I am using openldap. I configured a different server as ldap client. > When I say "id user", the information comes. I have two organized > units. "people" and "groups". my test environment. But I can't login. > What could be causing the problem? > The immediate reason for the failure should be found in the sshd logs in /var. But the trick with LDAP for login authentication is this: (1) Make sure the services file is stepping thru the authentication databases in the order you believe is correct. (2) make sure name resolution is doing what you think it's doing. (3) Make sure that clock time is synchronized across all servers involved in that login and authentication. Example: > $ id gokhan (ldap_user) > uid=10000(gokhan) gid=2000(ob) groups=2000(ob) > > Thanks. > > > -- > ⢀⣴⠾⠻⢶⣦⠀ > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org > ⠈⠳⣄⠀⠀⠀⠀ > >
[toc] | [prev] | [next] | [standalone]
| From | Henning Follmann <hfollmann@itcfollmann.com> |
|---|---|
| Date | 2021-10-12 16:10 +0200 |
| Message-ID | <D7qDE-Oo-9@gated-at.bofh.it> |
| In reply to | #241221 |
On Mon, Oct 11, 2021 at 06:04:08PM -0500, Nicholas Geovanis wrote: > On Mon, Oct 11, 2021, 7:31 AM Gokan Atmaca <linux.gokan@gmail.com> wrote: > > > Hello > > > > I am using openldap. I configured a different server as ldap client. > > When I say "id user", the information comes. I have two organized > > units. "people" and "groups". my test environment. But I can't login. > > What could be causing the problem? > > > > The immediate reason for the failure should be found in the sshd logs in > /var. But the trick with LDAP for login authentication is this: why should this be in the sshd logs? Is he/she even try to ssh into that machine and using openldap as a passwort store? Or a local login, httpd, email... He/she might even try to just login into ldap, from the post it is not clear what he/she is actually trying. > > (1) Make sure the services file is stepping thru the authentication > databases in the order you believe is correct. > (2) make sure name resolution is doing what you think it's doing. > (3) Make sure that clock time is synchronized across all servers involved > in that login and authentication. > > > Example: > > $ id gokhan (ldap_user) > > uid=10000(gokhan) gid=2000(ob) groups=2000(ob) > > > > Thanks. > > > > > > -- > > ⢀⣴⠾⠻⢶⣦⠀ > > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system > > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org > > ⠈⠳⣄⠀⠀⠀⠀ > > > > -- Henning Follmann | hfollmann@itcfollmann.com
[toc] | [prev] | [next] | [standalone]
| From | Gokan Atmaca <linux.gokan@gmail.com> |
|---|---|
| Date | 2021-10-12 18:40 +0200 |
| Message-ID | <D7sYN-25h-1@gated-at.bofh.it> |
| In reply to | #241239 |
> > The immediate reason for the failure should be found in the sshd logs in > > /var. But the trick with LDAP for login authentication is this: I'm probably making a mistake. I will try again from the beginning. I'll pass the information. Thanks. On Tue, Oct 12, 2021 at 5:04 PM Henning Follmann <hfollmann@itcfollmann.com> wrote: > > On Mon, Oct 11, 2021 at 06:04:08PM -0500, Nicholas Geovanis wrote: > > On Mon, Oct 11, 2021, 7:31 AM Gokan Atmaca <linux.gokan@gmail.com> wrote: > > > > > Hello > > > > > > I am using openldap. I configured a different server as ldap client. > > > When I say "id user", the information comes. I have two organized > > > units. "people" and "groups". my test environment. But I can't login. > > > What could be causing the problem? > > > > > > > The immediate reason for the failure should be found in the sshd logs in > > /var. But the trick with LDAP for login authentication is this: > > why should this be in the sshd logs? > > Is he/she even try to ssh into that machine and using openldap as a > passwort store? Or a local login, httpd, email... > > He/she might even try to just login into ldap, from the post > it is not clear what he/she is actually trying. > > > > > (1) Make sure the services file is stepping thru the authentication > > databases in the order you believe is correct. > > (2) make sure name resolution is doing what you think it's doing. > > (3) Make sure that clock time is synchronized across all servers involved > > in that login and authentication. > > > > > > Example: > > > $ id gokhan (ldap_user) > > > uid=10000(gokhan) gid=2000(ob) groups=2000(ob) > > > > > > Thanks. > > > > > > > > > -- > > > ⢀⣴⠾⠻⢶⣦⠀ > > > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system > > > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org > > > ⠈⠳⣄⠀⠀⠀⠀ > > > > > > > > -- > Henning Follmann | hfollmann@itcfollmann.com >
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web