You are not logged in.

#1 2019-03-08 09:46:51

Oleksiy
Member
Registered: 2019-03-08
Posts: 1

KRB5 access to LDAP over VPN (/etc/pam.d/ settings problem)

Hi there. I have my Arch machine at work and want to use it to access to all of our corporate services, but there is a problem: all manuals and how-tos are for debian-based distros only so I can't setup correctly LDAP authentication at my workstation.
This is the part of how-to from our documentation describes right settings of /etc/pam.d/common-account file:

account [success=1 new_authtok_reqd=done default=ignore]        pam_unix.so
account requisite                       pam_deny.so
account required                        pam_permit.so
account required                        pam_krb5.so minimum_uid=1000
session required pam_mkhomedir.so skel=/etc/skel/ umask=0027

But threre's no the same file in Arch. I tried to use the same in /etc/pam.d/system-auth but it doesn't work. After that I get even passwordless login for local users :-) Can you help me to resolve this issue please?

VPN works fine, kinit too, I can get kerberos ticket without any problems, but I can't login using my LDAP login.

Offline

Board footer

Powered by FluxBB