<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-14178</id>
	<title>Nabble - PAM LDAP</title>
	<updated>2008-05-02T07:27:33Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/PAM-LDAP-f14178.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/PAM-LDAP-f14178.html" />
	<subtitle type="html">Discussion amongst users of pam_ldap.</subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-17022810</id>
	<title>Re: openldap authentication</title>
	<published>2008-05-02T07:27:33Z</published>
	<updated>2008-05-02T07:27:33Z</updated>
	<author>
		<name>nowen</name>
	</author>
	<content type="html">Jyotishmaan Ray wrote:
&lt;br&gt;&amp;gt; Hello List,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Recently I had been exploring the authentication types- Weak and
&lt;br&gt;&amp;gt; Strong type of authentication mainly!!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Can you plz give some pointers in that direction as such to classify
&lt;br&gt;&amp;gt; the openldap authentication-weak or strong. Please justify??
&lt;br&gt;&lt;br&gt;Weak authentication is single- factor, e.g. password only. &amp;nbsp;Strong 
&lt;br&gt;authentication incorporates more than one factor, e.g. knowledge of a 
&lt;br&gt;PIN and possession of the ATM card. Typically, strong authentication is 
&lt;br&gt;not handled by the ldap store, but rather a dedicated authentication 
&lt;br&gt;system often via SASL.
&lt;br&gt;&lt;br&gt;HTH,
&lt;br&gt;&lt;br&gt;Nick
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Nick Owen
&lt;br&gt;WiKID Systems, Inc.
&lt;br&gt;404-962-8983 (desk)
&lt;br&gt;&lt;a href=&quot;http://www.wikidsystems.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.wikidsystems.com&lt;/a&gt;&lt;br&gt;Two-factor authentication, without the hassle factor.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/openldap-authentication-tp16987101p17022810.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16987101</id>
	<title>openldap authentication</title>
	<published>2008-04-30T07:51:48Z</published>
	<updated>2008-04-30T07:51:48Z</updated>
	<author>
		<name>Jyotishmaan</name>
	</author>
	<content type="html">&lt;br&gt;Hello List,
&lt;br&gt;&lt;br&gt;Recently I had been exploring the authentication types- Weak and Strong type of authentication mainly!!
&lt;br&gt;&lt;br&gt;Can you plz give some pointers in that direction as such to classify the openldap authentication-weak or strong. Please justify??
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;Thanks, 
&lt;br&gt;Jyotishmaan Ray 
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; ____________________________________________________________________________________
&lt;br&gt;Be a better friend, newshound, and 
&lt;br&gt;know-it-all with Yahoo! Mobile. &amp;nbsp;Try it now. &amp;nbsp;&lt;a href=&quot;http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/openldap-authentication-tp16987101p16987101.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16789174</id>
	<title>Re: pam_check_host_attr + PAM configuration</title>
	<published>2008-04-19T17:29:39Z</published>
	<updated>2008-04-19T17:29:39Z</updated>
	<author>
		<name>zf</name>
	</author>
	<content type="html">&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;zf wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message&quot;&gt;I'm struggling for the past few days to setup host-based authentication on a CentOS 5 system using pam_check_host_attr directive but i really cannot understand how to make it work. I lack expertise in PAM so i'm trying many configurations found on the net about that subject but still none of these works either.
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
Damn, sometimes you miss the most obvious thing! Anyway, host-based authentication works as expected, my bad, i was changing a different sshd_config file so ssh didn't cooperate with PAM at all.
&lt;br&gt;&lt;br&gt;Sorry for that!
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/pam_check_host_attr-%2B-PAM-configuration-tp16781951p16789174.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16781951</id>
	<title>pam_check_host_attr + PAM configuration</title>
	<published>2008-04-19T04:11:22Z</published>
	<updated>2008-04-19T05:42:13Z</updated>
	<author>
		<name>zf</name>
	</author>
	<content type="html">Hi all,
&lt;br&gt;&lt;br&gt;I'm struggling for the past few days to setup host-based authentication on a CentOS 5 system using pam_check_host_attr directive but i really cannot understand how to make it work. I lack expertise in PAM so i'm trying many configurations found on the net about that subject but still none of these works either.
&lt;br&gt;&lt;br&gt;My /etc/ldap.conf is pretty simple and straightforward:
&lt;br&gt;-------------------------
&lt;br&gt;host 127.0.0.1
&lt;br&gt;base dc=people,dc=domain
&lt;br&gt;scope sub
&lt;br&gt;ssl no
&lt;br&gt;pam_check_host_attr yes
&lt;br&gt;-------------------------
&lt;br&gt;&lt;br&gt;partial /etc/nsswitch.conf :
&lt;br&gt;&lt;br&gt;-------------------
&lt;br&gt;passwd: &amp;nbsp; &amp;nbsp; files ldap
&lt;br&gt;shadow: &amp;nbsp; &amp;nbsp; files ldap
&lt;br&gt;group: &amp;nbsp; &amp;nbsp; &amp;nbsp;files ldap
&lt;br&gt;-------------------
&lt;br&gt;&lt;br&gt;partial /etc/ssh/sshd_config:
&lt;br&gt;&lt;br&gt;--------------
&lt;br&gt;UsePAM yes
&lt;br&gt;--------------
&lt;br&gt;&lt;br&gt;If anyone could guide me to setup PAM to support and respect this attribute, would be really appreciated.
&lt;br&gt;&lt;br&gt;TIA</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/pam_check_host_attr-%2B-PAM-configuration-tp16781951p16781951.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16753169</id>
	<title>Changing password after it has expired</title>
	<published>2008-04-17T10:18:55Z</published>
	<updated>2008-04-17T10:18:55Z</updated>
	<author>
		<name>Howard Wilkinson</name>
	</author>
	<content type="html">&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
Somebody on this list will know the definitive answer(s) to this
question. I have been knocking holes in the wall with my head all day
and cannot get an answer that makes sense.&lt;br&gt;
&lt;br&gt;
In active directory you can set a password as expired and when the user
logs in they get to type their old password to prove they are who they
say they are and then new passwords to get the change to happen.&lt;br&gt;
&lt;br&gt;
I want to achieve this via the LDAP interface but cannot find any
references that say if it is possible. I suspect that what really
happens under the cover is that the 'LDAP' code checks that the hash of
the presented old password matches the value in the AD and then uses a
privileged account rather&amp;nbsp; than the user to do the actual change (I am
thinking of the IISADMPWD application here!) What I had hoped I could
find would be an options that would allow a bind to succeed using the
users credentials (old password/username) that could only change the
password. But I have not.&lt;br&gt;
&lt;br&gt;
Am I right in that this is done by knowing that the HASH matches or is
there a hidden control to the AD LDAP interface I am missing?&lt;br&gt;
&lt;div class=&quot;moz-signature&quot;&gt;-- &lt;br&gt;
&lt;title&gt;Signature&lt;/title&gt;
&lt;div class=&quot;Section1&quot;&gt;
&lt;table class=&quot;MsoNormalTable&quot; style=&quot;width: 100%;&quot; border=&quot;0&quot; cellpadding=&quot;0&quot; width=&quot;100%&quot;&gt;
  &lt;tbody&gt;
    &lt;tr style=&quot;&quot;&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;Howard Wilkinson&lt;/p&gt;
      &lt;/td&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;Phone:&lt;/p&gt;
      &lt;/td&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;+44(20)76907075&lt;/p&gt;
      &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr style=&quot;&quot;&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;Coherent Technology Limited&lt;/p&gt;
      &lt;/td&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;Fax:&lt;/p&gt;
      &lt;/td&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;
      &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr style=&quot;&quot;&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;23 Northampton Square,&lt;/p&gt;
      &lt;/td&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;Mobile:&lt;/p&gt;
      &lt;/td&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;+44(7980)639379&lt;/p&gt;
      &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr style=&quot;&quot;&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;United Kingdom, EC1V 0HL&lt;/p&gt;
      &lt;/td&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;Email:&lt;/p&gt;
      &lt;/td&gt;
      &lt;td style=&quot;padding: 1.5pt;&quot; valign=&quot;top&quot;&gt;
      &lt;p class=&quot;MsoNormal&quot;&gt;&lt;a name=&quot;howardcohtech.com&quot; target=&quot;_top&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16753169&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;howard@...&lt;/a&gt;&lt;/p&gt;
      &lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/body&gt;
&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Changing-password-after-it-has-expired-tp16753169p16753169.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16740126</id>
	<title>Disbling and Eanbling an openldap ACCOUNT</title>
	<published>2008-04-16T22:40:25Z</published>
	<updated>2008-04-16T22:40:25Z</updated>
	<author>
		<name>Jyotishmaan</name>
	</author>
	<content type="html">Hello List
&lt;br&gt;&lt;br&gt;Though i can disable a user &amp;nbsp;(with the addition of the attribute- shadowExpire) from successful authentication and hence log on- i am not in a position to enable the same user ?
&lt;br&gt;&lt;br&gt;Can any one suggest a way to delete this attribute ? I see no ways to delete an attribute from the GUI or the command line ?
&lt;br&gt;&lt;br&gt;&lt;br&gt;But then if there is &amp;nbsp;are any other wayz using ACLS , ppolicy &amp;nbsp;etc disable a user account at will and enable it again at a later time whenevr they want. 
&lt;br&gt;&lt;br&gt;Please let me tell you that my set up is that of openldap in linux fedora 8.
&lt;br&gt;&lt;br&gt;&lt;br&gt;I am trying since yesterday night.
&lt;br&gt;&lt;br&gt;Please give some pointers!!!
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Thanks, &amp;nbsp;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks, 
&lt;br&gt;Jyotishmaan Ray 
&lt;br&gt;Moderator Of Paradise Groups 
&lt;br&gt;&lt;a href=&quot;http://yahoogroups.com/group/Spirituality-Paradise&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://yahoogroups.com/group/Spirituality-Paradise&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;Are You Spiritually Aware &amp;nbsp;!!! Are You Enjoying Yourself &amp;nbsp;!!! &amp;nbsp;See What All You Had Been Missing !!!!
&lt;br&gt;Please Join Immediately By Sending A Blank Mail @ &amp;nbsp;
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16740126&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Spirituality-Paradise-subscribe@...&lt;/a&gt; 
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; ____________________________________________________________________________________
&lt;br&gt;Be a better friend, newshound, and 
&lt;br&gt;know-it-all with Yahoo! Mobile. &amp;nbsp;Try it now. &amp;nbsp;&lt;a href=&quot;http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Disbling-and-Eanbling-an-openldap-ACCOUNT-tp16740126p16740126.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16717283</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-15T22:19:03Z</published>
	<updated>2008-04-15T22:19:03Z</updated>
	<author>
		<name>Jyotishmaan</name>
	</author>
	<content type="html">Hello Prakash,
&lt;br&gt;&lt;br&gt;That is fine. Thanks, it serves the purpose. But the thing is that-once i add this attribue to a uid and set its value say 0 (anyinteger) it disables the account and the user gets the message ofexpiry of his password. 
&lt;br&gt;&lt;br&gt;But then if there is any way again to enable the same account by deleting this attribute etc.
&lt;br&gt;&lt;br&gt;I am trying since yesterday night.
&lt;br&gt;&lt;br&gt;Please give some pointers!!!
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Thanks, &amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks, 
&lt;br&gt;Jyotishmaan Ray 
&lt;br&gt;Moderator Of Paradise Groups 
&lt;br&gt;&lt;a href=&quot;http://yahoogroups.com/group/Spirituality-Paradise&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://yahoogroups.com/group/Spirituality-Paradise&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;Are You Spiritually Aware &amp;nbsp;!!! Are You Enjoying Yourself &amp;nbsp;!!! &amp;nbsp;See What All You Had Been Missing !!!!
&lt;br&gt;Please Join Immediately By Sending A Blank Mail @ &amp;nbsp;
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16717283&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Spirituality-Paradise-subscribe@...&lt;/a&gt; 
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Prakash Velayutham &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16717283&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;prakash.velayutham@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: Andrew Morgan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16717283&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;morgan@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cc: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16717283&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pamldap@...&lt;/a&gt;
&lt;br&gt;Sent: Monday, April 14, 2008 10:22:19 PM
&lt;br&gt;Subject: Re: [pamldap] How to make it unsuccessful authentication ??
&lt;br&gt;&lt;br&gt;If you use the shadowAccount ObjectClass, I think you can use the &amp;nbsp;
&lt;br&gt;attribute shadowExpire to control this in OpenLDAP.
&lt;br&gt;&lt;br&gt;Prakash
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; ____________________________________________________________________________________
&lt;br&gt;Be a better friend, newshound, and 
&lt;br&gt;know-it-all with Yahoo! Mobile. &amp;nbsp;Try it now. &amp;nbsp;&lt;a href=&quot;http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16717283.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16714313</id>
	<title>pam_ldap dynamic groups</title>
	<published>2008-04-15T17:45:59Z</published>
	<updated>2008-04-15T17:45:59Z</updated>
	<author>
		<name>jheenan</name>
	</author>
	<content type="html">Pam LDAP List,
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Does pam_ldap support dynamic groups, that is groups that return in the form memberUrl: instead of the memberUid: form?
&lt;br&gt;&amp;nbsp;
&lt;br&gt;If so how do I set it up to use dynamic groups?
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Thanks
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Joel</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/pam_ldap-dynamic-groups-tp16714313p16714313.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16714859</id>
	<title>does pam_ldap support dynamic groups</title>
	<published>2008-04-15T17:24:10Z</published>
	<updated>2008-04-15T17:24:10Z</updated>
	<author>
		<name>jheenan</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.0 Transitional//EN&quot;&gt;
&lt;HTML&gt;&lt;HEAD&gt;
&lt;META http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;META content=&quot;MSHTML 6.00.2900.3268&quot; name=GENERATOR&gt;&lt;/HEAD&gt;
&lt;BODY&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;Pam LDAP
List,&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;Does pam_ldap
support dynamic groups, that is groups that return in the form memberUrl:
instead of the memberUid: form?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;If so how do I set
it up to use dynamic groups?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;Thanks&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=117482805-15042008&gt;&lt;FONT face=Arial size=2&gt;Joel&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;p&gt;&lt;/p&gt;
&lt;hr size=2 width=&quot;100%&quot; align=center tabindex=-1&gt;
&lt;font face=Arial size=1&gt;The information contained in this e-mail message and any accompanying files is or may be confidential. If you are not the intended recipient, any use, dissemination, reliance, forwarding, printing or copying of this e-mail or any attached files is unauthorised. This e-mail is subject to copyright. No part of it should be reproduced, adapted or communicated without the written consent of the copyright owner. If you have received this e-mail in error please advise the sender immediately by return e-mail or telephone and delete all copies. Fairfax does not guarantee the accuracy or completeness of any information contained in this e-mail or attached files. Internet communications are not secure, therefore Fairfax does not accept legal responsibility for the contents of this message or attached files.&lt;/font&gt;
&lt;hr size=2 width=&quot;100%&quot; align=center tabindex=-1&gt;
&lt;/BODY&gt;&lt;/HTML&gt;
</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/does-pam_ldap-support-dynamic-groups-tp16714859p16714859.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16690069</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-14T12:49:25Z</published>
	<updated>2008-04-14T12:49:25Z</updated>
	<author>
		<name>Gavin Henry</name>
	</author>
	<content type="html">&amp;lt;quote who=&amp;quot;Prakash Velayutham&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; If you use the shadowAccount ObjectClass, I think you can use the
&lt;br&gt;&amp;gt; attribute shadowExpire to control this in OpenLDAP.
&lt;br&gt;&lt;br&gt;Also if you use the Password Policy Overlay, I'm sure this is what SunOne
&lt;br&gt;does with it's own account/policy module.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Prakash
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Apr 14, 2008, at 12:28 PM, Andrew Morgan wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Sat, 12 Apr 2008, Jyotishmaan Ray wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Please see below for your reply,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Yes, that is what i exactly meant. Suspend, means not allowing the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; user to have successful authentication, without hampering his
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; password, for some time !!
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I'm not familiar with OpenLDAP, but the Sun Directory Server offers
&lt;br&gt;&amp;gt;&amp;gt; a way to &amp;quot;disable&amp;quot; accounts. &amp;nbsp;A disabled account will always fail to
&lt;br&gt;&amp;gt;&amp;gt; authenticate to the LDAP server, but the stored password is not
&lt;br&gt;&amp;gt;&amp;gt; modified. The account can be un-disabled anytime without setting a
&lt;br&gt;&amp;gt;&amp;gt; new password.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Does OpenLDAP offer a similar feature?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; 	Andy
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Prakash Velayutham
&lt;br&gt;&amp;gt; Programmer / Analyst
&lt;br&gt;&amp;gt; Cincinnati Children's Hospital Medical Center
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16690069.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16685196</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-14T09:52:19Z</published>
	<updated>2008-04-14T09:52:19Z</updated>
	<author>
		<name>vsp_123</name>
	</author>
	<content type="html">If you use the shadowAccount ObjectClass, I think you can use the &amp;nbsp;
&lt;br&gt;attribute shadowExpire to control this in OpenLDAP.
&lt;br&gt;&lt;br&gt;Prakash
&lt;br&gt;&lt;br&gt;&lt;br&gt;On Apr 14, 2008, at 12:28 PM, Andrew Morgan wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Sat, 12 Apr 2008, Jyotishmaan Ray wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Please see below for your reply,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Yes, that is what i exactly meant. Suspend, means not allowing the &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; user to have successful authentication, without hampering his &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; password, for some time !!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'm not familiar with OpenLDAP, but the Sun Directory Server offers &amp;nbsp;
&lt;br&gt;&amp;gt; a way to &amp;quot;disable&amp;quot; accounts. &amp;nbsp;A disabled account will always fail to &amp;nbsp;
&lt;br&gt;&amp;gt; authenticate to the LDAP server, but the stored password is not &amp;nbsp;
&lt;br&gt;&amp;gt; modified. The account can be un-disabled anytime without setting a &amp;nbsp;
&lt;br&gt;&amp;gt; new password.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Does OpenLDAP offer a similar feature?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 	Andy
&lt;/div&gt;&lt;br&gt;Prakash Velayutham
&lt;br&gt;Programmer / Analyst
&lt;br&gt;Cincinnati Children's Hospital Medical Center
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16685196.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16685134</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-14T09:28:17Z</published>
	<updated>2008-04-14T09:28:17Z</updated>
	<author>
		<name>Andrew Morgan</name>
	</author>
	<content type="html">On Sat, 12 Apr 2008, Jyotishmaan Ray wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Please see below for your reply,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Yes, that is what i exactly meant. Suspend, means not allowing the user 
&lt;br&gt;&amp;gt; to have successful authentication, without hampering his password, for 
&lt;br&gt;&amp;gt; some time !!
&lt;br&gt;&lt;br&gt;I'm not familiar with OpenLDAP, but the Sun Directory Server offers a way 
&lt;br&gt;to &amp;quot;disable&amp;quot; accounts. &amp;nbsp;A disabled account will always fail to 
&lt;br&gt;authenticate to the LDAP server, but the stored password is not modified. 
&lt;br&gt;The account can be un-disabled anytime without setting a new password.
&lt;br&gt;&lt;br&gt;Does OpenLDAP offer a similar feature?
&lt;br&gt;&lt;br&gt;&amp;nbsp;	Andy
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16685134.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16680710</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-14T05:43:19Z</published>
	<updated>2008-04-14T05:43:19Z</updated>
	<author>
		<name>Jason Morrill</name>
	</author>
	<content type="html">So let me rephrase you're request just to make sure I understand what you're
&lt;br&gt;asking for:
&lt;br&gt;&lt;br&gt;A user sucessfully logs into a server. Then their account is immediately locked
&lt;br&gt;out so they cannot log in again for a period of time. Perhaps you're doing this
&lt;br&gt;because you don't want a user to log into a server more than once is a 5 minute
&lt;br&gt;period, for example ?
&lt;br&gt;&lt;br&gt;I'm not sure that pamLDAP is the proper place to look for the solution.
&lt;br&gt;The way I see it you need one of these solutions:
&lt;br&gt;&lt;br&gt;1) The LDAP Directory locks an account after a successful (or even unsuccessful)
&lt;br&gt;log in.
&lt;br&gt;&lt;br&gt;2) Your application, which is using pamLDAP to speak the the Directory, needs to
&lt;br&gt;cache the user's name and temporarily block them from re-connecting for a period
&lt;br&gt;of time.
&lt;br&gt;&lt;br&gt;If you're the developer for a particular application then I'd suggest going with
&lt;br&gt;solution #2. If you're the administrator of the Directory then perhaps you can
&lt;br&gt;find a solution there.
&lt;br&gt;&lt;br&gt;Thanks!
&lt;br&gt;&amp;nbsp;Jason Morrill
&lt;br&gt;&amp;nbsp;IT Manager
&lt;br&gt;&amp;nbsp;Child &amp; Family Agency of Southeastern Connecticut
&lt;br&gt;&amp;nbsp;(860) 443-2896 x1422
&lt;br&gt;&lt;br&gt;&lt;br&gt;Quoting Jyotishmaan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16680710&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jyotishmaan@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Yes, I agree with you.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; My question remains unasnwered as it could not be understood!!!!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Here it goes once again:-
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; A user x logs onto &amp;nbsp;his system say-&amp;quot;x&amp;quot; which then is being checked with the
&lt;br&gt;&amp;gt; stored entry in the openldap database, and if it only matches that, the
&lt;br&gt;&amp;gt; authentication process is said to be successful and the user is said to have
&lt;br&gt;&amp;gt; successful authentication from his system &amp;quot;x&amp;quot; to the server say &amp;quot;y&amp;quot;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Well after this phase of authentication, comes authirization, as such to
&lt;br&gt;&amp;gt; check -&amp;quot;who has been granted what&amp;quot; ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; My question, was it is possible to suspend a user to successfully log onto
&lt;br&gt;&amp;gt; the server system, without affectinng his password etc for a short period of
&lt;br&gt;&amp;gt; time something called &amp;quot;quarantine&amp;quot; , plz correct me if i am wrong. This i
&lt;br&gt;&amp;gt; need to set up in my kind of adminitration where the users has been &amp;nbsp;given
&lt;br&gt;&amp;gt; limited &amp;nbsp;access privleges and downloading capacities etc.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Plz Give me some pointers !!!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Jason Morrill wrote:
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Perhaps I'm as confused as everyone else on this list.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Security is typical two-fold:
&lt;br&gt;&amp;gt; &amp;gt; 1) Authentication = the username exists in the system and the password
&lt;br&gt;&amp;gt; &amp;gt; matches
&lt;br&gt;&amp;gt; &amp;gt; 2) Authorization = the username is allows to do what is being asked
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; In many systems Authentication is all that is needed to get in the 'front
&lt;br&gt;&amp;gt; &amp;gt; door'.
&lt;br&gt;&amp;gt; &amp;gt; Authorization is left for more detailed security measures.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; For example:
&lt;br&gt;&amp;gt; &amp;gt; Let's say we have a basic Webmail application. Bob, enters his information
&lt;br&gt;&amp;gt; &amp;gt; into
&lt;br&gt;&amp;gt; &amp;gt; a 'login' screen. That information is then **Authenticated** against the
&lt;br&gt;&amp;gt; &amp;gt; Directory using LDAP. Let's say he entered the correct info. So now he's
&lt;br&gt;&amp;gt; &amp;gt; part
&lt;br&gt;&amp;gt; &amp;gt; way into the Webmail system. Now Webmail checks Bobs **Authorization** to
&lt;br&gt;&amp;gt; &amp;gt; see
&lt;br&gt;&amp;gt; &amp;gt; if it should show him links to things like 'Admin' and 'Edit Global
&lt;br&gt;&amp;gt; &amp;gt; Addresbook'. Since Bob is not Authorizated for that level he doesn't see
&lt;br&gt;&amp;gt; &amp;gt; those
&lt;br&gt;&amp;gt; &amp;gt; options.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; For a further elaboration on authentication vs. authorization:
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://en.wikipedia.org/wiki/Authorization&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://en.wikipedia.org/wiki/Authorization&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; I know this doesn't answer your question but I don't think anyone here
&lt;br&gt;&amp;gt; &amp;gt; understands your question. Perhaps the information I've outlined above
&lt;br&gt;&amp;gt; &amp;gt; will
&lt;br&gt;&amp;gt; &amp;gt; help you to rephrase it so we can understand what you're asking for.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Jason
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Quoting Jyotishmaan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16680710&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jyotishmaan@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Yes, i am sure you are wrong, as per my knowledge and experience with
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; openldap.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Please give some pointers on this-In what wayz can i make my request DN
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; and
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; not match with the entry stored in the database ?
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; vsp_123 wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt; Hi,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt; I always thought authorization came after authentication. But I guess
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt; I could be wrong :)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt; Prakash
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt; On Apr 10, 2008, at 3:08 AM, Jyotishmaan Ray wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; Hello List,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; Can anybody let me know if there are anywayz that, after
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; authorization, authentication can be stopped ??
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; In other words when a user logs on and he is being authorized and
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; his entry is checked in the database but after that, is it possible
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; to make it a unsuccessful authentication manually for a sepcific
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; user ?
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; This I want to do, in order to suspend the user to log on for some
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; time, temporarily.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; Please throw some pointers in this direction !!!!
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; Jyotishmaan Ray
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt; Prakash Velayutham
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt; Programmer / Analyst
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt; Cincinnati Children's Hospital Medical Center
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; View this message in context:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;a href=&quot;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html&lt;/a&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Sent from the PAM LDAP mailing list archive at Nabble.com.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; This message has been scanned for viruses and
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; dangerous content by MailScanner, and is
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; believed to be clean.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; This message has been scanned for viruses and
&lt;br&gt;&amp;gt; &amp;gt; dangerous content by MailScanner, and is
&lt;br&gt;&amp;gt; &amp;gt; believed to be clean.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; View this message in context:
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;a href=&quot;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16646393.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16646393.html&lt;/a&gt;&lt;br&gt;&amp;gt; Sent from the PAM LDAP mailing list archive at Nabble.com.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; This message has been scanned for viruses and
&lt;br&gt;&amp;gt; dangerous content by MailScanner, and is
&lt;br&gt;&amp;gt; believed to be clean.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;This message has been scanned for viruses and
&lt;br&gt;dangerous content by MailScanner, and is
&lt;br&gt;believed to be clean.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16680710.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16651500</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-12T06:41:02Z</published>
	<updated>2008-04-12T06:41:02Z</updated>
	<author>
		<name>Jyotishmaan</name>
	</author>
	<content type="html">Please see below for your reply,
&lt;br&gt;&lt;br&gt;Yes, that is what i exactly meant. Suspend, means not allowing the user to have successful authentication, without hampering his password, for some time !!
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks, 
&lt;br&gt;Jyotishmaan Ray 
&lt;br&gt;Moderator Of Paradise Groups 
&lt;br&gt;&lt;a href=&quot;http://yahoogroups.com/group/Spirituality-Paradise&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://yahoogroups.com/group/Spirituality-Paradise&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;Are You Spiritually Aware &amp;nbsp;!!! Are You Enjoying Yourself &amp;nbsp;!!! &amp;nbsp;See What All You Had Been Missing !!!!
&lt;br&gt;Please Join Immediately By Sending A Blank Mail @ &amp;nbsp;
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16651500&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Spirituality-Paradise-subscribe@...&lt;/a&gt; 
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Prakash Velayutham &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16651500&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;prakash.velayutham@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: Jyotishmaan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16651500&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jyotishmaan@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cc: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16651500&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pamldap@...&lt;/a&gt;
&lt;br&gt;Sent: Saturday, April 12, 2008 6:02:53 PM
&lt;br&gt;Subject: Re: [pamldap] How to make it unsuccessful authentication ??
&lt;br&gt;&lt;br&gt;Hi,
&lt;br&gt;&lt;br&gt;* Do you want the user to be not allowed to login even if his &amp;nbsp;
&lt;br&gt;credential is correct and hence is properly authenticated by PAM?
&lt;br&gt;&lt;br&gt;* What does suspend in this case mean?
&lt;br&gt;&lt;br&gt;Prakash
&lt;br&gt;&lt;br&gt;On Apr 12, 2008, at 3:54 AM, Jyotishmaan wrote:
&lt;br&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________
&lt;br&gt;Do You Yahoo!?
&lt;br&gt;Tired of spam? &amp;nbsp;Yahoo! Mail has the best spam protection around 
&lt;br&gt;&lt;a href=&quot;http://mail.yahoo.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://mail.yahoo.com&lt;/a&gt;&amp;nbsp;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16651500.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16651030</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-12T05:32:53Z</published>
	<updated>2008-04-12T05:32:53Z</updated>
	<author>
		<name>vsp_123</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;* Do you want the user to be not allowed to login even if his &amp;nbsp;
&lt;br&gt;credential is correct and hence is properly authenticated by PAM?
&lt;br&gt;&lt;br&gt;* What does suspend in this case mean?
&lt;br&gt;&lt;br&gt;Prakash
&lt;br&gt;&lt;br&gt;On Apr 12, 2008, at 3:54 AM, Jyotishmaan wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Yes, I agree with you.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; My question remains unasnwered as it could not be understood!!!!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Here it goes once again:-
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; A user x logs onto &amp;nbsp;his system say-&amp;quot;x&amp;quot; which then is being checked &amp;nbsp;
&lt;br&gt;&amp;gt; with the
&lt;br&gt;&amp;gt; stored entry in the openldap database, and if it only matches that, &amp;nbsp;
&lt;br&gt;&amp;gt; the
&lt;br&gt;&amp;gt; authentication process is said to be successful and the user is said &amp;nbsp;
&lt;br&gt;&amp;gt; to have
&lt;br&gt;&amp;gt; successful authentication from his system &amp;quot;x&amp;quot; to the server say &amp;quot;y&amp;quot;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Well after this phase of authentication, comes authirization, as &amp;nbsp;
&lt;br&gt;&amp;gt; such to
&lt;br&gt;&amp;gt; check -&amp;quot;who has been granted what&amp;quot; ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; My question, was it is possible to suspend a user to successfully &amp;nbsp;
&lt;br&gt;&amp;gt; log onto
&lt;br&gt;&amp;gt; the server system, without affectinng his password etc for a short &amp;nbsp;
&lt;br&gt;&amp;gt; period of
&lt;br&gt;&amp;gt; time something called &amp;quot;quarantine&amp;quot; , plz correct me if i am wrong. &amp;nbsp;
&lt;br&gt;&amp;gt; This i
&lt;br&gt;&amp;gt; need to set up in my kind of adminitration where the users has been &amp;nbsp; 
&lt;br&gt;&amp;gt; given
&lt;br&gt;&amp;gt; limited &amp;nbsp;access privleges and downloading capacities etc.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Plz Give me some pointers !!!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Jason Morrill wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Perhaps I'm as confused as everyone else on this list.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Security is typical two-fold:
&lt;br&gt;&amp;gt;&amp;gt; 1) Authentication = the username exists in the system and the &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; password
&lt;br&gt;&amp;gt;&amp;gt; matches
&lt;br&gt;&amp;gt;&amp;gt; 2) Authorization = the username is allows to do what is being asked
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; In many systems Authentication is all that is needed to get in the &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; 'front
&lt;br&gt;&amp;gt;&amp;gt; door'.
&lt;br&gt;&amp;gt;&amp;gt; Authorization is left for more detailed security measures.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; For example:
&lt;br&gt;&amp;gt;&amp;gt; Let's say we have a basic Webmail application. Bob, enters his &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; information
&lt;br&gt;&amp;gt;&amp;gt; into
&lt;br&gt;&amp;gt;&amp;gt; a 'login' screen. That information is then **Authenticated** &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; against the
&lt;br&gt;&amp;gt;&amp;gt; Directory using LDAP. Let's say he entered the correct info. So now &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; he's
&lt;br&gt;&amp;gt;&amp;gt; part
&lt;br&gt;&amp;gt;&amp;gt; way into the Webmail system. Now Webmail checks Bobs &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; **Authorization** to
&lt;br&gt;&amp;gt;&amp;gt; see
&lt;br&gt;&amp;gt;&amp;gt; if it should show him links to things like 'Admin' and 'Edit Global
&lt;br&gt;&amp;gt;&amp;gt; Addresbook'. Since Bob is not Authorizated for that level he &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; doesn't see
&lt;br&gt;&amp;gt;&amp;gt; those
&lt;br&gt;&amp;gt;&amp;gt; options.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; For a further elaboration on authentication vs. authorization:
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://en.wikipedia.org/wiki/Authorization&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://en.wikipedia.org/wiki/Authorization&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I know this doesn't answer your question but I don't think anyone &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; here
&lt;br&gt;&amp;gt;&amp;gt; understands your question. Perhaps the information I've outlined &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; above
&lt;br&gt;&amp;gt;&amp;gt; will
&lt;br&gt;&amp;gt;&amp;gt; help you to rephrase it so we can understand what you're asking for.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Jason
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Quoting Jyotishmaan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16651030&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jyotishmaan@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Yes, i am sure you are wrong, as per my knowledge and experience &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; with
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; openldap.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Please give some pointers on this-In what wayz can i make my &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; request DN
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; not match with the entry stored in the database ?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; vsp_123 wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I always thought authorization came after authentication. But I &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; guess
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I could be wrong :)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Prakash
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Apr 10, 2008, at 3:08 AM, Jyotishmaan Ray wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello List,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Can anybody let me know if there are anywayz that, after
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; authorization, authentication can be stopped ??
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; In other words when a user logs on and he is being authorized and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; his entry is checked in the database but after that, is it &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; possible
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; to make it a unsuccessful authentication manually for a sepcific
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; user ?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This I want to do, in order to suspend the user to log on for some
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; time, temporarily.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Please throw some pointers in this direction !!!!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Jyotishmaan Ray
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Prakash Velayutham
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Programmer / Analyst
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Cincinnati Children's Hospital Medical Center
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; View this message in context:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Sent from the PAM LDAP mailing list archive at Nabble.com.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; This message has been scanned for viruses and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; dangerous content by MailScanner, and is
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; believed to be clean.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -- 
&lt;br&gt;&amp;gt;&amp;gt; This message has been scanned for viruses and
&lt;br&gt;&amp;gt;&amp;gt; dangerous content by MailScanner, and is
&lt;br&gt;&amp;gt;&amp;gt; believed to be clean.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; View this message in context: &lt;a href=&quot;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16646393.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16646393.html&lt;/a&gt;&lt;br&gt;&amp;gt; Sent from the PAM LDAP mailing list archive at Nabble.com.
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;Prakash Velayutham
&lt;br&gt;Programmer / Analyst
&lt;br&gt;Cincinnati Children's Hospital Medical Center
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16651030.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16646393</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-12T00:54:54Z</published>
	<updated>2008-04-12T00:54:54Z</updated>
	<author>
		<name>Jyotishmaan</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;Yes, I agree with you.
&lt;br&gt;&lt;br&gt;My question remains unasnwered as it could not be understood!!!!
&lt;br&gt;&lt;br&gt;Here it goes once again:-
&lt;br&gt;&lt;br&gt;A user x logs onto &amp;nbsp;his system say-&amp;quot;x&amp;quot; which then is being checked with the stored entry in the openldap database, and if it only matches that, the authentication process is said to be successful and the user is said to have successful authentication from his system &amp;quot;x&amp;quot; to the server say &amp;quot;y&amp;quot;.
&lt;br&gt;&lt;br&gt;Well after this phase of authentication, comes authirization, as such to check -&amp;quot;who has been granted what&amp;quot; ?
&lt;br&gt;&lt;br&gt;My question, was it is possible to suspend a user to successfully log onto the server system, without affectinng his password etc for a short period of time something called &amp;quot;quarantine&amp;quot; , plz correct me if i am wrong. This i need to set up in my kind of adminitration where the users has been &amp;nbsp;given limited &amp;nbsp;access privleges and downloading capacities etc.
&lt;br&gt;&lt;br&gt;Plz Give me some pointers !!!
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Jason Morrill wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Perhaps I'm as confused as everyone else on this list.
&lt;br&gt;&lt;br&gt;Security is typical two-fold:
&lt;br&gt;1) Authentication = the username exists in the system and the password matches
&lt;br&gt;2) Authorization = the username is allows to do what is being asked
&lt;br&gt;&lt;br&gt;In many systems Authentication is all that is needed to get in the 'front door'.
&lt;br&gt;Authorization is left for more detailed security measures.
&lt;br&gt;&lt;br&gt;For example:
&lt;br&gt;Let's say we have a basic Webmail application. Bob, enters his information into
&lt;br&gt;a 'login' screen. That information is then **Authenticated** against the
&lt;br&gt;Directory using LDAP. Let's say he entered the correct info. So now he's part
&lt;br&gt;way into the Webmail system. Now Webmail checks Bobs **Authorization** to see
&lt;br&gt;if it should show him links to things like 'Admin' and 'Edit Global
&lt;br&gt;Addresbook'. Since Bob is not Authorizated for that level he doesn't see those
&lt;br&gt;options.
&lt;br&gt;&lt;br&gt;For a further elaboration on authentication vs. authorization:
&lt;br&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Authorization&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://en.wikipedia.org/wiki/Authorization&lt;/a&gt;&lt;br&gt;&lt;br&gt;I know this doesn't answer your question but I don't think anyone here
&lt;br&gt;understands your question. Perhaps the information I've outlined above will
&lt;br&gt;help you to rephrase it so we can understand what you're asking for.
&lt;br&gt;&lt;br&gt;Jason
&lt;br&gt;&lt;br&gt;&lt;br&gt;Quoting Jyotishmaan &amp;lt;jyotishmaan@yahoo.com&amp;gt;:
&lt;br&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Yes, i am sure you are wrong, as per my knowledge and experience with
&lt;br&gt;&amp;gt; openldap.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please give some pointers on this-In what wayz can i make my request DN and
&lt;br&gt;&amp;gt; not match with the entry stored in the database ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; vsp_123 wrote:
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Hi,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; I always thought authorization came after authentication. But I guess
&lt;br&gt;&amp;gt; &amp;gt; I could be wrong :)
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Prakash
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; On Apr 10, 2008, at 3:08 AM, Jyotishmaan Ray wrote:
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Hello List,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Can anybody let me know if there are anywayz that, after
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; authorization, authentication can be stopped ??
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; In other words when a user logs on and he is being authorized and
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; his entry is checked in the database but after that, is it possible
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; to make it a unsuccessful authentication manually for a sepcific
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; user ?
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; This I want to do, in order to suspend the user to log on for some
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; time, temporarily.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Please throw some pointers in this direction !!!!
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Jyotishmaan Ray
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Prakash Velayutham
&lt;br&gt;&amp;gt; &amp;gt; Programmer / Analyst
&lt;br&gt;&amp;gt; &amp;gt; Cincinnati Children's Hospital Medical Center
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; View this message in context:
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html&lt;/a&gt;&lt;br&gt;&amp;gt; Sent from the PAM LDAP mailing list archive at Nabble.com.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; This message has been scanned for viruses and
&lt;br&gt;&amp;gt; dangerous content by MailScanner, and is
&lt;br&gt;&amp;gt; believed to be clean.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;This message has been scanned for viruses and
&lt;br&gt;dangerous content by MailScanner, and is
&lt;br&gt;believed to be clean.
&lt;br&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16646393.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16634075</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-11T05:51:12Z</published>
	<updated>2008-04-11T05:51:12Z</updated>
	<author>
		<name>Jason Morrill</name>
	</author>
	<content type="html">Perhaps I'm as confused as everyone else on this list.
&lt;br&gt;&lt;br&gt;Security is typical two-fold:
&lt;br&gt;1) Authentication = the username exists in the system and the password matches
&lt;br&gt;2) Authorization = the username is allows to do what is being asked
&lt;br&gt;&lt;br&gt;In many systems Authentication is all that is needed to get in the 'front door'.
&lt;br&gt;Authorization is left for more detailed security measures.
&lt;br&gt;&lt;br&gt;For example:
&lt;br&gt;Let's say we have a basic Webmail application. Bob, enters his information into
&lt;br&gt;a 'login' screen. That information is then **Authenticated** against the
&lt;br&gt;Directory using LDAP. Let's say he entered the correct info. So now he's part
&lt;br&gt;way into the Webmail system. Now Webmail checks Bobs **Authorization** to see
&lt;br&gt;if it should show him links to things like 'Admin' and 'Edit Global
&lt;br&gt;Addresbook'. Since Bob is not Authorizated for that level he doesn't see those
&lt;br&gt;options.
&lt;br&gt;&lt;br&gt;For a further elaboration on authentication vs. authorization:
&lt;br&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Authorization&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://en.wikipedia.org/wiki/Authorization&lt;/a&gt;&lt;br&gt;&lt;br&gt;I know this doesn't answer your question but I don't think anyone here
&lt;br&gt;understands your question. Perhaps the information I've outlined above will
&lt;br&gt;help you to rephrase it so we can understand what you're asking for.
&lt;br&gt;&lt;br&gt;Jason
&lt;br&gt;&lt;br&gt;&lt;br&gt;Quoting Jyotishmaan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16634075&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jyotishmaan@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Yes, i am sure you are wrong, as per my knowledge and experience with
&lt;br&gt;&amp;gt; openldap.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please give some pointers on this-In what wayz can i make my request DN and
&lt;br&gt;&amp;gt; not match with the entry stored in the database ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; vsp_123 wrote:
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Hi,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; I always thought authorization came after authentication. But I guess
&lt;br&gt;&amp;gt; &amp;gt; I could be wrong :)
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Prakash
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; On Apr 10, 2008, at 3:08 AM, Jyotishmaan Ray wrote:
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Hello List,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Can anybody let me know if there are anywayz that, after
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; authorization, authentication can be stopped ??
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; In other words when a user logs on and he is being authorized and
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; his entry is checked in the database but after that, is it possible
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; to make it a unsuccessful authentication manually for a sepcific
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; user ?
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; This I want to do, in order to suspend the user to log on for some
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; time, temporarily.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Please throw some pointers in this direction !!!!
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; Jyotishmaan Ray
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Prakash Velayutham
&lt;br&gt;&amp;gt; &amp;gt; Programmer / Analyst
&lt;br&gt;&amp;gt; &amp;gt; Cincinnati Children's Hospital Medical Center
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; View this message in context:
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;a href=&quot;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html&lt;/a&gt;&lt;br&gt;&amp;gt; Sent from the PAM LDAP mailing list archive at Nabble.com.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; This message has been scanned for viruses and
&lt;br&gt;&amp;gt; dangerous content by MailScanner, and is
&lt;br&gt;&amp;gt; believed to be clean.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;This message has been scanned for viruses and
&lt;br&gt;dangerous content by MailScanner, and is
&lt;br&gt;believed to be clean.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16634075.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16627298</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-11T02:45:06Z</published>
	<updated>2008-04-11T02:45:06Z</updated>
	<author>
		<name>Jyotishmaan</name>
	</author>
	<content type="html">Yes, i am sure you are wrong, as per my knowledge and experience with openldap.
&lt;br&gt;&lt;br&gt;Please give some pointers on this-In what wayz can i make my request DN and not match with the entry stored in the database ?
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;vsp_123 wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Hi,
&lt;br&gt;&lt;br&gt;I always thought authorization came after authentication. But I guess &amp;nbsp;
&lt;br&gt;I could be wrong :)
&lt;br&gt;&lt;br&gt;Prakash
&lt;br&gt;&lt;br&gt;&lt;br&gt;On Apr 10, 2008, at 3:08 AM, Jyotishmaan Ray wrote:
&lt;br&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hello List,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Can anybody let me know if there are anywayz that, after &amp;nbsp;
&lt;br&gt;&amp;gt; authorization, authentication can be stopped ??
&lt;br&gt;&amp;gt; In other words when a user logs on and he is being authorized and &amp;nbsp;
&lt;br&gt;&amp;gt; his entry is checked in the database but after that, is it possible &amp;nbsp;
&lt;br&gt;&amp;gt; to make it a unsuccessful authentication manually for a sepcific &amp;nbsp;
&lt;br&gt;&amp;gt; user ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This I want to do, in order to suspend the user to log on for some &amp;nbsp;
&lt;br&gt;&amp;gt; time, temporarily.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please throw some pointers in this direction !!!!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; Jyotishmaan Ray
&lt;br&gt;&lt;br&gt;Prakash Velayutham
&lt;br&gt;Programmer / Analyst
&lt;br&gt;Cincinnati Children's Hospital Medical Center
&lt;br&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16627298.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16616456</id>
	<title>Re: How to make it unsuccessful authentication ??</title>
	<published>2008-04-10T09:32:10Z</published>
	<updated>2008-04-10T09:32:10Z</updated>
	<author>
		<name>vsp_123</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I always thought authorization came after authentication. But I guess &amp;nbsp;
&lt;br&gt;I could be wrong :)
&lt;br&gt;&lt;br&gt;Prakash
&lt;br&gt;&lt;br&gt;&lt;br&gt;On Apr 10, 2008, at 3:08 AM, Jyotishmaan Ray wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hello List,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Can anybody let me know if there are anywayz that, after &amp;nbsp;
&lt;br&gt;&amp;gt; authorization, authentication can be stopped ??
&lt;br&gt;&amp;gt; In other words when a user logs on and he is being authorized and &amp;nbsp;
&lt;br&gt;&amp;gt; his entry is checked in the database but after that, is it possible &amp;nbsp;
&lt;br&gt;&amp;gt; to make it a unsuccessful authentication manually for a sepcific &amp;nbsp;
&lt;br&gt;&amp;gt; user ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This I want to do, in order to suspend the user to log on for some &amp;nbsp;
&lt;br&gt;&amp;gt; time, temporarily.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please throw some pointers in this direction !!!!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; Jyotishmaan Ray
&lt;/div&gt;&lt;br&gt;Prakash Velayutham
&lt;br&gt;Programmer / Analyst
&lt;br&gt;Cincinnati Children's Hospital Medical Center
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16616456.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-16605307</id>
	<title>How to make it unsuccessful authentication ??</title>
	<published>2008-04-10T00:08:49Z</published>
	<updated>2008-04-10T00:08:49Z</updated>
	<author>
		<name>Jyotishmaan</name>
	</author>
	<content type="html">&lt;br&gt;&amp;nbsp;Hello List,
&lt;br&gt;&lt;br&gt;Can anybody let me know if there are anywayz that, after authorization, authentication can be stopped ??
&lt;br&gt;In other words when a user logs on and he is being authorized and his entry is checked in the database but after that, is it possible to make it a unsuccessful authentication manually for a sepcific user ?
&lt;br&gt;&lt;br&gt;This I want to do, in order to suspend the user to log on for some time, temporarily.
&lt;br&gt;&lt;br&gt;Please throw some pointers in this direction !!!!
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks, 
&lt;br&gt;Jyotishmaan Ray 
&lt;br&gt;Moderator Of Paradise Groups 
&lt;br&gt;&lt;a href=&quot;http://yahoogroups.com/group/Spirituality-Paradise&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://yahoogroups.com/group/Spirituality-Paradise&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;Are You Spiritually Aware &amp;nbsp;!!! Are You Enjoying Yourself &amp;nbsp;!!! &amp;nbsp;See What All You Had Been Missing !!!!
&lt;br&gt;Please Join Immediately By Sending A Blank Mail @ &amp;nbsp;
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=16605307&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Spirituality-Paradise-subscribe@...&lt;/a&gt; 
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________
&lt;br&gt;Do You Yahoo!?
&lt;br&gt;Tired of spam? &amp;nbsp;Yahoo! Mail has the best spam protection around 
&lt;br&gt;&lt;a href=&quot;http://mail.yahoo.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://mail.yahoo.com&lt;/a&gt;&amp;nbsp;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-make-it-unsuccessful-authentication----tp16605307p16605307.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15848492</id>
	<title>Re: Problem setting up OpenLDAP for user authentication</title>
	<published>2008-03-05T02:05:45Z</published>
	<updated>2008-03-05T02:05:45Z</updated>
	<author>
		<name>Guennadi Liakhovetski</name>
	</author>
	<content type="html">On Wed, 5 Mar 2008, Jokke Heikkila wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; On 4.3.2008, at 12.45, Guennadi Liakhovetski wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; I'm new to LDAP, and I must say it took me a LONG time to set it up under
&lt;br&gt;&amp;gt; &amp;gt; Debian etch on both server and client at all to do anything useful.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Sorry, this is not an answer to your question, but I was interested if you
&lt;br&gt;&amp;gt; could tell does ssh login work for you (for ldap accounts) with this setup?
&lt;br&gt;&amp;gt; I've got this same setup but I'm failing to ssh in (as in this thread
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://marc.info/?l=pamldap&amp;m=120220811015423&amp;w=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://marc.info/?l=pamldap&amp;m=120220811015423&amp;w=2&lt;/a&gt;&amp;nbsp;).
&lt;br&gt;&lt;br&gt;Yes, it works for me. And sorry, I have no idea what your problem can be. 
&lt;br&gt;I think ssh might be trying some other kind of authentication - not 
&lt;br&gt;simple, but SASL? And it is not configured on your server?
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;Guennadi
&lt;br&gt;---
&lt;br&gt;Guennadi Liakhovetski
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Problem-setting-up-OpenLDAP-for-user-authentication-tp15839595p15848492.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15839595</id>
	<title>Problem setting up OpenLDAP for user authentication</title>
	<published>2008-03-04T02:45:18Z</published>
	<updated>2008-03-04T02:45:18Z</updated>
	<author>
		<name>Guennadi Liakhovetski</name>
	</author>
	<content type="html">Hi all
&lt;br&gt;&lt;br&gt;I'm new to LDAP, and I must say it took me a LONG time to set it up under 
&lt;br&gt;Debian etch on both server and client at all to do anything useful.
&lt;br&gt;&lt;br&gt;Now I can do &amp;quot;ldapsearch -x -v -L&amp;quot; type requests from remote a host and 
&lt;br&gt;locally. I then &amp;nbsp;tried switching the remote host to using LDAP for user 
&lt;br&gt;authentication. I'd like users not registered locally to be able to login 
&lt;br&gt;using ldap, and for locally-known users nothing should change.
&lt;br&gt;&lt;br&gt;I did manage to get logins to use ldap by configuring all 
&lt;br&gt;/etc/pam.d/common-* files to first try pam_unix and then, if that fails to 
&lt;br&gt;use ldap:
&lt;br&gt;&lt;br&gt;* sufficient pam_unix
&lt;br&gt;* sufficient pam_ldap (should this be &amp;quot;required?)
&lt;br&gt;&lt;br&gt;where * is &amp;quot;account&amp;quot;, &amp;quot;auth&amp;quot;, &amp;quot;password&amp;quot; and &amp;quot;session&amp;quot;. In &amp;quot;auth&amp;quot; and 
&lt;br&gt;&amp;quot;password&amp;quot; I also had to put 
&lt;br&gt;&lt;br&gt;* required pam_deny
&lt;br&gt;&lt;br&gt;after ldap, because otherwise wrong passwords were accepted. In 
&lt;br&gt;nsswitch.conf I put
&lt;br&gt;&lt;br&gt;*: files ldap
&lt;br&gt;&lt;br&gt;for &amp;quot;passwd&amp;quot;, &amp;quot;group&amp;quot;, &amp;quot;shadow&amp;quot;. Now I would expect that with sequences 
&lt;br&gt;(&amp;quot;pam_unix&amp;quot; before &amp;quot;pam_ldap&amp;quot; and &amp;quot;files&amp;quot; before &amp;quot;ldap&amp;quot;) indeed locally 
&lt;br&gt;known users wouldn't be authenticated using ldap. Unfortunately, this 
&lt;br&gt;doesn't seem to be the case. Now _all_ nss / pam requests go to the LDAP 
&lt;br&gt;server. Including calls from udevd, avahi-daemon, and others, which causes 
&lt;br&gt;them to fail in various ways.
&lt;br&gt;&lt;br&gt;What am I doing wrong?
&lt;br&gt;&lt;br&gt;I know SASL is not configured in my setup, but that shouldn't be a 
&lt;br&gt;problem? At least not for the cases when LDAP shouldn't be attempted at 
&lt;br&gt;all.
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;Guennadi
&lt;br&gt;---
&lt;br&gt;Guennadi Liakhovetski
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Problem-setting-up-OpenLDAP-for-user-authentication-tp15839595p15839595.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15697443</id>
	<title>login problem after LDAP server change</title>
	<published>2008-02-26T08:55:31Z</published>
	<updated>2008-02-26T08:55:31Z</updated>
	<author>
		<name>Frank Bonnet</name>
	</author>
	<content type="html">Hello
&lt;br&gt;&lt;br&gt;Since we change the machine supporting our LDAP server we get the following
&lt;br&gt;when normal user attempt to log in from a Linux station , below is the transcript
&lt;br&gt;of a su session but the same message appears if we attempt from the KDM login panel.
&lt;br&gt;&lt;br&gt;Feb 26 17:07:27 acme11 su[893]: (pam_unix) expired password for user exam40 (password aged)
&lt;br&gt;&lt;br&gt;We didn't any change on clients
&lt;br&gt;&lt;br&gt;The server software has been re-compiled from the same sources (2.0.27) as on the preceding machine
&lt;br&gt;and the base has been exported and re-imported from a LDIF file ...
&lt;br&gt;&lt;br&gt;Thanks for any help/infos
&lt;br&gt;&lt;br&gt;Frank
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/login-problem-after-LDAP-server-change-tp15697443p15697443.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15537091</id>
	<title>Re: Need help determining cause of login problem</title>
	<published>2008-02-17T15:11:16Z</published>
	<updated>2008-02-17T15:11:16Z</updated>
	<author>
		<name>Howard Chu</name>
	</author>
	<content type="html">Tony Earnshaw wrote:
&lt;br&gt;&amp;gt; Howard Chu skrev, on 17-02-2008 19:07:
&lt;br&gt;&amp;gt;&amp;gt; I've often thought that these tags should be logged in hex instead of
&lt;br&gt;&amp;gt;&amp;gt; decimal. Perhaps it's worth an ITS.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks a lot for all of this, Howard - much appreciated. I trust that OP
&lt;br&gt;&amp;gt; also feels the same.
&lt;br&gt;&lt;br&gt;Sure. Just remember, we're not making any of this stuff up, it's all standard 
&lt;br&gt;values defined by the RFC. As we've said many times before - it's not the 
&lt;br&gt;OpenLDAP Project's job to teach you the basics of LDAP; you're supposed to 
&lt;br&gt;know them already. You're supposed to know what's in the RFCs. We won't 
&lt;br&gt;duplicate the RFC content in our documentation, that's a waste of effort. Our 
&lt;br&gt;documentation's purpose is only to tell you how we've mapped LDAP into our code.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&amp;nbsp; &amp;nbsp;-- Howard Chu
&lt;br&gt;&amp;nbsp; &amp;nbsp;Chief Architect, Symas Corp. &amp;nbsp;&lt;a href=&quot;http://www.symas.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.symas.com&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Director, Highland Sun &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://highlandsun.com/hyc/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://highlandsun.com/hyc/&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Chief Architect, OpenLDAP &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openldap.org/project/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openldap.org/project/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15537091.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15534297</id>
	<title>Re: Need help determining cause of login problem</title>
	<published>2008-02-17T11:14:30Z</published>
	<updated>2008-02-17T11:14:30Z</updated>
	<author>
		<name>Tony Earnshaw-4</name>
	</author>
	<content type="html">Howard Chu skrev, on 17-02-2008 19:07:
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;&amp;gt; Ah. Well, this gives a subset (granted including 32) ... it's debatable
&lt;br&gt;&amp;gt;&amp;gt; whether 97, 101, 103 are status codes or error codes - where are they?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;quot;tag=97&amp;quot; is not an error code or a status code. It is a message type 
&lt;br&gt;&amp;gt; tag. Look in ldap.h for an overview of tag bits and definitions of all 
&lt;br&gt;&amp;gt; the tags used in LDAP. They're defined in hex in ldap.h, which is why 
&lt;br&gt;&amp;gt; grepping for 97 won't show it to you. 97 = 0x61, which is a Bind 
&lt;br&gt;&amp;gt; response. You won't find &amp;quot;97&amp;quot; in the RFC either, instead you find the 
&lt;br&gt;&amp;gt; ASN.1:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; BindResponse ::= [APPLICATION 1] SEQUENCE {
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;COMPONENTS OF LDAPResult,
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;serverSaslCreds &amp;nbsp; &amp;nbsp;[7] OCTET STRING OPTIONAL }
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; To really understand the correspondence you need to understand how ASN.1 
&lt;br&gt;&amp;gt; is encoded in BER. The &amp;quot;APPLICATION&amp;quot; corresponds to a specific bit 
&lt;br&gt;&amp;gt; (0x40). The value &amp;quot;1&amp;quot; is simply OR'd in, yielding 0x41. The entity is a 
&lt;br&gt;&amp;gt; structure, not a simple value, so it gets the Constructed bit, yielding 
&lt;br&gt;&amp;gt; 0x61.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I've often thought that these tags should be logged in hex instead of 
&lt;br&gt;&amp;gt; decimal. Perhaps it's worth an ITS.
&lt;/div&gt;&lt;br&gt;Thanks a lot for all of this, Howard - much appreciated. I trust that OP 
&lt;br&gt;also feels the same.
&lt;br&gt;&lt;br&gt;Best,
&lt;br&gt;&lt;br&gt;--Tonni
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Tony Earnshaw
&lt;br&gt;Email: tonni at hetnet dot nl
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15534297.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15533407</id>
	<title>Re: Need help determining cause of login problem</title>
	<published>2008-02-17T10:07:44Z</published>
	<updated>2008-02-17T10:07:44Z</updated>
	<author>
		<name>Howard Chu</name>
	</author>
	<content type="html">Tony Earnshaw wrote:
&lt;br&gt;&amp;gt; Howard Chu skrev, on 17-02-2008 02:06:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Is there a list available anywhere that gives possible reasons for error
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; messages?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Apparently not, as far as OpenLDAP is concerned.
&lt;br&gt;&amp;gt;&amp;gt; Not quite. LDAP error codes are already documented in RFC4511.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Ah. Well, this gives a subset (granted including 32) ... it's debatable
&lt;br&gt;&amp;gt; whether 97, 101, 103 are status codes or error codes - where are they?
&lt;br&gt;&lt;br&gt;&amp;quot;tag=97&amp;quot; is not an error code or a status code. It is a message type tag. Look 
&lt;br&gt;in ldap.h for an overview of tag bits and definitions of all the tags used in 
&lt;br&gt;LDAP. They're defined in hex in ldap.h, which is why grepping for 97 won't 
&lt;br&gt;show it to you. 97 = 0x61, which is a Bind response. You won't find &amp;quot;97&amp;quot; in 
&lt;br&gt;the RFC either, instead you find the ASN.1:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;BindResponse ::= [APPLICATION 1] SEQUENCE {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; COMPONENTS OF LDAPResult,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; serverSaslCreds &amp;nbsp; &amp;nbsp;[7] OCTET STRING OPTIONAL }
&lt;br&gt;&lt;br&gt;To really understand the correspondence you need to understand how ASN.1 is 
&lt;br&gt;encoded in BER. The &amp;quot;APPLICATION&amp;quot; corresponds to a specific bit (0x40). The 
&lt;br&gt;value &amp;quot;1&amp;quot; is simply OR'd in, yielding 0x41. The entity is a structure, not a 
&lt;br&gt;simple value, so it gets the Constructed bit, yielding 0x61.
&lt;br&gt;&lt;br&gt;I've often thought that these tags should be logged in hex instead of decimal. 
&lt;br&gt;Perhaps it's worth an ITS.
&lt;br&gt;&lt;br&gt;&amp;gt; 1027 [tonni:tru.leerlingen] /usr/share/doc/openldap2.4-doc-2.4.7/rfc $
&lt;br&gt;&amp;gt; grep 103 *&amp;lt;
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&amp;nbsp; &amp;nbsp;-- Howard Chu
&lt;br&gt;&amp;nbsp; &amp;nbsp;Chief Architect, Symas Corp. &amp;nbsp;&lt;a href=&quot;http://www.symas.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.symas.com&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Director, Highland Sun &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://highlandsun.com/hyc/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://highlandsun.com/hyc/&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Chief Architect, OpenLDAP &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openldap.org/project/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openldap.org/project/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15533407.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15532910</id>
	<title>FreeBSD Auth Wierdness</title>
	<published>2008-02-17T08:53:33Z</published>
	<updated>2008-02-17T08:53:33Z</updated>
	<author>
		<name>Hubuki Kai</name>
	</author>
	<content type="html">&lt;html&gt;&lt;body style=&quot;word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; &quot;&gt;
&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;Hey all,&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;I've been pounding my head against a screen for a few weeks trying to figure&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;this one out- and pounding on Google like a madman.&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;I'm running a few FreeBSD 6.2 servers, one with OpenLDAP 2.2. I have the&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;PADL nss_ldap and pam_ldap modules installed, and I have configured PAM.&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;I've been using the LDAP directory for many things- groupware, forums, wiki,&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;etc, running on the web server, which is separate from the LDAP host, so I&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;know that I can connect.&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;I can do an &quot;ldapsearch -D -W -x&quot; on all the servers. I can do &quot;getent&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;passwd&quot; and see the LDAP users there.&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;I can su to an LDAP user. I see the ldap users/groups when doing an &quot;ls -l&quot;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;(mostly, more on that later).&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;But I can not SSH into the servers as an LDAP user. Here's what happens: if&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;I &quot;ssh avishai@login&quot; I get a normal password prompt. If I enter the wrong&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;password for that user, I get another prompt, with the message:&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;&quot;Jan 27 10:47:12 login sshd[4497]: pam_ldap: error trying to bind as user&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;&quot;uid=avishai,ou=Users,dc=cwssoftware,dc=com&quot; (Invalid credentials)&quot;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;&quot;Jan 27 11:04:40 login sshd[4570]: error: PAM: authentication error for&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;avishai from cool-device.cws.local&quot;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;in /var/log/messages.&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;If I enter the correct password, I get this prompt:&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;Old Password:&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;I have tried every possible password here- empty, correct, wrong- to no&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;avail. /var/log/messages shows this:&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;&quot;Jan 27 11:05:11 login sshd[4570]: error: PAM: permission denied for avishai&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;from cool-device.cws.local&quot;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;Again, I can authenticate as this user on the LDAP server (through&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;phpldapadmin and all others), and the different messages and behavior makes&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;me know that I am talking to the LDAP server-and authenticating to some&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;degree! My ldap.conf is linked to nss_ldap.conf, both in /usr/local/etc. TLS&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;makes no difference, I've tried it on and off.&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;As to the nss, I get a bit of strangeness. As root, I see all the LDAP users&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;and groups. As a normal user, I see only the ID numbers. /etc/nsswitch.conf&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;has 644 permissions, so the normal user should be able to read the file.&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;Last, and maybe helpful, is that I periodically get a message:&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;&quot;Jan 27 10:35:00 login cron[4404]: nss_ldap: could not search LDAP server -&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;Server is unavailable&quot;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;when I know the server IS available. Especially as NSS is working with LDAP&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;more or less, this has me baffled. I'm an amateur sysadmin, so I'm not sure&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;where to look for this particular cron job, but the message is wrong, if not&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;just misleading.&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;My pam.d/sshd file is below:&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;# $FreeBSD: src/etc/pam.d/sshd,v 1.15 2003/04/30 21:57:54 markm Exp $&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;# PAM configuration for the &quot;sshd&quot; service&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;# auth&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;auth            required        pam_nologin.so          no_warn&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;auth            sufficient      pam_opie.so             no_warn&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;no_fake_prompts&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;auth            requisite       pam_opieaccess.so       no_warn allow_local&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#auth           sufficient      pam_krb5.so             no_warn&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;try_first_pass&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#auth           sufficient      pam_ssh.so              no_warn&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;try_first_pass&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;auth            sufficient      /usr/local/lib/pam_ldap.so try_first_pass&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;auth            required        pam_unix.so             no_warn&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;try_first_pass&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#auth           required        pam_deny.so             try_first_pass&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;# account&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#account        required        pam_krb5.so&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#account        required        pam_login_access.so&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;account         required        pam_unix.so&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#account        required        /usr/local/lib/pam_ldap.so&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;# session&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#session        optional        pam_ssh.so&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;session         sufficient      /usr/local/lib/pam_mkhomedir.so&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;session         required        pam_permit.so&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;# password&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#password       sufficient      pam_krb5.so             no_warn&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;try_first_pass&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;#password       sufficient      /usr/local/lib/pam_ldap.so      debug&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;password        required        pam_unix.so             no_warn&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;try_first_pass&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; min-height: 14px; &quot;&gt;&lt;br&gt;&lt;/div&gt;&lt;div style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;Any help is much appreciated!&lt;/div&gt;&lt;div&gt;&lt;br class=&quot;webkit-block-placeholder&quot;&gt;&lt;/div&gt;&lt;br&gt;&lt;div&gt; &lt;span class=&quot;Apple-style-span&quot; style=&quot;border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0; &quot;&gt;&lt;div&gt;Charlie Sibbach&lt;/div&gt;&lt;div&gt;CWS Software&lt;/div&gt;&lt;div&gt;&lt;br class=&quot;webkit-block-placeholder&quot;&gt;&lt;/div&gt;&lt;/span&gt;&lt;br class=&quot;Apple-interchange-newline&quot;&gt; &lt;/div&gt;&lt;br&gt;&lt;/body&gt;&lt;/html&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/FreeBSD-Auth-Wierdness-tp15532910p15532910.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15527821</id>
	<title>Re: Need help determining cause of login problem</title>
	<published>2008-02-16T23:54:57Z</published>
	<updated>2008-02-16T23:54:57Z</updated>
	<author>
		<name>Tony Earnshaw-4</name>
	</author>
	<content type="html">Howard Chu skrev, on 17-02-2008 02:06:
&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Is there a list available anywhere that gives possible reasons for error
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; messages?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Apparently not, as far as OpenLDAP is concerned.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Not quite. LDAP error codes are already documented in RFC4511.
&lt;br&gt;&lt;br&gt;Ah. Well, this gives a subset (granted including 32) ... it's debatable 
&lt;br&gt;whether 97, 101, 103 are status codes or error codes - where are they?
&lt;br&gt;&lt;br&gt;1027 [tonni:tru.leerlingen] /usr/share/doc/openldap2.4-doc-2.4.7/rfc $ 
&lt;br&gt;grep 103 * &amp;nbsp;&amp;lt;
&lt;br&gt;rfc2247.txt: &amp;nbsp; &amp;nbsp; &amp;nbsp; STD 13, RFC 1034, November 1987.
&lt;br&gt;rfc3088.txt: &amp;nbsp; LDAP directory services to leverage the existing DNS 
&lt;br&gt;[RFC1034]
&lt;br&gt;rfc3088.txt: &amp;nbsp; [RFC1034] &amp;nbsp;Mockapetris, P., &amp;quot;Domain Names - Concepts and 
&lt;br&gt;Facilities&amp;quot;,
&lt;br&gt;rfc3088.txt: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;STD 13, RFC 1034, November 1987.
&lt;br&gt;rfc4517.txt: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 199412161032Z
&lt;br&gt;rfc4518.txt: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0F99-0FBC 0FC6 102C-1032 1036-1039 1056-1059 1712-1714
&lt;br&gt;rfc4519.txt: &amp;nbsp; [RFC1034][RFC2181] naming a host [RFC1123]. &amp;nbsp;That is, a 
&lt;br&gt;value of this
&lt;br&gt;rfc4519.txt: &amp;nbsp; [RFC1034] &amp;nbsp;Mockapetris, P., &amp;quot;Domain names - concepts and 
&lt;br&gt;facilities&amp;quot;,
&lt;br&gt;rfc4519.txt: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;STD 13, RFC 1034, November 1987.
&lt;br&gt;rfc4524.txt: &amp;nbsp; The 'associatedDomain' attribute specifies DNS 
&lt;br&gt;[RFC1034][RFC2181]
&lt;br&gt;rfc4524.txt: &amp;nbsp; organizational DIT associated with a DNS domain 
&lt;br&gt;[RFC1034][RFC2181].
&lt;br&gt;rfc4524.txt: &amp;nbsp; [RFC1034] &amp;nbsp; &amp;nbsp; Mockapetris, P., &amp;quot;Domain names - concepts and
&lt;br&gt;rfc4524.txt: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; facilities&amp;quot;, STD 13, RFC 1034, November 1987.
&lt;br&gt;&lt;br&gt;Best,
&lt;br&gt;&lt;br&gt;--Tonni
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Tony Earnshaw
&lt;br&gt;Email: tonni at hetnet dot nl
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15527821.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15525595</id>
	<title>Re: Need help determining cause of login problem</title>
	<published>2008-02-16T17:06:25Z</published>
	<updated>2008-02-16T17:06:25Z</updated>
	<author>
		<name>Howard Chu</name>
	</author>
	<content type="html">Tony Earnshaw wrote:
&lt;br&gt;&amp;gt; Jürgen Starek skrev, on 16-02-2008 18:04:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Is there a list available anywhere that gives possible reasons for error
&lt;br&gt;&amp;gt;&amp;gt; messages?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Apparently not, as far as OpenLDAP is concerned.
&lt;br&gt;&lt;br&gt;Not quite. LDAP error codes are already documented in RFC4511.
&lt;br&gt;&lt;br&gt;&amp;gt; This was &amp;quot;up&amp;quot; as late
&lt;br&gt;&amp;gt; as today in one of the 2/4 official OpenLDAP lists, with Pier-Angelo
&lt;br&gt;&amp;gt; Masarati asking Gavin Henry if he couldn't do anything about it.
&lt;br&gt;&lt;br&gt;The question Pierangelo and Gavin were addressing was whether the specific 
&lt;br&gt;format of OpenLDAP log messages was explicitly documented anywhere. The answer 
&lt;br&gt;to that is no, and we occasionally reformat the log messages to make them more 
&lt;br&gt;uniform and perform other cleanups over time.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; As far as I'm concerned, recognizing these error numbers at OL log level
&lt;br&gt;&amp;gt; Stats level has been an ever-increasingly important factor as LDAP
&lt;br&gt;&amp;gt; continues to mean more and more to my sites. No where to go to get
&lt;br&gt;&amp;gt; values, just recognize.
&lt;br&gt;&lt;br&gt;That is far overstating the situation. All of the relevant codes are already 
&lt;br&gt;documented in the LDAP RFCs.
&lt;br&gt;&lt;br&gt;&amp;gt; The importance has been highlighted by Red Hat
&lt;br&gt;&amp;gt; itself, who permits itself to charge US$ 15.000 per annum support for
&lt;br&gt;&amp;gt; each OL or RHDS master server installation and about the half for each
&lt;br&gt;&amp;gt; slave. If I charged the half for both, I'd long have had more money than
&lt;br&gt;&amp;gt; I do have.
&lt;br&gt;&lt;br&gt;Red Hat's practices are far from exemplary.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;&amp;gt; Without your mail, I would not have guessed that sending pam_ldap
&lt;br&gt;&amp;gt;&amp;gt; to look in a non-existing search base might lead to &amp;quot;No such object&amp;quot;, &amp;quot;No
&lt;br&gt;&amp;gt;&amp;gt; such search base&amp;quot; might have been more appropriate as the object /is/ in the
&lt;br&gt;&amp;gt;&amp;gt; directory, albeit with a different dn...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; That's what error 32 is about. Invariably it comes from people trying to
&lt;br&gt;&amp;gt; do things to a database/directory suffix that hasn't itself yet been
&lt;br&gt;&amp;gt; initiated.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Again Googling, here's how Michael Hammer does it:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tugll.tugraz.at/88684/weblog/3682.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tugll.tugraz.at/88684/weblog/3682.html&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; Well, I'm truly grateful for each tutorial or howto anyone puts on the web.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Watch out. People stuff the word HOWTO into everything, most often don't
&lt;br&gt;&amp;gt; date what they write and, most importantly, most of what they write is
&lt;br&gt;&amp;gt; trash anyway. I wouldn't have passed Michael Hammer's writeup to you if
&lt;br&gt;&amp;gt; I hadn't vetted it myself first and found it kosher.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I
&lt;br&gt;&amp;gt;&amp;gt; just wish they'd explain the meaning of options used and some alternatives...
&lt;br&gt;&amp;gt;&amp;gt; (Yes, I'll go and improve the howto on the Debian wiki once this is done.
&lt;br&gt;&amp;gt;&amp;gt; Promise.)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; *NEVER, NEVER* attempt to write any &amp;quot;HOWTO&amp;quot; about anything. A good
&lt;br&gt;&amp;gt; example is sexual seduction. *DO NOT*. Simply explain what worked for
&lt;br&gt;&amp;gt; you, and *ALWAYS* write the date and all software versions. *ALWAYS* the
&lt;br&gt;&amp;gt; best source of information is the software vendor's documentation and if
&lt;br&gt;&amp;gt; this doesn't suffice, your quarrel is with the vendor himself, not the
&lt;br&gt;&amp;gt; end user.
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;&amp;nbsp; &amp;nbsp;-- Howard Chu
&lt;br&gt;&amp;nbsp; &amp;nbsp;Chief Architect, Symas Corp. &amp;nbsp;&lt;a href=&quot;http://www.symas.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.symas.com&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Director, Highland Sun &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://highlandsun.com/hyc/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://highlandsun.com/hyc/&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Chief Architect, OpenLDAP &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openldap.org/project/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openldap.org/project/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15525595.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15524570</id>
	<title>Re: Need help determining cause of login problem</title>
	<published>2008-02-16T14:19:59Z</published>
	<updated>2008-02-16T14:19:59Z</updated>
	<author>
		<name>Tony Earnshaw-4</name>
	</author>
	<content type="html">Jürgen Starek skrev, on 16-02-2008 18:04:
&lt;br&gt;&lt;br&gt;&amp;gt; Is there a list available anywhere that gives possible reasons for error 
&lt;br&gt;&amp;gt; messages?
&lt;br&gt;&lt;br&gt;Apparently not, as far as OpenLDAP is concerned. This was &amp;quot;up&amp;quot; as late 
&lt;br&gt;as today in one of the 2/4 official OpenLDAP lists, with Pier-Angelo 
&lt;br&gt;Masarati asking Gavin Henry if he couldn't do anything about it.
&lt;br&gt;&lt;br&gt;As far as I'm concerned, recognizing these error numbers at OL log level 
&lt;br&gt;Stats level has been an ever-increasingly important factor as LDAP 
&lt;br&gt;continues to mean more and more to my sites. No where to go to get 
&lt;br&gt;values, just recognize. The importance has been highlighted by Red Hat 
&lt;br&gt;itself, who permits itself to charge US$ 15.000 per annum support for 
&lt;br&gt;each OL or RHDS master server installation and about the half for each 
&lt;br&gt;slave. If I charged the half for both, I'd long have had more money than 
&lt;br&gt;I do have.
&lt;br&gt;&lt;br&gt;&amp;gt; Without your mail, I would not have guessed that sending pam_ldap 
&lt;br&gt;&amp;gt; to look in a non-existing search base might lead to &amp;quot;No such object&amp;quot;, &amp;quot;No 
&lt;br&gt;&amp;gt; such search base&amp;quot; might have been more appropriate as the object /is/ in the 
&lt;br&gt;&amp;gt; directory, albeit with a different dn...
&lt;br&gt;&lt;br&gt;That's what error 32 is about. Invariably it comes from people trying to 
&lt;br&gt;do things to a database/directory suffix that hasn't itself yet been 
&lt;br&gt;initiated.
&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt; Again Googling, here's how Michael Hammer does it:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tugll.tugraz.at/88684/weblog/3682.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tugll.tugraz.at/88684/weblog/3682.html&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Well, I'm truly grateful for each tutorial or howto anyone puts on the web.
&lt;br&gt;&lt;br&gt;Watch out. People stuff the word HOWTO into everything, most often don't 
&lt;br&gt;date what they write and, most importantly, most of what they write is 
&lt;br&gt;trash anyway. I wouldn't have passed Michael Hammer's writeup to you if 
&lt;br&gt;I hadn't vetted it myself first and found it kosher.
&lt;br&gt;&lt;br&gt;&amp;gt; I 
&lt;br&gt;&amp;gt; just wish they'd explain the meaning of options used and some alternatives... 
&lt;br&gt;&amp;gt; (Yes, I'll go and improve the howto on the Debian wiki once this is done. 
&lt;br&gt;&amp;gt; Promise.)
&lt;br&gt;&lt;br&gt;*NEVER, NEVER* attempt to write any &amp;quot;HOWTO&amp;quot; about anything. A good 
&lt;br&gt;example is sexual seduction. *DO NOT*. Simply explain what worked for 
&lt;br&gt;you, and *ALWAYS* write the date and all software versions. *ALWAYS* the 
&lt;br&gt;best source of information is the software vendor's documentation and if 
&lt;br&gt;this doesn't suffice, your quarrel is with the vendor himself, not the 
&lt;br&gt;end user.
&lt;br&gt;&lt;br&gt;Best,
&lt;br&gt;&lt;br&gt;--Tonni
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Tony Earnshaw
&lt;br&gt;Email: tonni at hetnet dot nl
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15524570.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15521650</id>
	<title>Re: Need help determining cause of login problem</title>
	<published>2008-02-16T09:04:51Z</published>
	<updated>2008-02-16T09:04:51Z</updated>
	<author>
		<name>Jürgen Starek</name>
	</author>
	<content type="html">Am Samstag, 16. Februar 2008 14:17:37 schrieb Tony Earnshaw:
&lt;br&gt;&lt;br&gt;&amp;gt; This in your log: &amp;quot;ldap_search_s No such object&amp;quot; (aka error 32) means it
&lt;br&gt;&amp;gt; can't find the directory suffix c.q. search base, which should be
&lt;br&gt;&amp;gt; configured (with a lot more things) in said pam_ldap.conf.
&lt;br&gt;&lt;br&gt;Thanks for the hint! That pointed me to a typing error in /etc/pam_ldap.conf 
&lt;br&gt;which caused pam_ldap to check a wrong search base...
&lt;br&gt;&lt;br&gt;Is there a list available anywhere that gives possible reasons for error 
&lt;br&gt;messages? Without your mail, I would not have guessed that sending pam_ldap 
&lt;br&gt;to look in a non-existing search base might lead to &amp;quot;No such object&amp;quot;, &amp;quot;No 
&lt;br&gt;such search base&amp;quot; might have been more appropriate as the object /is/ in the 
&lt;br&gt;directory, albeit with a different dn...
&lt;br&gt;&lt;br&gt;&amp;gt; Again Googling, here's how Michael Hammer does it:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://tugll.tugraz.at/88684/weblog/3682.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tugll.tugraz.at/88684/weblog/3682.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Well, I'm truly grateful for each tutorial or howto anyone puts on the web. I 
&lt;br&gt;just wish they'd explain the meaning of options used and some alternatives... 
&lt;br&gt;(Yes, I'll go and improve the howto on the Debian wiki once this is done. 
&lt;br&gt;Promise.)
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; Jürgen
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://www.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (196 bytes) &lt;a href=&quot;http://www.nabble.com/attachment/15521650/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15521650.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15519359</id>
	<title>Re: Need help determining cause of login problem</title>
	<published>2008-02-16T05:17:37Z</published>
	<updated>2008-02-16T05:17:37Z</updated>
	<author>
		<name>Tony Earnshaw-4</name>
	</author>
	<content type="html">Jürgen Starek skrev, on 16-02-2008 10:25:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I am having trouble with authenticating users listed in an LDAP directory.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On my network, I set up an LDAP server and a client that tries to
&lt;br&gt;&amp;gt; authenticate using the server. Both machines run Debian Etch.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Client and Server setup are done according to tutorials on the net, and
&lt;br&gt;&amp;gt; where they contradicted themselves, O'Reilly's &amp;quot;LDAP System
&lt;br&gt;&amp;gt; Administration&amp;quot;.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I have populated the database with a &amp;quot;users&amp;quot; group and a sample
&lt;br&gt;&amp;gt; posixAccount. The server works fine: I can connect to it from the client
&lt;br&gt;&amp;gt; using GQ and a simple bind for the rootdn. Also, calling ldapsearch -x 
&lt;br&gt;&amp;gt; on the
&lt;br&gt;&amp;gt; client gives me the complete list of entries in the server's database.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; A &amp;quot;getent passwd&amp;quot; on the client shows my sample account on the LDAP 
&lt;br&gt;&amp;gt; directory
&lt;br&gt;&amp;gt; as if it were in the local passwd file, just as it's supposed to do.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; However, I can't log in. My nsswitch.conf uses LDAP as a password data
&lt;br&gt;&amp;gt; source, and I see network traffic at each login attempt. Passwords are
&lt;br&gt;&amp;gt; stored as an MD5 hash in the LDAP database, but trying CRYPT or PLAIN 
&lt;br&gt;&amp;gt; did not change anything. As mentioned above, binding to the server using
&lt;br&gt;&amp;gt; rootdn works fine. Only binding as a user does not seem to work...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Here's a log extract from /var/log/auth.log:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; testbox login[3850]: pam_ldap: ldap_search_s No such object
&lt;br&gt;&amp;gt; testbox login[3850]: pam_ldap: ldap_search_s No such object
&lt;br&gt;&amp;gt; testbox login[3850]: (pam_unix) authentication failure; logname= uid=0 
&lt;br&gt;&amp;gt; euid=0
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;tty=pts/0 ruser= rhost= &amp;nbsp;user=testuser
&lt;br&gt;&amp;gt; testbox login[3850]: FAILED LOGIN (1) auf &amp;quot;pts/0&amp;quot; FOR `testuser',
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Authentication failure
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Can anyone help me diagnose this problem further? Any help would be
&lt;br&gt;&amp;gt; appreciated.
&lt;/div&gt;&lt;br&gt;&amp;nbsp;From what you describe above it'd seem you've got most simple bind 
&lt;br&gt;stuff working ok for OpenLDAP, as well as name service switch stuff for 
&lt;br&gt;nss_ldap. I'm a Red Hat person, not Debian; be that as it may, you need 
&lt;br&gt;a configuration file for pam_ldap. Googling tells me that for Debian 
&lt;br&gt;this should be /etc/pam_ldap.conf.
&lt;br&gt;&lt;br&gt;This in your log: &amp;quot;ldap_search_s No such object&amp;quot; (aka error 32) means it 
&lt;br&gt;can't find the directory suffix c.q. search base, which should be 
&lt;br&gt;configured (with a lot more things) in said pam_ldap.conf.
&lt;br&gt;&lt;br&gt;Again Googling, here's how Michael Hammer does it:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://tugll.tugraz.at/88684/weblog/3682.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tugll.tugraz.at/88684/weblog/3682.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Best,
&lt;br&gt;&lt;br&gt;--Tonni
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Tony Earnshaw
&lt;br&gt;Email: tonni at hetnet dot nl
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15519359.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15517106</id>
	<title>Need help determining cause of login problem</title>
	<published>2008-02-16T01:25:12Z</published>
	<updated>2008-02-16T01:25:12Z</updated>
	<author>
		<name>Jürgen Starek</name>
	</author>
	<content type="html">Hello everyone,
&lt;br&gt;&lt;br&gt;I am having trouble with authenticating users listed in an LDAP directory.
&lt;br&gt;&lt;br&gt;On my network, I set up an LDAP server and a client that tries to
&lt;br&gt;authenticate using the server. Both machines run Debian Etch.
&lt;br&gt;&lt;br&gt;Client and Server setup are done according to tutorials on the net, and
&lt;br&gt;where they contradicted themselves, O'Reilly's &amp;quot;LDAP System
&lt;br&gt;Administration&amp;quot;.
&lt;br&gt;&lt;br&gt;I have populated the database with a &amp;quot;users&amp;quot; group and a sample
&lt;br&gt;posixAccount. The server works fine: I can connect to it from the client
&lt;br&gt;using GQ and a simple bind for the rootdn. Also, calling ldapsearch -x 
&lt;br&gt;on the
&lt;br&gt;client gives me the complete list of entries in the server's database.
&lt;br&gt;&lt;br&gt;A &amp;quot;getent passwd&amp;quot; on the client shows my sample account on the LDAP 
&lt;br&gt;directory
&lt;br&gt;as if it were in the local passwd file, just as it's supposed to do.
&lt;br&gt;&lt;br&gt;However, I can't log in. My nsswitch.conf uses LDAP as a password data
&lt;br&gt;source, and I see network traffic at each login attempt. Passwords are
&lt;br&gt;stored as an MD5 hash in the LDAP database, but trying CRYPT or PLAIN 
&lt;br&gt;did not change anything. As mentioned above, binding to the server using
&lt;br&gt;rootdn works fine. Only binding as a user does not seem to work...
&lt;br&gt;&lt;br&gt;Here's a log extract from /var/log/auth.log:
&lt;br&gt;&lt;br&gt;testbox login[3850]: pam_ldap: ldap_search_s No such object
&lt;br&gt;testbox login[3850]: pam_ldap: ldap_search_s No such object
&lt;br&gt;testbox login[3850]: (pam_unix) authentication failure; logname= uid=0 
&lt;br&gt;euid=0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; tty=pts/0 ruser= rhost= &amp;nbsp;user=testuser
&lt;br&gt;testbox login[3850]: FAILED LOGIN (1) auf &amp;quot;pts/0&amp;quot; FOR `testuser',
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Authentication failure
&lt;br&gt;&lt;br&gt;&lt;br&gt;Can anyone help me diagnose this problem further? Any help would be
&lt;br&gt;appreciated.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Jürgen
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://www.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (194 bytes) &lt;a href=&quot;http://www.nabble.com/attachment/15517106/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Need-help-determining-cause-of-login-problem-tp15517106p15517106.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15363075</id>
	<title>Re: local authentication problems (tls, nscd, nss_ldap)</title>
	<published>2008-02-08T10:25:56Z</published>
	<updated>2008-02-08T10:25:56Z</updated>
	<author>
		<name>Rafael A Barrero</name>
	</author>
	<content type="html">Hi Tony;
&lt;br&gt;&lt;br&gt;Thanks for the feedback. We use a proxy user because user password &amp;nbsp;
&lt;br&gt;changes are done only through a web portal. I'm not entirely certain &amp;nbsp;
&lt;br&gt;that the TLS negotiation problem can be attributed only to networking &amp;nbsp;
&lt;br&gt;problems. As I mentioned, we have two servers and the consumers use &amp;nbsp;
&lt;br&gt;the closest server to them. In other words, the consumers are always &amp;nbsp;
&lt;br&gt;on the same subnet as their &amp;quot;primary&amp;quot; OpenLDAP server.
&lt;br&gt;&lt;br&gt;I have read a lot of people having problems using nscd, yet as I &amp;nbsp;
&lt;br&gt;mentioned, I can get TLS to work without it! How have you been bitten &amp;nbsp;
&lt;br&gt;badly?
&lt;br&gt;&lt;br&gt;I will try again on RHEL5 to see if we can enable TLS successfully.
&lt;br&gt;&lt;br&gt;Can someone explain the workflow of communications for pam_ldap, &amp;nbsp;
&lt;br&gt;nss_ldap and how they interface with the other system libs/daemons?
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;Rafael
&lt;br&gt;&lt;br&gt;&lt;br&gt;On Feb 6, 2008, at 12:04 AM, Tony Earnshaw wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Rafael A Barrero skrev, on 06-02-2008 04:53:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; In my environment, we have about 20 servers (rhel4+rhel5) &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; connecting as clients for local authentication to an OpenLDAP &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; server (openldap2.3-2.3.39-3.rhel4, Buchan's RPMs) with slurpd &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; replicating to a slave server. Half of the servers primarily use &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; the master, while the other half primarily use the slave.
&lt;br&gt;&amp;gt;&amp;gt; The OpenLDAP implemenation is working well, however we're having a &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; few issues with the nss_ldap client:
&lt;br&gt;&amp;gt;&amp;gt; 1. TLS negotiation errors - doesn't seem to occur for all rhel4 &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; clients, or all the time... Doesn't work on RHEL5. Has anyone seen &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; this? Why does it occur?
&lt;br&gt;&amp;gt;&amp;gt; 2. If nscd is not running and TLS is configured, authentication &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; doesn't work (su - user), but lookups do work (id user). nss_ldap &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; complains about binding to the ldap server.
&lt;br&gt;&amp;gt;&amp;gt; 3. If nscd is not running and TLS is *not* configured, everything &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; works (including failover to slave).
&lt;br&gt;&amp;gt;&amp;gt; I should say that in our /etc/ldap.conf file, we have a specific &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; 'binddn' user that has read-only privileges to the ldap database &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; for querying (works)...
&lt;br&gt;&amp;gt;&amp;gt; I'm wondering why TLS doesn't work on RHEL5, and why TLS doesn't &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; work when nscd is not running. Also, any explanations or references &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; on how nss_ldap and nscd work would be great.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi, the following is not going to help you solve your problem, but &amp;nbsp;
&lt;br&gt;&amp;gt; it will make you take a fresh look.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We swapped out our 4 RHAS4 servers with RHEL5 last summer. Delta &amp;nbsp;
&lt;br&gt;&amp;gt; syncrepl master is an i386 machine, the 3 consumer slaves are x86_64 &amp;nbsp;
&lt;br&gt;&amp;gt; all running Buchan's stuff but built on the appropriate platform &amp;nbsp;
&lt;br&gt;&amp;gt; from a single srpm. Master is running OL 2.3.33, consumers 2.3.38. &amp;nbsp;
&lt;br&gt;&amp;gt; One of the consumers is a Samba PDC that insists on Red Hat's &amp;nbsp;
&lt;br&gt;&amp;gt; clients but all the others are running Buchan's clients.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In connection with the introduction of a password policy regime &amp;nbsp;
&lt;br&gt;&amp;gt; shortly before Christmas we cut out the use of a proxy user for &amp;nbsp;
&lt;br&gt;&amp;gt; ldap.conf because users have to be able to change their own &amp;nbsp;
&lt;br&gt;&amp;gt; passwords (write access) using pam_exop. Users on all 4 consumers &amp;nbsp;
&lt;br&gt;&amp;gt; must be able to change passwords and use utilities on all consumers.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We are using the standard Red Hat pam_ldap/nss_ldap libraries. pam &amp;nbsp;
&lt;br&gt;&amp;gt; is going directly to the master from all of them for password &amp;nbsp;
&lt;br&gt;&amp;gt; modification and authentication and I'm using TLS (starttls) for all &amp;nbsp;
&lt;br&gt;&amp;gt; of this. Local stuff that uses OL's own libraries goes directly to &amp;nbsp;
&lt;br&gt;&amp;gt; the machine's slave LDAP.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I've been bitten badly in the past by nscd and would never touch it &amp;nbsp;
&lt;br&gt;&amp;gt; again with a bargepole. Besides which it would be impossible in our &amp;nbsp;
&lt;br&gt;&amp;gt; ppolicy situation with people constantly changing passwords.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I could only guess that you could have a network problem; in our &amp;nbsp;
&lt;br&gt;&amp;gt; case the three slaves are on one segment, the master on another over &amp;nbsp;
&lt;br&gt;&amp;gt; a 2Gb switch and firewall (master is in the DMZ).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sorry, but there it is. pam starttls works as designed with RHEL5 at &amp;nbsp;
&lt;br&gt;&amp;gt; our site.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Best,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --Tonni
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; Tony Earnshaw
&lt;br&gt;&amp;gt; Email: tonni at hetnet dot nl
&lt;/div&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/local-authentication-problems-%28tls%2C-nscd%2C-nss_ldap%29-tp15305568p15363075.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-15320566</id>
	<title>Re: Access denied for this service</title>
	<published>2008-02-06T10:21:21Z</published>
	<updated>2008-02-06T10:21:21Z</updated>
	<author>
		<name>Matthew Hardin</name>
	</author>
	<content type="html">Tony Earnshaw wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; bdptcob skrev, on 05-02-2008 22:11:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I get this message when logging in. It still drops me to a prompt but 
&lt;br&gt;&amp;gt;&amp;gt; I want
&lt;br&gt;&amp;gt;&amp;gt;