|
From: Bruce S. <br...@ar...> - 2006-06-13 17:16:18
|
Serge, someone told me that 'groupadd' wasn't working (PAM problem), and found the cause and solution of the problem here: http://linuxfromscratch.org/pipermail/blfs-support/2004-December/052929.html So I changed the Linux-PAM install script to copy /etc/pam.d/useradd to /etc/pamd.d/groupadd as quick fix to get 1.2.10 released soon. I wasn't sure if I should add groupadd to $SRCDIR/pam.d.tar.bz2 or not. Feel free to redo my "fix" for 1.2.11 if there is a better way to solve the groupadd problem. :-) - BS |
|
From: John B. <jbr...@gm...> - 2006-06-13 23:33:01
|
On 6/13/06, Bruce Smith <br...@ar...> wrote: > > Serge, someone told me that 'groupadd' wasn't working (PAM problem), and > found the cause and solution of the problem here: > > > http://linuxfromscratch.org/pipermail/blfs-support/2004-December/052929.html > > So I changed the Linux-PAM install script to copy /etc/pam.d/useradd > to /etc/pamd.d/groupadd as quick fix to get 1.2.10 released soon. > > I wasn't sure if I should add groupadd to $SRCDIR/pam.d.tar.bz2 or not. > > Feel free to redo my "fix" for 1.2.11 if there is a better way to solve > the groupadd problem. :-) > I also get the same error when I try to delete a user or a group: root@squid:/etc # useradd test root@squid:/etc # userdel test userdel: PAM authentication failed root@squid:/etc # root@squid:/etc # groupadd test1 root@squid:/etc # groupdel test1 groupdel: PAM authentication failed root@squid:/etc # -- John Bridleman |
|
From: Bruce S. <bw...@ar...> - 2006-06-14 00:05:17
|
> I also get the same error when I try to delete a user or a group: > > root@squid :/etc # useradd test > root@squid:/etc # userdel test > userdel: PAM authentication failed > root@squid:/etc # > > root@squid:/etc # groupadd test1 > root@squid:/etc # groupdel test1 > groupdel: PAM authentication failed > root@squid:/etc # Does it fix the problem if you copy /etc/pam.d/groupadd to groupdel? - BS |
|
From: John B. <jbr...@gm...> - 2006-06-14 00:13:27
|
On 6/13/06, Bruce Smith <bw...@ar...> wrote: > > > I also get the same error when I try to delete a user or a group: > > > > root@squid :/etc # useradd test > > root@squid:/etc # userdel test > > userdel: PAM authentication failed > > root@squid:/etc # > > > > root@squid:/etc # groupadd test1 > > root@squid:/etc # groupdel test1 > > groupdel: PAM authentication failed > > root@squid:/etc # > > Does it fix the problem if you copy /etc/pam.d/groupadd to groupdel? > I tried that before my last message and it didn't work. root@squid:/etc # groupadd test1 root@squid:/etc # groupdel test1 groupdel: PAM authentication failed root@squid:/etc # But after your message I tried it again and it works! root@squid:/etc # groupadd test2 root@squid:/etc # groupdel test2 root@squid:/etc # However, doing the same with userdel doesn't seem to: root@squid:/etc # useradd test3 root@squid:/etc # userdel test3 userdel: error removing group entry userdel: error removing shadow group entry root@squid:/etc # -- John Bridleman |
|
From: Heiko Z. <he...@zu...> - 2006-06-14 01:03:21
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, June 13, 2006 19:13, John Bridleman wrote: > On 6/13/06, Bruce Smith <bw...@ar...> wrote: > >> >>> I also get the same error when I try to delete a user or a group: >>> >>> >>> root@squid :/etc # useradd test root@squid:/etc # userdel test >>> userdel: PAM authentication failed >>> root@squid:/etc # >>> >>> >>> root@squid:/etc # groupadd test1 >>> root@squid:/etc # groupdel test1 >>> groupdel: PAM authentication failed >>> root@squid:/etc # >>> >> >> Does it fix the problem if you copy /etc/pam.d/groupadd to groupdel? >> >> > > I tried that before my last message and it didn't work. > > > root@squid:/etc # groupadd test1 > root@squid:/etc # groupdel test1 > groupdel: PAM authentication failed > root@squid:/etc # > > > But after your message I tried it again and it works! > root@squid:/etc # groupadd test2 > root@squid:/etc # groupdel test2 > root@squid:/etc # > > > However, doing the same with userdel doesn't seem to: > root@squid:/etc # useradd test3 > root@squid:/etc # userdel test3 > userdel: error removing group entry > userdel: error removing shadow group entry > root@squid:/etc # > -- > John Bridleman It seems we should look at this problem before we release 1.2.10. Guess it's time to look how other distros handle this one, I don't think it makes sense to list every single program here... - -- Regards Heiko Zuerker http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iEYEARECAAYFAkSPYEgACgkQUcytMSbs+YX0UgCeKhhfpH6Wsp09FqTCtOKK25dT d1sAoJG1Ct0+eDvTBCIGEKUxXKTB6K3Z =suq2 -----END PGP SIGNATURE----- |
|
From: Bruce S. <bw...@ar...> - 2006-06-14 01:28:51
|
Heiko Zuerker wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
>
> On Tue, June 13, 2006 19:13, John Bridleman wrote:
>
>> On 6/13/06, Bruce Smith <bw...@ar...> wrote:
>>
>>
>>>> I also get the same error when I try to delete a user or a group:
>>>>
>>>>
>>>> root@squid :/etc # useradd test root@squid:/etc # userdel test
>>>> userdel: PAM authentication failed
>>>> root@squid:/etc #
>>>>
>>>>
>>>> root@squid:/etc # groupadd test1
>>>> root@squid:/etc # groupdel test1
>>>> groupdel: PAM authentication failed
>>>> root@squid:/etc #
>>>>
>>>>
>>> Does it fix the problem if you copy /etc/pam.d/groupadd to groupdel?
>>>
>>>
>>>
>> I tried that before my last message and it didn't work.
>>
>>
>> root@squid:/etc # groupadd test1
>> root@squid:/etc # groupdel test1
>> groupdel: PAM authentication failed
>> root@squid:/etc #
>>
>>
>> But after your message I tried it again and it works!
>> root@squid:/etc # groupadd test2
>> root@squid:/etc # groupdel test2
>> root@squid:/etc #
>>
>>
>> However, doing the same with userdel doesn't seem to:
>> root@squid:/etc # useradd test3
>> root@squid:/etc # userdel test3
>> userdel: error removing group entry
>> userdel: error removing shadow group entry
>> root@squid:/etc #
>> --
>> John Bridleman
>>
>
> It seems we should look at this problem before we release 1.2.10.
> Guess it's time to look how other distros handle this one, I don't think
> it makes sense to list every single program here...
>
SuSE 10.1 only has useradd in /etc/pam.d/. No entries for userdel and
group{add,del}.
- BS
|
|
From: Bruce S. <bw...@ar...> - 2006-06-14 01:31:12
|
>>>> I also get the same error when I try to delete a user or a group: >>>> >>>> >>>> root@squid :/etc # useradd test root@squid:/etc # userdel test >>>> userdel: PAM authentication failed >>>> root@squid:/etc # >>>> >>>> >>>> root@squid:/etc # groupadd test1 >>>> root@squid:/etc # groupdel test1 >>>> groupdel: PAM authentication failed >>>> root@squid:/etc # >>>> >>>> >>> Does it fix the problem if you copy /etc/pam.d/groupadd to groupdel? >>> >>> >>> >> I tried that before my last message and it didn't work. >> >> >> root@squid:/etc # groupadd test1 >> root@squid:/etc # groupdel test1 >> groupdel: PAM authentication failed >> root@squid:/etc # >> >> >> But after your message I tried it again and it works! >> root@squid:/etc # groupadd test2 >> root@squid:/etc # groupdel test2 >> root@squid:/etc # >> >> >> However, doing the same with userdel doesn't seem to: >> root@squid:/etc # useradd test3 >> root@squid:/etc # userdel test3 >> userdel: error removing group entry >> userdel: error removing shadow group entry >> root@squid:/etc # >> -- >> John Bridleman >> > > It seems we should look at this problem before we release 1.2.10. > Guess it's time to look how other distros handle this one, I don't think > it makes sense to list every single program here... > Let's not forget about 'usermod' & 'groupmod'. Can you try those John? - BS |
|
From: John B. <jbr...@gm...> - 2006-06-14 01:51:28
|
On 6/13/06, Bruce Smith <bw...@ar...> wrote: > > Let's not forget about 'usermod' & 'groupmod'. Can you try those John? > Nope. root@squid:~ # useradd bruce root@squid:~ # usermod -L bruce usermod: PAM authentication failed root@squid:~ # groupadd devil root@squid:~ # groupmod -g 5000 devil groupmod: PAM authentication failed root@squid:~ # -- John Bridleman |
|
From: Serge L. <fi...@in...> - 2006-06-14 03:23:17
|
Bruce, Tuesday, June 13, 2006, 6:31:04 PM, you wrote: >>>>> I also get the same error when I try to delete a user or a group: >>>>> >>>>> >>>>> root@squid :/etc # useradd test root@squid:/etc # userdel test >>>>> userdel: PAM authentication failed >>>>> root@squid:/etc # >>>>> >>>>> >>>>> root@squid:/etc # groupadd test1 >>>>> root@squid:/etc # groupdel test1 >>>>> groupdel: PAM authentication failed >>>>> root@squid:/etc # >>>>> >>>>> >>>> Does it fix the problem if you copy /etc/pam.d/groupadd to groupdel? >>>> >>>> >>>> >>> I tried that before my last message and it didn't work. >>> >>> >>> root@squid:/etc # groupadd test1 >>> root@squid:/etc # groupdel test1 >>> groupdel: PAM authentication failed >>> root@squid:/etc # >>> >>> >>> But after your message I tried it again and it works! >>> root@squid:/etc # groupadd test2 >>> root@squid:/etc # groupdel test2 >>> root@squid:/etc # >>> >>> >>> However, doing the same with userdel doesn't seem to: >>> root@squid:/etc # useradd test3 >>> root@squid:/etc # userdel test3 >>> userdel: error removing group entry >>> userdel: error removing shadow group entry >>> root@squid:/etc # >>> -- >>> John Bridleman >>> >> >> It seems we should look at this problem before we release 1.2.10. >> Guess it's time to look how other distros handle this one, I don't think >> it makes sense to list every single program here... >> > Let's not forget about 'usermod' & 'groupmod'. Can you try those John? As far as I know, if pam config for usermod (or groupmod) is absent, the "other" config should be used. Otherwise we have to write configs for _all_ binaries from the system... I guess, there are 2 possible causes of problem: 1) the package ( which contain userdel, useradd etc) is wrongly compiled 2) the pam config "other" is wrong. I'll see tonight. But I can't start compilation on my note due to the note age, so I'll see on the latest beta - devil-linux-1.2.10-2006-06-08-i686-SMP.tar.bz2 . I'm sorry, but I'm now in business trip in Sunnyvale, CA and have no access to build environment & build boxes. -- Best regards, Serge mailto:fi...@in... |
|
From: Dr. A. B. <be...@ec...> - 2006-06-14 10:01:11
|
Yes, the problem is /etc/pam.d/other file. In Red Hat Enterprise Linux ES release 3: auth required /lib/security/$ISA/pam_deny.so account required /lib/security/$ISA/pam_deny.so password required /lib/security/$ISA/pam_deny.so session required /lib/security/$ISA/pam_deny.so In my internal server, I use: auth required pam_unix.so account required pam_unix.so password required pam_unix.so session required pam_unix.so Alberto +--------------------------+ | Dott. Alberto Benati | | System Administrator | | Faculty of Economics | | University of Ferrara | | be...@ec... | | Tel: +39 0532 293006 | +--------------------------+ ---------- Original Message ----------- From: Serge Leschinsky <fi...@in...> To: Bruce Smith <dev...@li...> Sent: Tue, 13 Jun 2006 19:32:22 -0700 Subject: Re: [Devil-linux-develop] groupadd PAM problem. > > > Let's not forget about 'usermod' & 'groupmod'. Can you try those John? > > As far as I know, if pam config for usermod (or groupmod) is absent, > the "other" config should be used. Otherwise we have to write > configs for _all_ binaries from the system... > > I guess, there are 2 possible causes of problem: > 1) the package ( which contain userdel, useradd etc) is wrongly compiled > 2) the pam config "other" is wrong. > > I'll see tonight. But I can't start compilation on my note due to the > note age, so I'll see on the latest beta - > devil-linux-1.2.10-2006-06-08-i686-SMP.tar.bz2 . I'm sorry, but I'm > now in business trip in Sunnyvale, CA and have no access to build > environment & build boxes. > ------- End of Original Message ------- |
|
From: Serge L. <fi...@in...> - 2006-06-14 03:44:53
|
> I guess, there are 2 possible causes of problem:
> 1) the package ( which contain userdel, useradd etc) is wrongly compiled
> 2) the pam config "other" is wrong.
> I'll see tonight. But I can't start compilation on my note due to the
> note age
note == notebook
And as regards the question:
========================================================
for i in usermod userdel groupadd groudel groupmod do
cp -a /etc/pam.d/useradd %i
done
save-config
========================================================
This one should resolve the problem. John, could you please check it?
--
Best regards,
Serge mailto:fi...@in...
|
|
From: Serge L. <fi...@in...> - 2006-06-14 03:47:50
|
Oops.. I am in a great hurry ... > ======================================================== > for i in usermod userdel groupadd groudel groupmod > do > cp -a /etc/pam.d/useradd /etc/pam.d/$i > done > save-config > ======================================================== -- Best regards, Serge mailto:fi...@in... |
|
From: Serge L. <fi...@in...> - 2006-06-14 04:00:06
|
Bruce, Tuesday, June 13, 2006, 10:15:51 AM, you wrote: > Serge, someone told me that 'groupadd' wasn't working (PAM problem), and > found the cause and solution of the problem here: > http://linuxfromscratch.org/pipermail/blfs-support/2004-December/052929.html > So I changed the Linux-PAM install script to copy /etc/pam.d/useradd > to /etc/pamd.d/groupadd as quick fix to get 1.2.10 released soon. > I wasn't sure if I should add groupadd to $SRCDIR/pam.d.tar.bz2 or not. You are absolutely right. I've looked through /etc/pam.d/other. It's very secure .... Needless to say that groupdel, usermod etc weren't able to work this such config. Sorry for inconvenience... -- Best regards, Serge mailto:fi...@in... |
|
From: Dr. A. B. <be...@ec...> - 2006-06-14 10:01:28
|
Yes, the problem is /etc/pam.d/other file. In Red Hat Enterprise Linux ES release 3: auth required /lib/security/$ISA/pam_deny.so account required /lib/security/$ISA/pam_deny.so password required /lib/security/$ISA/pam_deny.so session required /lib/security/$ISA/pam_deny.so In my internal server, I use: auth required pam_unix.so account required pam_unix.so password required pam_unix.so session required pam_unix.so Alberto +--------------------------+ | Dott. Alberto Benati | | System Administrator | | Faculty of Economics | | University of Ferrara | | be...@ec... | | Tel: +39 0532 293006 | +--------------------------+ ---------- Original Message ----------- From: Serge Leschinsky <fi...@in...> To: Bruce Smith <dev...@li...> Sent: Tue, 13 Jun 2006 19:32:22 -0700 Subject: Re: [Devil-linux-develop] groupadd PAM problem. > > > Let's not forget about 'usermod' & 'groupmod'. Can you try those John? > > As far as I know, if pam config for usermod (or groupmod) is absent, > the "other" config should be used. Otherwise we have to write > configs for _all_ binaries from the system... > > I guess, there are 2 possible causes of problem: > 1) the package ( which contain userdel, useradd etc) is wrongly compiled > 2) the pam config "other" is wrong. > > I'll see tonight. But I can't start compilation on my note due to the > note age, so I'll see on the latest beta - > devil-linux-1.2.10-2006-06-08-i686-SMP.tar.bz2 . I'm sorry, but I'm > now in business trip in Sunnyvale, CA and have no access to build > environment & build boxes. > ------- End of Original Message ------- |
|
From: John B. <jbr...@gm...> - 2006-06-14 12:52:24
|
On 6/13/06, Serge Leschinsky <fi...@in...> wrote: > > Oops.. I am in a great hurry ... > > > ======================================================== > > for i in usermod userdel groupadd groudel groupmod > > do > > cp -a /etc/pam.d/useradd /etc/pam.d/$i > > done > > > save-config > > ======================================================== > root@squid:~ # useradd serge root@squid:~ # usermod -L serge root@squid:~ # usermod -U serge root@squid:~ # userdel serge userdel: error removing group entry userdel: error removing shadow group entry root@squid:~ # groupadd dl-linux root@squid:~ # groupmod -g 6000 dl-linux root@squid:~ # groupdel dl-linux So, everything is working except userdel. -- John Bridleman |
|
From: Bruce S. <bw...@ar...> - 2006-06-14 13:27:12
|
> root@squid:~ # userdel serge > userdel: error removing group entry > userdel: error removing shadow group entry It's not saying "PAM" error any more... Is there anything in the messages log (VC10?) or dmesg with a more descriptive error message? - BS |
|
From: Bruce S. <bw...@ar...> - 2006-06-14 14:24:42
|
After looking around a little after a full compile, I found these: .....build/tmp/shadow-4.0.16/etc/pam.d # ll total 76 -rw-r--r-- 1 root root 10519 Jun 14 02:05 Makefile -rw-r--r-- 1 2732 2732 379 May 11 12:48 Makefile.am -rw-r--r-- 1 2732 2732 10882 Jun 1 17:19 Makefile.in -rw-r--r-- 1 2732 2732 103 Jan 2 15:36 chage -rw-r--r-- 1 2732 2732 103 May 11 12:47 chgpasswd -rw-r--r-- 1 2732 2732 103 Jan 2 15:36 chpasswd -rw-r--r-- 1 2732 2732 103 Jan 2 15:36 groupadd -rw-r--r-- 1 2732 2732 103 Jan 2 15:36 groupdel -rw-r--r-- 1 2732 2732 103 Jan 2 15:36 groupmod -rw-r--r-- 1 2732 2732 336 Jan 2 15:36 login -rw-r--r-- 1 2732 2732 103 Jan 2 15:36 newusers -rw-r--r-- 1 2732 2732 97 Jan 2 15:36 passwd -rw-r--r-- 1 2732 2732 512 Jan 2 15:36 su -rw-r--r-- 1 2732 2732 103 Jan 2 15:36 useradd -rw-r--r-- 1 2732 2732 103 Jan 2 15:36 usermod Should we be using those PAM files instead of the ones we have? Most are a little different than the ones we're using now. - BS |
|
From: Heiko Z. <he...@zu...> - 2006-06-14 15:19:45
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, June 14, 2006 05:00, Dr. Alberto Benati wrote: > Yes, the problem is /etc/pam.d/other file. > > > In Red Hat Enterprise Linux ES release 3: > auth required /lib/security/$ISA/pam_deny.so account required > /lib/security/$ISA/pam_deny.so > password required /lib/security/$ISA/pam_deny.so session required > /lib/security/$ISA/pam_deny.so > > > In my internal server, I use: > auth required pam_unix.so account required pam_unix.so > password required pam_unix.so session required pam_unix.so So the question is, which route should we go? Leave the locked down 'other' and create a new file for every program? It may be best just to copy the ones Serge found within the shadow package. - -- Regards Heiko Zuerker http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iEYEARECAAYFAkSQKPcACgkQUcytMSbs+YXFiQCfTsKkG00gdn64a8uButLRVvlU Q+cAn3lIHnqrTAL3NqkN5P1YxPEvZxfZ =Fy/w -----END PGP SIGNATURE----- |
|
From: Bruce S. <br...@ar...> - 2006-06-14 20:32:14
|
> So the question is, which route should we go? > Leave the locked down 'other' and create a new file for every program? It sounds more secure to have a locked down 'other', but I'm not a PAM expert, so I really don't know. > It may be best just to copy the ones Serge found within the shadow package. Ah hum, the ones *I* found in the shadow package! :-) They look like they might be worth a try. Try them all, or just the ones we're missing (there may be conflicts)? I'd stick them all in and see what happens. - BS |
|
From: Heiko Z. <he...@zu...> - 2006-06-14 20:43:05
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, June 14, 2006 15:32, Bruce Smith wrote: >> So the question is, which route should we go? >> Leave the locked down 'other' and create a new file for every program? >> > > It sounds more secure to have a locked down 'other', > but I'm not a PAM expert, so I really don't know. > >> It may be best just to copy the ones Serge found within the shadow >> package. > > Ah hum, the ones *I* found in the shadow package! :-) That's what I wrote. The bytes must have gotten messed up when the data was transfered to the mail server. I heard that happens somtimes. ;-) > They look like they might be worth a try. > > > Try them all, or just the ones we're missing (there may be conflicts)? > I'd stick them all in and see what happens. I agree, let's use 'em all. - -- Regards Heiko Zuerker http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iEYEARECAAYFAkSQdJYACgkQUcytMSbs+YU2MwCgh2ORFdbhv+mBBn7uiAe3Iw1J tg0An0hKkqy9IwgatTSuv4jKk1iPQUdj =VnuO -----END PGP SIGNATURE----- |
|
From: Bruce S. <bw...@ar...> - 2006-06-15 15:29:06
|
> > They look like they might be worth a try. > > > > Try them all, or just the ones we're missing (there may be conflicts)? > > I'd stick them all in and see what happens. > > I agree, let's use 'em all. After looking and comparing them, we can't use them all. For example, the "login" in the shadow package has "include" lines to files that don't exist, and it calls pam modules that we don't have (i.e. pam_selinux.so). It looks like we're going to have to create our own pam files for the ones we're missing. We can use the list of pam files in the shadow package as reference to make sure we have every file that it has, and we are missing a few of them now. Currently the pam files are in a src tar file, and there are some that I think should be changed. So, I'm going to get rid of the tar file and put the pam files in CVS (build/config/etc/pam.d/) so we have a record of changes. - BS |