You can subscribe to this list here.
| 2001 |
Jan
(39) |
Feb
(258) |
Mar
(396) |
Apr
(439) |
May
(337) |
Jun
(351) |
Jul
(296) |
Aug
(205) |
Sep
(328) |
Oct
(174) |
Nov
(252) |
Dec
(172) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(213) |
Feb
(194) |
Mar
(337) |
Apr
(314) |
May
(373) |
Jun
(522) |
Jul
(417) |
Aug
(471) |
Sep
(486) |
Oct
(422) |
Nov
(274) |
Dec
(299) |
| 2003 |
Jan
(354) |
Feb
(310) |
Mar
(379) |
Apr
(349) |
May
(388) |
Jun
(218) |
Jul
(368) |
Aug
(340) |
Sep
(222) |
Oct
(176) |
Nov
(214) |
Dec
(211) |
| 2004 |
Jan
(221) |
Feb
(187) |
Mar
(190) |
Apr
(211) |
May
(114) |
Jun
(136) |
Jul
(124) |
Aug
(178) |
Sep
(244) |
Oct
(203) |
Nov
(215) |
Dec
(156) |
| 2005 |
Jan
(334) |
Feb
(268) |
Mar
(302) |
Apr
(309) |
May
(192) |
Jun
(288) |
Jul
(273) |
Aug
(215) |
Sep
(318) |
Oct
(347) |
Nov
(226) |
Dec
(265) |
| 2006 |
Jan
(192) |
Feb
(227) |
Mar
(311) |
Apr
(197) |
May
(224) |
Jun
(213) |
Jul
(285) |
Aug
(227) |
Sep
(190) |
Oct
(209) |
Nov
(169) |
Dec
(174) |
| 2007 |
Jan
(149) |
Feb
(112) |
Mar
(144) |
Apr
(204) |
May
(178) |
Jun
(155) |
Jul
(246) |
Aug
(221) |
Sep
(187) |
Oct
(262) |
Nov
(163) |
Dec
(158) |
| 2008 |
Jan
(256) |
Feb
(318) |
Mar
(307) |
Apr
(237) |
May
(202) |
Jun
(105) |
Jul
(131) |
Aug
(107) |
Sep
(153) |
Oct
(165) |
Nov
(159) |
Dec
(189) |
| 2009 |
Jan
(202) |
Feb
(150) |
Mar
(151) |
Apr
(132) |
May
(56) |
Jun
(115) |
Jul
(103) |
Aug
(150) |
Sep
(141) |
Oct
(187) |
Nov
(154) |
Dec
(105) |
| 2010 |
Jan
(128) |
Feb
(83) |
Mar
(64) |
Apr
(37) |
May
(92) |
Jun
(91) |
Jul
(90) |
Aug
(145) |
Sep
(53) |
Oct
(69) |
Nov
(98) |
Dec
(149) |
| 2011 |
Jan
(44) |
Feb
(99) |
Mar
(70) |
Apr
(78) |
May
(138) |
Jun
(132) |
Jul
(151) |
Aug
(146) |
Sep
(107) |
Oct
(168) |
Nov
(88) |
Dec
(94) |
| 2012 |
Jan
(51) |
Feb
(153) |
Mar
(141) |
Apr
(102) |
May
(79) |
Jun
(63) |
Jul
(87) |
Aug
(39) |
Sep
(67) |
Oct
(84) |
Nov
(57) |
Dec
(31) |
| 2013 |
Jan
(55) |
Feb
(96) |
Mar
(79) |
Apr
(33) |
May
(53) |
Jun
(63) |
Jul
(57) |
Aug
(76) |
Sep
(39) |
Oct
(47) |
Nov
(68) |
Dec
(61) |
| 2014 |
Jan
(26) |
Feb
(98) |
Mar
(29) |
Apr
(57) |
May
(58) |
Jun
(51) |
Jul
(34) |
Aug
(26) |
Sep
(69) |
Oct
(81) |
Nov
(52) |
Dec
(48) |
| 2015 |
Jan
(67) |
Feb
(18) |
Mar
(92) |
Apr
(32) |
May
(37) |
Jun
(21) |
Jul
(26) |
Aug
(28) |
Sep
(6) |
Oct
(24) |
Nov
(35) |
Dec
(34) |
| 2016 |
Jan
(16) |
Feb
(24) |
Mar
(49) |
Apr
(11) |
May
(37) |
Jun
(68) |
Jul
(35) |
Aug
(24) |
Sep
(35) |
Oct
(63) |
Nov
(20) |
Dec
(26) |
| 2017 |
Jan
(98) |
Feb
(82) |
Mar
(42) |
Apr
(62) |
May
(55) |
Jun
(28) |
Jul
(17) |
Aug
(13) |
Sep
(4) |
Oct
(11) |
Nov
(6) |
Dec
(17) |
| 2018 |
Jan
(22) |
Feb
(6) |
Mar
(16) |
Apr
(9) |
May
(20) |
Jun
(25) |
Jul
(15) |
Aug
(10) |
Sep
(6) |
Oct
(2) |
Nov
(14) |
Dec
(25) |
| 2019 |
Jan
(8) |
Feb
(6) |
Mar
(6) |
Apr
(4) |
May
(13) |
Jun
(8) |
Jul
(14) |
Aug
(36) |
Sep
(10) |
Oct
(27) |
Nov
(5) |
Dec
|
| 2020 |
Jan
(10) |
Feb
(4) |
Mar
|
Apr
(1) |
May
(2) |
Jun
(3) |
Jul
(4) |
Aug
(11) |
Sep
(1) |
Oct
(1) |
Nov
(5) |
Dec
(12) |
| 2021 |
Jan
(2) |
Feb
|
Mar
(4) |
Apr
(6) |
May
(8) |
Jun
(2) |
Jul
(1) |
Aug
(7) |
Sep
(3) |
Oct
(23) |
Nov
(10) |
Dec
(17) |
| 2022 |
Jan
(1) |
Feb
|
Mar
(1) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
(27) |
Aug
(5) |
Sep
(3) |
Oct
(9) |
Nov
(3) |
Dec
(11) |
| 2023 |
Jan
(13) |
Feb
(7) |
Mar
(3) |
Apr
|
May
(4) |
Jun
(9) |
Jul
|
Aug
(17) |
Sep
|
Oct
|
Nov
(1) |
Dec
(1) |
| 2025 |
Jan
(2) |
Feb
(6) |
Mar
(4) |
Apr
(10) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
(2) |
| 2026 |
Jan
|
Feb
(3) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Adam \Fuzzy\ K. <fu...@fu...> - 2006-02-20 16:01:37
|
Is anyone using Virtualmin and Dovecot? If so, how? I have roughly 3000+ mailboxes I need to move off our other mail system (windows based IMail). We host nearly 80 domains and anywhere from 2 to 150 users each domain, plus our dialup/wireless customers. I can't figure out how to make dovecot translate a login such as "us...@do..." to the unix user of user-domain or user-domain.com or anything of the like. Anyone else have this working? Am I even posting this to the right place? -Adam "Fuzzy" Kennedy |
|
From: Murray T. <mtr...@ce...> - 2006-02-20 06:06:45
|
On Mon, 2006-02-20 at 13:01, Jamie Cameron wrote: > On Mon, 2006-02-20 at 15:19, Murray Trainer wrote: > > On Fri, 2006-02-17 at 18:53, Jamie Cameron wrote: > > > On 17/Feb/2006 16:49 Murray Trainer wrote .. > > > > Hi Jamie, > > > > > > > > I am testing the LDAP User's and Groups module in 1.2.63 and I am > > > > getting the error below: > > > > > > > > The user was saved successfully in the LDAP database, but an IMAP error > > > > occurred : : Login failed: authentication failure > > > > > > > > It looks like the user and their Cyrus mailbox and LDAP addressbook are > > > > being created OK. I did the tests below after creating the user which > > > > confirm that they can authenticate to Cyrus OK. Not sure why the > > > > authentication is failing? It seems to be OK shortly afterwards. > > > > > > Hi Murray, > > > Are you seeing this when adding a new user with IMAP, or only when enabling > > > it for an existing user? > > > > > > - Jamie > > > > Hi Jamie, > > > > When adding a new user with IMAP - we normally only do that. > > I am not sure what could be happening then - perhaps the IMAP server has > a delay between when a user is added to LDAP and when it can login? Perhaps this is an issue similar to that which required a restart of the nscd daemon. > > As an > > aside, I tried to add a new user with IMAP disabled but I get the error > > below: > > > > Failed to save user : Failed to add user to LDAP database : object class > > 'inetOrgPerson' requires attribute 'sn' > > > > Not sure why we get an error as inetOrgPerson is not the object class we > > use for IMAP - we use SuseEmailObject. > > Do you have that object class anywhere in your module configuration? > > - Jamie Yes, Other objectClasses to add to new users: top person inetOrgPerson LDAP object class for Samba users: sambaSamAccount LDAP object class for Samba group: sambaGroupMapping LDAP object class for IMAP users: SuSEeMailObject Murray |
|
From: Jamie C. <jca...@we...> - 2006-02-20 05:02:13
|
On Mon, 2006-02-20 at 15:19, Murray Trainer wrote: > On Fri, 2006-02-17 at 18:53, Jamie Cameron wrote: > > On 17/Feb/2006 16:49 Murray Trainer wrote .. > > > Hi Jamie, > > > > > > I am testing the LDAP User's and Groups module in 1.2.63 and I am > > > getting the error below: > > > > > > The user was saved successfully in the LDAP database, but an IMAP error > > > occurred : : Login failed: authentication failure > > > > > > It looks like the user and their Cyrus mailbox and LDAP addressbook are > > > being created OK. I did the tests below after creating the user which > > > confirm that they can authenticate to Cyrus OK. Not sure why the > > > authentication is failing? It seems to be OK shortly afterwards. > > > > Hi Murray, > > Are you seeing this when adding a new user with IMAP, or only when enabling > > it for an existing user? > > > > - Jamie > > Hi Jamie, > > When adding a new user with IMAP - we normally only do that. I am not sure what could be happening then - perhaps the IMAP server has a delay between when a user is added to LDAP and when it can login? > As an > aside, I tried to add a new user with IMAP disabled but I get the error > below: > > Failed to save user : Failed to add user to LDAP database : object class > 'inetOrgPerson' requires attribute 'sn' > > Not sure why we get an error as inetOrgPerson is not the object class we > use for IMAP - we use SuseEmailObject. Do you have that object class anywhere in your module configuration? - Jamie |
|
From: Murray T. <mtr...@ce...> - 2006-02-20 04:19:24
|
On Fri, 2006-02-17 at 18:53, Jamie Cameron wrote: > On 17/Feb/2006 16:49 Murray Trainer wrote .. > > Hi Jamie, > > > > I am testing the LDAP User's and Groups module in 1.2.63 and I am > > getting the error below: > > > > The user was saved successfully in the LDAP database, but an IMAP error > > occurred : : Login failed: authentication failure > > > > It looks like the user and their Cyrus mailbox and LDAP addressbook are > > being created OK. I did the tests below after creating the user which > > confirm that they can authenticate to Cyrus OK. Not sure why the > > authentication is failing? It seems to be OK shortly afterwards. > > Hi Murray, > Are you seeing this when adding a new user with IMAP, or only when enabling > it for an existing user? > > - Jamie Hi Jamie, When adding a new user with IMAP - we normally only do that. As an aside, I tried to add a new user with IMAP disabled but I get the error below: Failed to save user : Failed to add user to LDAP database : object class 'inetOrgPerson' requires attribute 'sn' Not sure why we get an error as inetOrgPerson is not the object class we use for IMAP - we use SuseEmailObject. Murray |
|
From: Murray T. <mtr...@ce...> - 2006-02-20 04:11:39
|
On Fri, 2006-02-17 at 18:47, Jamie Cameron wrote: > On 17/Feb/2006 17:09 Murray Trainer wrote .. > > Hi Jamie, > > > > More testing shows that when I save an LDAP user with default LDAP > > groups they appear as they should in the secondary groups list box on > > the Add User screen but when the user is saved they are not added to the > > appropriate LDAP groups. I tried it with a single word group name and > > still have the problem. This might be a side-effect of the fix you did > > to support groups with spaces like "Domain Users". > > That is odd, I am not seeing this on my system, even if I use groups > with or without spaces in them. Are the groups selected when you add the user? > Can you add the groups later when you re-edit the user? > > - Jamie Hi Jamie, I tried it again this morning and now the user does have the default groups. I did it using Konqueror instead of Firefox. Perhaps it was some strange cache issue. I'll let you know if it starts happening again. Thanks Murray |
|
From: Jamie C. <jca...@we...> - 2006-02-19 03:42:14
|
Hi Mohammed, That is not the correct file, sorry. The one you attached is for the NSS-LDAP configuration, but there is also a separate file for PAM-LDAP configuration. I am not sure where it would be located on your system though - it varies from one Linux distribution to another. - Jamie -----Original Message----- From: "Khan, Mohammed [SMO]" <MK...@fr...> Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan Date: Sat 18 Feb 2006 5:55 am Size: 2K To: <web...@li...> Morning Jamie, I am attaching my ldap.conf file please check and let me know what I am doing wrong. If I an able the bindpw I am not able to login to usermin. Please check if the way I have set it up is correct. Do I create a file /etc/ldap.secret and copy the line from ldap.conf file. Please let me know # @(#)$Id: ldap.conf,v 1.27 2003/01/17 21:37:12 lukeh Exp $ # # This is the configuration file for the LDAP nameservice # switch library and the LDAP PAM module. # # PADL Software # http://www.padl.com # # Your LDAP server. Must be resolvable without using LDAP. # Multiple hosts may be specified, each separated by a # space. How long nss_ldap takes to failover depends on # whether your LDAP client library supports configurable # network or connect timeouts (see bind_timelimit). #host 127.0.0.1 host dublx06.noam.corp.frk.com # The distinguished name of the search base. #base dc=example,dc=com #base dc=people,dc=noam,dc=corp,dc=frk,dc=com base dc=noam,dc=corp,dc=frk,dc=com # Another way to specify your LDAP server is to provide an # uri with the server name. This allows to use # Unix Domain Sockets to connect to a local LDAP Server. #uri ldap://127.0.0.1/ #uri ldaps://127.0.0.1/ #uri ldapi://%2fvar%2frun%2fldapi_sock/ # Note: %2f encodes the '/' used as directory separator # The LDAP version to use (defaults to 3 # if supported by client library) ldap_version 3 # The distinguished name to bind to the server with. # Optional: default is to bind anonymously. #binddn cn=proxyuser,dc=example,dc=com #binddn cn=Directory Manager # The credentials to bind with. # Optional: default is no credential. bindpw secret # The distinguished name to bind to the server with # if the effective user ID is root. Password is # stored in /etc/ldap.secret (mode 600) #rootbinddn cn=manager,dc=example,dc=com rootbinddn cn=Directory Manager # The port. # Optional: default is 389. #port 389 # The search scope. #scope sub #scope one #scope base # Search timelimit #timelimit 30 # Bind timelimit #bind_timelimit 30 # Idle timelimit; client will close connections # (nss_ldap only) if the server has not been contacted # for the number of seconds specified below. #idle_timelimit 3600 # Filter to AND with uid=%s #pam_filter objectclass=account pam_filter objectclass=posixAccount # The user ID attribute (defaults to uid) pam_login_attribute uid # Search the root DSE for the password policy (works # with Netscape Directory Server) #pam_lookup_policy yes # Check the 'host' attribute for access control # Default is no; if set to yes, and user has no # value for the host attribute, and pam_ldap is # configured for account management (authorization) --- message truncated --- |
|
From: Craig W. <cra...@az...> - 2006-02-18 01:18:58
|
That's sort of an unfair request. I doubt he's using FDS. If I was going to take a guess...it would be these lines in /etc/ldap.conf #nss_base_passwd ou=People,dc=noam,dc=corp,dc=frk,dc=com #nss_base_shadow ou=People,dc=noam,dc=corp,dc=frk,dc=com #nss_base_passwd ou=People,dc=example,dc=com?one I don't think that they should be commented out but should probably be nss_base_passwd ou=People,dc=noam,dc=corp,dc=frk,dc=com?one nss_base_shadow ou=People,dc=noam,dc=corp,dc=frk,dc=com?one nss_base_passwd ou=People,dc=noam,dc=corp,dc=frk,dc=com?one but that could be ou=Users - it all depends upon how you have Directory Server set up. and I'm guessing that you are using something like RHEL 4 by the ldap.conf below and I have never set up pam_ldap and thus am not qualified to give you an opinion on how it works. I do use FDS and OpenLDAP on various servers all RHEL and have never used pam_ldap and can change passwords from the command line which is what Jamie asked you. i.e. # passwd craig Changing password for user craig. New UNIX password: Retype new UNIX password: LDAP password information changed for craig passwd: all authentication tokens updated successfully. and then to verify that the password change actually worked... # ssh craig@localhost craig@localhost's password: Last login: Fri Jan 27 22:16:45 2006 because what Jamie is suggesting is that if you can do what I just demonstrated, he believes Usermin would authenticate a user. perhaps you should spend a little more time learning how to do handle your own administration because once you can do you own administration, configuring a client tool such as Webmin or Usermin becomes much easier. Craig ---- > On Fri, 2006-02-17 at 15:54 -0800, Khan, Mohammed [SMO] wrote: > Jamie, Please can you please check my file. And let me know what I am doing wrong. > > -----Original Message----- > From: Khan, Mohammed [SMO] > Sent: Friday, February 17, 2006 10:55 AM > To: 'web...@li...' > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > Morning Jamie, > I am attaching my ldap.conf file please check and let me know what I am doing wrong. If I an able the bindpw I am not able to login to usermin. Please check if the way I have set it up is correct. Do I create a file /etc/ldap.secret and copy the line from ldap.conf file. Please let me know > # @(#)$Id: ldap.conf,v 1.27 2003/01/17 21:37:12 lukeh Exp $ > # > # This is the configuration file for the LDAP nameservice > # switch library and the LDAP PAM module. > # > # PADL Software > # http://www.padl.com > # > > # Your LDAP server. Must be resolvable without using LDAP. > # Multiple hosts may be specified, each separated by a > # space. How long nss_ldap takes to failover depends on > # whether your LDAP client library supports configurable > # network or connect timeouts (see bind_timelimit). > #host 127.0.0.1 > host dublx06.noam.corp.frk.com > > # The distinguished name of the search base. > #base dc=example,dc=com > #base dc=people,dc=noam,dc=corp,dc=frk,dc=com > base dc=noam,dc=corp,dc=frk,dc=com > > # Another way to specify your LDAP server is to provide an > # uri with the server name. This allows to use > # Unix Domain Sockets to connect to a local LDAP Server. > #uri ldap://127.0.0.1/ > #uri ldaps://127.0.0.1/ > #uri ldapi://%2fvar%2frun%2fldapi_sock/ > # Note: %2f encodes the '/' used as directory separator > > # The LDAP version to use (defaults to 3 > # if supported by client library) > ldap_version 3 > > # The distinguished name to bind to the server with. > # Optional: default is to bind anonymously. > #binddn cn=proxyuser,dc=example,dc=com > #binddn cn=Directory Manager > > # The credentials to bind with. > # Optional: default is no credential. > bindpw secret > # The distinguished name to bind to the server with > # if the effective user ID is root. Password is > # stored in /etc/ldap.secret (mode 600) > #rootbinddn cn=manager,dc=example,dc=com > rootbinddn cn=Directory Manager > > # The port. > # Optional: default is 389. > #port 389 > > # The search scope. > #scope sub > #scope one > #scope base > > # Search timelimit > #timelimit 30 > > # Bind timelimit > #bind_timelimit 30 > > # Idle timelimit; client will close connections > # (nss_ldap only) if the server has not been contacted > # for the number of seconds specified below. > #idle_timelimit 3600 > > # Filter to AND with uid=%s > #pam_filter objectclass=account > pam_filter objectclass=posixAccount > > # The user ID attribute (defaults to uid) > pam_login_attribute uid > > # Search the root DSE for the password policy (works > # with Netscape Directory Server) > #pam_lookup_policy yes > > # Check the 'host' attribute for access control > # Default is no; if set to yes, and user has no > # value for the host attribute, and pam_ldap is > # configured for account management (authorization) > # then the user will not be allowed to login. > #pam_check_host_attr yes > > # Group to enforce membership of > #pam_groupdn cn=PAM,ou=Groups,dc=example,dc=com > pam_groupdn cn=TestGroup,ou=Groups,dc=noam,dc=corp,dc=frk,dc=com > #pam_groupdn cn=dublx09,ou=Groups,dc=noam,dc=corp,dc=frk,dc=com > > # Group member attribute > #pam_member_attribute uniquemember > pam_member_attribute memberUid > > # Specify a minium or maximum UID number allowed > #pam_min_uid 0 > #pam_max_uid 0 > > # Template login attribute, default template user > # (can be overriden by value of former attribute > # in user's entry) > #pam_login_attribute userPrincipalName > #pam_template_login_attribute uid > #pam_template_login nobody > > # HEADS UP: the pam_crypt, pam_nds_passwd, > # and pam_ad_passwd options are no > # longer supported. > > # Do not hash the password at all; presume > # the directory server will do it, if > # necessary. This is the default. > #pam_password clear > > # Hash password locally; required for University of > # Michigan LDAP server, and works with Netscape > # Directory Server if you're using the UNIX-Crypt > # hash mechanism and not using the NT Synchronization > # service. > #pam_password crypt > > # Remove old password first, then update in > # cleartext. Necessary for use with Novell > # Directory Services (NDS) > #pam_password nds > > # Update Active Directory password, by > # creating Unicode password and updating > # unicodePwd attribute. > #pam_password ad > > # Use the OpenLDAP password change > # extended operation to update the password. > #pam_password exop > #pam_password crypt > > # Redirect users to a URL or somesuch on password > # changes. > #pam_password_prohibit_message Please visit http://internal to change your password. > > # RFC2307bis naming contexts > # Syntax: > # nss_base_XXX base?scope?filter > # where scope is {base,one,sub} > # and filter is a filter to be &'d with the > # default filter. > # You can omit the suffix eg: > # nss_base_passwd ou=People, > # to append the default base DN but this > # may incur a small performance impact. > #nss_base_passwd ou=People,dc=noam,dc=corp,dc=frk,dc=com > #nss_base_shadow ou=People,dc=noam,dc=corp,dc=frk,dc=com > #nss_base_passwd ou=People,dc=example,dc=com?one > #nss_base_shadow ou=People,dc=example,dc=com?one > #nss_base_group ou=Group,dc=example,dc=com?one > #nss_base_group ou=Groups,dc=noam,dc=corp,dc=frk,dc=com > #nss_base_hosts ou=Hosts,dc=example,dc=com?one > #nss_base_services ou=Services,dc=example,dc=com?one > #nss_base_networks ou=Networks,dc=example,dc=com?one > #nss_base_protocols ou=Protocols,dc=example,dc=com?one > #nss_base_rpc ou=Rpc,dc=example,dc=com?one > #nss_base_ethers ou=Ethers,dc=example,dc=com?one > #nss_base_netmasks ou=Networks,dc=example,dc=com?ne > #nss_base_bootparams ou=Ethers,dc=example,dc=com?one > #nss_base_aliases ou=Aliases,dc=example,dc=com?one > #nss_base_netgroup ou=Netgroup,dc=example,dc=com?one > > # attribute/objectclass mapping > # Syntax: > #nss_map_attribute rfc2307attribute mapped_attribute > #nss_map_objectclass rfc2307objectclass mapped_objectclass > > # configure --enable-nds is no longer supported. > # For NDS now do: > #nss_map_attribute uniqueMember member > > # configure --enable-mssfu-schema is no longer supported. > # For MSSFU now do: > #nss_map_objectclass posixAccount User > #nss_map_attribute uid msSFUName > #nss_map_attribute uniqueMember posixMember > #nss_map_attribute userPassword msSFUPassword > #nss_map_attribute homeDirectory msSFUHomeDirectory > #nss_map_objectclass posixGroup Group > #pam_login_attribute msSFUName > #pam_filter objectclass=User > #pam_password ad > > # configure --enable-authpassword is no longer supported > # For authPassword support, now do: > #nss_map_attribute userPassword authPassword > #pam_password nds > > # For IBM SecureWay support, do: > #nss_map_objectclass posixAccount aixAccount > #nss_map_attribute uid userName > #nss_map_attribute gidNumber gid > #nss_map_attribute uidNumber uid > #nss_map_attribute userPassword passwordChar > #nss_map_objectclass posixGroup aixAccessGroup > #nss_map_attribute cn dublx09 > #nss_map_attribute memberUid member > #pam_login_attribute userName > #pam_filter objectclass=aixAccount > #pam_password clear > > # Netscape SDK LDAPS > #ssl on > > # Netscape SDK SSL options > #sslpath /etc/ssl/certs/cert7.db > > # OpenLDAP SSL mechanism > # start_tls mechanism uses the normal LDAP port, LDAPS typically 636 > #ssl start_tls > #ssl on > > # OpenLDAP SSL options > # Require and verify server certificate (yes/no) > # Default is "no" > #tls_checkpeer yes > > # CA certificates for server certificate verification > # At least one of these are required if tls_checkpeer is "yes" > #tls_cacertfile /etc/ssl/ca.cert > #tls_cacertdir /etc/ssl/certs > > # Seed the PRNG if /dev/urandom is not provided > #tls_randfile /var/run/egd-pool > > # SSL cipher suite > # See man ciphers for syntax > #tls_ciphers TLSv1 > > # Client certificate and key > # Use these, if your server requires client authentication. > #tls_cert > #tls_key > ssl no > > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Friday, February 17, 2006 9:02 AM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > That file should already exist somewhere under /etc on your system. It may be called something different too, like pam_ldap.conf > > - Jamie > > -----Original Message----- > > From: "Khan, Mohammed [SMO]" <MK...@fr...> > Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan > Date: Fri 17 Feb 2006 4:21 pm > Size: 2K > To: <web...@li...> > > I don't have that file so shall I create these files, just fyi my server linux AS2.1. If I do what shall I put in the file. > > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 5:26 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > Make sure that in your PAM LDAP config file (/etc/pam_ldap/auth_ldap.conf > on my system) that the binddn and rootbinddn parameters are set to your > LDAP administration user, and that the passwords in the bindpw parameter and > /etc/ldap.secret file are set to match. Otherwise PAM will connect to LDAP > as the user who is changing his password, which will generally not be allowed. > > - Jamie > > On 17/Feb/2006 11:43 Khan, Mohammed [SMO] wrote .. > > Jamie, now i am getting this error: > > Feb 16 16:36:29 dublx09 l/usermin/changepass/changepass.cgi: pam_ldap: > > error trying to bind as user "uid=mkhan,ou=People, dc=noam,dc=corp,dc=frk,dc=com" > > (Invalid credentials) > > > > -----Original Message----- > > From: web...@li... > > [mailto:web...@li...]On Behalf Of Jamie > > Cameron > > Sent: Friday, February 17, 2006 2:10 AM > > To: web...@li... > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > > > > Hi, > > That looks OK.. > > Can LDAP users use the command-line passwd command to change their passwords? > > > > - Jamie > > > > -----Original Message----- > > > > From: "Khan, Mohammed [SMO]" <MK...@fr...> > > Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan > > Date: Fri 17 Feb 2006 10:07 am > > Size: 2K > > To: <web...@li...> > > > > Hi Jamie, > > Here is my passwd file: Pls tell me what I am doing worng. > > #%PAM-1.0 > > password required pam_cracklib.so > > password sufficient pam_ldap.so > > password sufficient pam_unix.so > > password required pam_deny.so > > > > > > > > Thanks > > Mohammed > > > > -----Original Message----- > > From: web...@li... > > [mailto:web...@li...]On Behalf Of Jamie > > Cameron > > Sent: Thursday, February 16, 2006 2:46 PM > > To: web...@li... > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > > > > Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that > > Usermin's > > Change Password module is setup to use PAM. > > > > - Jamie > > > > On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > > > Hello Jamie, > > > Do you know how can I use usermin to change my ldap password. Please > > need > > > your help. > > > > > > Thanks > > > Mohammed > > > |
|
From: Khan, M. [SMO] <MK...@fr...> - 2006-02-17 23:54:51
|
Jamie, Please can you please check my file. And let me know what I am doin= g wrong. -----Original Message----- From: Khan, Mohammed [SMO]=20 Sent: Friday, February 17, 2006 10:55 AM To: 'web...@li...' Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Morning Jamie, I am attaching my ldap.conf file please check and let me know what I am do= ing wrong. If I an able the bindpw I am not able to login to usermin. Pl= ease check if the way I have set it up is correct. Do I create a file /etc= /ldap.secret and copy the line from ldap.conf file. Please let me know # @(#)$Id: ldap.conf,v 1.27 2003/01/17 21:37:12 lukeh Exp $ # # This is the configuration file for the LDAP nameservice # switch library and the LDAP PAM module. # # PADL Software # http://www.padl.com # # Your LDAP server. Must be resolvable without using LDAP. # Multiple hosts may be specified, each separated by a # space. How long nss_ldap takes to failover depends on # whether your LDAP client library supports configurable # network or connect timeouts (see bind_timelimit). #host 127.0.0.1 host dublx06.noam.corp.frk.com # The distinguished name of the search base. #base dc=3Dexample,dc=3Dcom #base dc=3Dpeople,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom base dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom # Another way to specify your LDAP server is to provide an # uri with the server name. This allows to use # Unix Domain Sockets to connect to a local LDAP Server. #uri ldap://127.0.0.1/ #uri ldaps://127.0.0.1/ #uri ldapi://%2fvar%2frun%2fldapi_sock/ # Note: %2f encodes the '/' used as directory separator # The LDAP version to use (defaults to 3 # if supported by client library) ldap_version 3 # The distinguished name to bind to the server with. # Optional: default is to bind anonymously. #binddn cn=3Dproxyuser,dc=3Dexample,dc=3Dcom #binddn cn=3DDirectory Manager # The credentials to bind with. # Optional: default is no credential. bindpw secret # The distinguished name to bind to the server with # if the effective user ID is root. Password is # stored in /etc/ldap.secret (mode 600) #rootbinddn cn=3Dmanager,dc=3Dexample,dc=3Dcom rootbinddn cn=3DDirectory Manager # The port. # Optional: default is 389. #port 389 # The search scope. #scope sub #scope one #scope base # Search timelimit #timelimit 30 # Bind timelimit #bind_timelimit 30 # Idle timelimit; client will close connections # (nss_ldap only) if the server has not been contacted # for the number of seconds specified below. #idle_timelimit 3600 # Filter to AND with uid=3D%s #pam_filter objectclass=3Daccount pam_filter objectclass=3DposixAccount # The user ID attribute (defaults to uid) pam_login_attribute uid # Search the root DSE for the password policy (works # with Netscape Directory Server) #pam_lookup_policy yes # Check the 'host' attribute for access control # Default is no; if set to yes, and user has no # value for the host attribute, and pam_ldap is # configured for account management (authorization) # then the user will not be allowed to login. #pam_check_host_attr yes # Group to enforce membership of #pam_groupdn cn=3DPAM,ou=3DGroups,dc=3Dexample,dc=3Dcom pam_groupdn cn=3DTestGroup,ou=3DGroups,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom #pam_groupdn cn=3Ddublx09,ou=3DGroups,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom # Group member attribute #pam_member_attribute uniquemember pam_member_attribute memberUid # Specify a minium or maximum UID number allowed #pam_min_uid 0 #pam_max_uid 0 # Template login attribute, default template user # (can be overriden by value of former attribute # in user's entry) #pam_login_attribute userPrincipalName #pam_template_login_attribute uid #pam_template_login nobody # HEADS UP: the pam_crypt, pam_nds_passwd, # and pam_ad_passwd options are no # longer supported. # Do not hash the password at all; presume # the directory server will do it, if # necessary. This is the default. #pam_password clear # Hash password locally; required for University of # Michigan LDAP server, and works with Netscape # Directory Server if you're using the UNIX-Crypt # hash mechanism and not using the NT Synchronization # service. #pam_password crypt # Remove old password first, then update in # cleartext. Necessary for use with Novell # Directory Services (NDS) #pam_password nds # Update Active Directory password, by # creating Unicode password and updating # unicodePwd attribute. #pam_password ad # Use the OpenLDAP password change # extended operation to update the password. #pam_password exop #pam_password crypt # Redirect users to a URL or somesuch on password # changes. #pam_password_prohibit_message Please visit http://internal to change your = password. # RFC2307bis naming contexts # Syntax: # nss_base_XXX base?scope?filter # where scope is {base,one,sub} # and filter is a filter to be &'d with the # default filter. # You can omit the suffix eg: # nss_base_passwd ou=3DPeople, # to append the default base DN but this # may incur a small performance impact. #nss_base_passwd ou=3DPeople,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom #nss_base_shadow ou=3DPeople,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom #nss_base_passwd ou=3DPeople,dc=3Dexample,dc=3Dcom?one #nss_base_shadow ou=3DPeople,dc=3Dexample,dc=3Dcom?one #nss_base_group ou=3DGroup,dc=3Dexample,dc=3Dcom?one #nss_base_group ou=3DGroups,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom #nss_base_hosts ou=3DHosts,dc=3Dexample,dc=3Dcom?one #nss_base_services ou=3DServices,dc=3Dexample,dc=3Dcom?one #nss_base_networks ou=3DNetworks,dc=3Dexample,dc=3Dcom?one #nss_base_protocols ou=3DProtocols,dc=3Dexample,dc=3Dcom?one #nss_base_rpc ou=3DRpc,dc=3Dexample,dc=3Dcom?one #nss_base_ethers ou=3DEthers,dc=3Dexample,dc=3Dcom?one #nss_base_netmasks ou=3DNetworks,dc=3Dexample,dc=3Dcom?ne #nss_base_bootparams ou=3DEthers,dc=3Dexample,dc=3Dcom?one #nss_base_aliases ou=3DAliases,dc=3Dexample,dc=3Dcom?one #nss_base_netgroup ou=3DNetgroup,dc=3Dexample,dc=3Dcom?one # attribute/objectclass mapping # Syntax: #nss_map_attribute rfc2307attribute mapped_attribute #nss_map_objectclass rfc2307objectclass mapped_objectclass # configure --enable-nds is no longer supported. # For NDS now do: #nss_map_attribute uniqueMember member # configure --enable-mssfu-schema is no longer supported. # For MSSFU now do: #nss_map_objectclass posixAccount User #nss_map_attribute uid msSFUName #nss_map_attribute uniqueMember posixMember #nss_map_attribute userPassword msSFUPassword #nss_map_attribute homeDirectory msSFUHomeDirectory #nss_map_objectclass posixGroup Group #pam_login_attribute msSFUName #pam_filter objectclass=3DUser #pam_password ad # configure --enable-authpassword is no longer supported # For authPassword support, now do: #nss_map_attribute userPassword authPassword #pam_password nds # For IBM SecureWay support, do: #nss_map_objectclass posixAccount aixAccount #nss_map_attribute uid userName #nss_map_attribute gidNumber gid #nss_map_attribute uidNumber uid #nss_map_attribute userPassword passwordChar #nss_map_objectclass posixGroup aixAccessGroup #nss_map_attribute cn dublx09 #nss_map_attribute memberUid member #pam_login_attribute userName #pam_filter objectclass=3DaixAccount #pam_password clear # Netscape SDK LDAPS #ssl on # Netscape SDK SSL options #sslpath /etc/ssl/certs/cert7.db # OpenLDAP SSL mechanism # start_tls mechanism uses the normal LDAP port, LDAPS typically 636 #ssl start_tls #ssl on # OpenLDAP SSL options # Require and verify server certificate (yes/no) # Default is "no" #tls_checkpeer yes # CA certificates for server certificate verification # At least one of these are required if tls_checkpeer is "yes" #tls_cacertfile /etc/ssl/ca.cert #tls_cacertdir /etc/ssl/certs # Seed the PRNG if /dev/urandom is not provided #tls_randfile /var/run/egd-pool # SSL cipher suite # See man ciphers for syntax #tls_ciphers TLSv1 # Client certificate and key # Use these, if your server requires client authentication. #tls_cert #tls_key ssl no -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Friday, February 17, 2006 9:02 AM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan That file should already exist somewhere under /etc on your system. It may = be called something different too, like pam_ldap.conf - Jamie -----Original Message----- From: "Khan, Mohammed [SMO]" <MK...@fr...> Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan Date: Fri 17 Feb 2006 4:21 pm Size: 2K To: <web...@li...> I don't have that file so shall I create these files, just fyi my server li= nux AS2.1. If I do what shall I put in the file. -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Thursday, February 16, 2006 5:26 PM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Make sure that in your PAM LDAP config file (/etc/pam_ldap/auth_ldap.conf on my system) that the binddn and rootbinddn parameters are set to your LDAP administration user, and that the passwords in the bindpw parameter and /etc/ldap.secret file are set to match. Otherwise PAM will connect to LDAP as the user who is changing his password, which will generally not be allow= ed. - Jamie On 17/Feb/2006 11:43 Khan, Mohammed [SMO] wrote .. > Jamie, now i am getting this error: > Feb 16 16:36:29 dublx09 l/usermin/changepass/changepass.cgi: pam_ldap: > error trying to bind as user "uid=3Dmkhan,ou=3DPeople, dc=3Dnoam,dc=3Dcor= p,dc=3Dfrk,dc=3Dcom" > (Invalid credentials) >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Friday, February 17, 2006 2:10 AM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Hi, > That looks OK.. > Can LDAP users use the command-line passwd command to change their passwo= rds? >=20 > - Jamie >=20 > -----Original Message----- >=20 > From: "Khan, Mohammed [SMO]" <MK...@fr...> > Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan > Date: Fri 17 Feb 2006 10:07 am > Size: 2K > To: <web...@li...> >=20 > Hi Jamie, > Here is my passwd file: Pls tell me what I am doing worng. > #%PAM-1.0 > password required pam_cracklib.so > password sufficient pam_ldap.so > password sufficient pam_unix.so > password required pam_deny.so >=20 >=20 >=20 > Thanks > Mohammed >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:46 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that > Usermin's > Change Password module is setup to use PAM. >=20 > - Jamie >=20 > On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > > Hello Jamie,=20 > > Do you know how can I use usermin to change my ldap password. Please > need > > your help. > >=20 > > Thanks > > Mohammed > >=20 --- message truncated --- ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D103432&bid=3D230486&dat=3D1= 21642 - Forwarded by the Webmin mailing list at web...@li... To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list Notice: All email and instant messages (including attachments) sent to or from Franklin Templeton Investments (FTI) personnel may be retained, monitored and/or reviewed by FTI and its agents, or authorized law enforcement personnel, without further notice or consent. |
|
From: Jamie C. <jca...@we...> - 2006-02-17 23:44:46
|
Hi Dave,
You are absolutely correct .. that is a bug in Webmin, and your change fixes it. I didn't notice it myself as I don't usually have that module setup to force the admin to re-enter the old password when changing..
- Jamie
-----Original Message-----
From: Dave Isaacs <dav...@en...>
Subj: RE: [webmin-l] Change Password error
Date: Sat 18 Feb 2006 2:43 am
Size: 2K
To: "'web...@li...'" <web...@li...>
I think I found the problem.
Below is a snippet from passwd/save_passwd.cgi (shown with line numbers).
Note line 70, where $user gets assigned. I think this line should be up at
line 55. If I compare this version of save_passwd.cgi to one from an older
version of Webmin (v1.170 to be specific), in the older version the code to
assign $user does occur before the "# Validate inputs" comment.
I tried moving line 70 to line 55 as described above, and the problem I was
having validating the old password went away.
Unfortunately this did not fix my original problem (the "Failed to encrypt
password" error), so the tweak to the unix_crypt() subroutine you described
is still necessary.
53 # Update the config files directly via the useradmin module
54 &foreign_require("useradmin", "user-lib.pl");
55
56 # Validate inputs
57 if ($access{'old'} == 1 ||
58 $access{'old'} == 2 && $user->{'user'} ne $remote_user)
{
59 &unix_crypt($in{'old'}, $user->{'pass'}) eq
$user->{'pass'} ||
60 &error($text{'passwd_eold'});
61 }
62 if ($access{'repeat'}) {
63 $in{'new'} eq $in{'repeat'} ||
&error($text{'passwd_erepeat'});
64 }
65 $err = &useradmin::check_password_restrictions(
66 $in{'new'}, $in{'user'});
67 &error($err) if ($err);
68
69 # Find the user, either in local password file or LDAP
70 $user = &find_user($in{'user'});
71
72 if ($user) {
73 &can_edit_passwd([ $user->{'user'}, $user->{'pass'},
74 $user->{'uid'}, $user->{'gid'} ])
||
75 &error($text{'passwd_ecannot'});
76
77 # Actually do the change
78 &change_password($user, $in{'new'},
79 $access{'others'} == 1 ||
80 $access{'others'} == 2 && $in{'others'});
81 }
82 else {
83 &error($text{'passwd_euser'});
84 }
85 delete($user->{'plainpass'});
86 delete($user->{'pass'});
87 &webmin_log("passwd", undef, $user->{'user'}, $user);
88 }
Thanks
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...] On Behalf Of Dave Isaacs
Sent: Friday, February 17, 2006 10:10 AM
To: 'web...@li...'
Subject: RE: [webmin-l] Change Password error
Here is the line from /etc/shadow
entconfig:FTtGqKpdrEpjg:13196:0:99999:7:::
In Users and Groups, the Pre-encrypted password shows up as FTtGqKpdrEpjg.
Thanks
Dave I
--- message truncated ---
|
|
From: Khan, M. [SMO] <MK...@fr...> - 2006-02-17 18:54:48
|
Morning Jamie, I am attaching my ldap.conf file please check and let me know what I am do= ing wrong. If I an able the bindpw I am not able to login to usermin. Pl= ease check if the way I have set it up is correct. Do I create a file /etc= /ldap.secret and copy the line from ldap.conf file. Please let me know # @(#)$Id: ldap.conf,v 1.27 2003/01/17 21:37:12 lukeh Exp $ # # This is the configuration file for the LDAP nameservice # switch library and the LDAP PAM module. # # PADL Software # http://www.padl.com # # Your LDAP server. Must be resolvable without using LDAP. # Multiple hosts may be specified, each separated by a # space. How long nss_ldap takes to failover depends on # whether your LDAP client library supports configurable # network or connect timeouts (see bind_timelimit). #host 127.0.0.1 host dublx06.noam.corp.frk.com # The distinguished name of the search base. #base dc=3Dexample,dc=3Dcom #base dc=3Dpeople,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom base dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom # Another way to specify your LDAP server is to provide an # uri with the server name. This allows to use # Unix Domain Sockets to connect to a local LDAP Server. #uri ldap://127.0.0.1/ #uri ldaps://127.0.0.1/ #uri ldapi://%2fvar%2frun%2fldapi_sock/ # Note: %2f encodes the '/' used as directory separator # The LDAP version to use (defaults to 3 # if supported by client library) ldap_version 3 # The distinguished name to bind to the server with. # Optional: default is to bind anonymously. #binddn cn=3Dproxyuser,dc=3Dexample,dc=3Dcom #binddn cn=3DDirectory Manager # The credentials to bind with. # Optional: default is no credential. bindpw secret # The distinguished name to bind to the server with # if the effective user ID is root. Password is # stored in /etc/ldap.secret (mode 600) #rootbinddn cn=3Dmanager,dc=3Dexample,dc=3Dcom rootbinddn cn=3DDirectory Manager # The port. # Optional: default is 389. #port 389 # The search scope. #scope sub #scope one #scope base # Search timelimit #timelimit 30 # Bind timelimit #bind_timelimit 30 # Idle timelimit; client will close connections # (nss_ldap only) if the server has not been contacted # for the number of seconds specified below. #idle_timelimit 3600 # Filter to AND with uid=3D%s #pam_filter objectclass=3Daccount pam_filter objectclass=3DposixAccount # The user ID attribute (defaults to uid) pam_login_attribute uid # Search the root DSE for the password policy (works # with Netscape Directory Server) #pam_lookup_policy yes # Check the 'host' attribute for access control # Default is no; if set to yes, and user has no # value for the host attribute, and pam_ldap is # configured for account management (authorization) # then the user will not be allowed to login. #pam_check_host_attr yes # Group to enforce membership of #pam_groupdn cn=3DPAM,ou=3DGroups,dc=3Dexample,dc=3Dcom pam_groupdn cn=3DTestGroup,ou=3DGroups,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom #pam_groupdn cn=3Ddublx09,ou=3DGroups,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom # Group member attribute #pam_member_attribute uniquemember pam_member_attribute memberUid # Specify a minium or maximum UID number allowed #pam_min_uid 0 #pam_max_uid 0 # Template login attribute, default template user # (can be overriden by value of former attribute # in user's entry) #pam_login_attribute userPrincipalName #pam_template_login_attribute uid #pam_template_login nobody # HEADS UP: the pam_crypt, pam_nds_passwd, # and pam_ad_passwd options are no # longer supported. # Do not hash the password at all; presume # the directory server will do it, if # necessary. This is the default. #pam_password clear # Hash password locally; required for University of # Michigan LDAP server, and works with Netscape # Directory Server if you're using the UNIX-Crypt # hash mechanism and not using the NT Synchronization # service. #pam_password crypt # Remove old password first, then update in # cleartext. Necessary for use with Novell # Directory Services (NDS) #pam_password nds # Update Active Directory password, by # creating Unicode password and updating # unicodePwd attribute. #pam_password ad # Use the OpenLDAP password change # extended operation to update the password. #pam_password exop #pam_password crypt # Redirect users to a URL or somesuch on password # changes. #pam_password_prohibit_message Please visit http://internal to change your = password. # RFC2307bis naming contexts # Syntax: # nss_base_XXX base?scope?filter # where scope is {base,one,sub} # and filter is a filter to be &'d with the # default filter. # You can omit the suffix eg: # nss_base_passwd ou=3DPeople, # to append the default base DN but this # may incur a small performance impact. #nss_base_passwd ou=3DPeople,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom #nss_base_shadow ou=3DPeople,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom #nss_base_passwd ou=3DPeople,dc=3Dexample,dc=3Dcom?one #nss_base_shadow ou=3DPeople,dc=3Dexample,dc=3Dcom?one #nss_base_group ou=3DGroup,dc=3Dexample,dc=3Dcom?one #nss_base_group ou=3DGroups,dc=3Dnoam,dc=3Dcorp,dc=3Dfrk,dc=3Dcom #nss_base_hosts ou=3DHosts,dc=3Dexample,dc=3Dcom?one #nss_base_services ou=3DServices,dc=3Dexample,dc=3Dcom?one #nss_base_networks ou=3DNetworks,dc=3Dexample,dc=3Dcom?one #nss_base_protocols ou=3DProtocols,dc=3Dexample,dc=3Dcom?one #nss_base_rpc ou=3DRpc,dc=3Dexample,dc=3Dcom?one #nss_base_ethers ou=3DEthers,dc=3Dexample,dc=3Dcom?one #nss_base_netmasks ou=3DNetworks,dc=3Dexample,dc=3Dcom?ne #nss_base_bootparams ou=3DEthers,dc=3Dexample,dc=3Dcom?one #nss_base_aliases ou=3DAliases,dc=3Dexample,dc=3Dcom?one #nss_base_netgroup ou=3DNetgroup,dc=3Dexample,dc=3Dcom?one # attribute/objectclass mapping # Syntax: #nss_map_attribute rfc2307attribute mapped_attribute #nss_map_objectclass rfc2307objectclass mapped_objectclass # configure --enable-nds is no longer supported. # For NDS now do: #nss_map_attribute uniqueMember member # configure --enable-mssfu-schema is no longer supported. # For MSSFU now do: #nss_map_objectclass posixAccount User #nss_map_attribute uid msSFUName #nss_map_attribute uniqueMember posixMember #nss_map_attribute userPassword msSFUPassword #nss_map_attribute homeDirectory msSFUHomeDirectory #nss_map_objectclass posixGroup Group #pam_login_attribute msSFUName #pam_filter objectclass=3DUser #pam_password ad # configure --enable-authpassword is no longer supported # For authPassword support, now do: #nss_map_attribute userPassword authPassword #pam_password nds # For IBM SecureWay support, do: #nss_map_objectclass posixAccount aixAccount #nss_map_attribute uid userName #nss_map_attribute gidNumber gid #nss_map_attribute uidNumber uid #nss_map_attribute userPassword passwordChar #nss_map_objectclass posixGroup aixAccessGroup #nss_map_attribute cn dublx09 #nss_map_attribute memberUid member #pam_login_attribute userName #pam_filter objectclass=3DaixAccount #pam_password clear # Netscape SDK LDAPS #ssl on # Netscape SDK SSL options #sslpath /etc/ssl/certs/cert7.db # OpenLDAP SSL mechanism # start_tls mechanism uses the normal LDAP port, LDAPS typically 636 #ssl start_tls #ssl on # OpenLDAP SSL options # Require and verify server certificate (yes/no) # Default is "no" #tls_checkpeer yes # CA certificates for server certificate verification # At least one of these are required if tls_checkpeer is "yes" #tls_cacertfile /etc/ssl/ca.cert #tls_cacertdir /etc/ssl/certs # Seed the PRNG if /dev/urandom is not provided #tls_randfile /var/run/egd-pool # SSL cipher suite # See man ciphers for syntax #tls_ciphers TLSv1 # Client certificate and key # Use these, if your server requires client authentication. #tls_cert #tls_key ssl no -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Friday, February 17, 2006 9:02 AM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan That file should already exist somewhere under /etc on your system. It may = be called something different too, like pam_ldap.conf - Jamie -----Original Message----- From: "Khan, Mohammed [SMO]" <MK...@fr...> Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan Date: Fri 17 Feb 2006 4:21 pm Size: 2K To: <web...@li...> I don't have that file so shall I create these files, just fyi my server li= nux AS2.1. If I do what shall I put in the file. -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Thursday, February 16, 2006 5:26 PM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Make sure that in your PAM LDAP config file (/etc/pam_ldap/auth_ldap.conf on my system) that the binddn and rootbinddn parameters are set to your LDAP administration user, and that the passwords in the bindpw parameter and /etc/ldap.secret file are set to match. Otherwise PAM will connect to LDAP as the user who is changing his password, which will generally not be allow= ed. - Jamie On 17/Feb/2006 11:43 Khan, Mohammed [SMO] wrote .. > Jamie, now i am getting this error: > Feb 16 16:36:29 dublx09 l/usermin/changepass/changepass.cgi: pam_ldap: > error trying to bind as user "uid=3Dmkhan,ou=3DPeople, dc=3Dnoam,dc=3Dcor= p,dc=3Dfrk,dc=3Dcom" > (Invalid credentials) >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Friday, February 17, 2006 2:10 AM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Hi, > That looks OK.. > Can LDAP users use the command-line passwd command to change their passwo= rds? >=20 > - Jamie >=20 > -----Original Message----- >=20 > From: "Khan, Mohammed [SMO]" <MK...@fr...> > Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan > Date: Fri 17 Feb 2006 10:07 am > Size: 2K > To: <web...@li...> >=20 > Hi Jamie, > Here is my passwd file: Pls tell me what I am doing worng. > #%PAM-1.0 > password required pam_cracklib.so > password sufficient pam_ldap.so > password sufficient pam_unix.so > password required pam_deny.so >=20 >=20 >=20 > Thanks > Mohammed >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:46 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that > Usermin's > Change Password module is setup to use PAM. >=20 > - Jamie >=20 > On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > > Hello Jamie,=20 > > Do you know how can I use usermin to change my ldap password. Please > need > > your help. > >=20 > > Thanks > > Mohammed > >=20 --- message truncated --- ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D103432&bid=3D230486&dat=3D1= 21642 - Forwarded by the Webmin mailing list at web...@li... To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list Notice: All email and instant messages (including attachments) sent to or from Franklin Templeton Investments (FTI) personnel may be retained, monitored and/or reviewed by FTI and its agents, or authorized law enforcement personnel, without further notice or consent. |
|
From: Dave I. <dav...@en...> - 2006-02-17 16:07:49
|
Correction. The change I outlined below *does* fix both my original problem
and the follow-up problem. So the tweak to unix_crypt() is *not* necessary.
Cheers
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...] On Behalf Of Dave Isaacs
Sent: Friday, February 17, 2006 10:42 AM
To: 'web...@li...'
Subject: RE: [webmin-l] Change Password error
I think I found the problem.
Below is a snippet from passwd/save_passwd.cgi (shown with line numbers).
Note line 70, where $user gets assigned. I think this line should be up at
line 55. If I compare this version of save_passwd.cgi to one from an older
version of Webmin (v1.170 to be specific), in the older version the code to
assign $user does occur before the "# Validate inputs" comment.
I tried moving line 70 to line 55 as described above, and the problem I was
having validating the old password went away.
Unfortunately this did not fix my original problem (the "Failed to encrypt
password" error), so the tweak to the unix_crypt() subroutine you described
is still necessary.
53 # Update the config files directly via the useradmin module
54 &foreign_require("useradmin", "user-lib.pl");
55
56 # Validate inputs
57 if ($access{'old'} == 1 ||
58 $access{'old'} == 2 && $user->{'user'} ne $remote_user)
{
59 &unix_crypt($in{'old'}, $user->{'pass'}) eq
$user->{'pass'} ||
60 &error($text{'passwd_eold'});
61 }
62 if ($access{'repeat'}) {
63 $in{'new'} eq $in{'repeat'} ||
&error($text{'passwd_erepeat'});
64 }
65 $err = &useradmin::check_password_restrictions(
66 $in{'new'}, $in{'user'});
67 &error($err) if ($err);
68
69 # Find the user, either in local password file or LDAP
70 $user = &find_user($in{'user'});
71
72 if ($user) {
73 &can_edit_passwd([ $user->{'user'}, $user->{'pass'},
74 $user->{'uid'}, $user->{'gid'} ])
||
75 &error($text{'passwd_ecannot'});
76
77 # Actually do the change
78 &change_password($user, $in{'new'},
79 $access{'others'} == 1 ||
80 $access{'others'} == 2 && $in{'others'});
81 }
82 else {
83 &error($text{'passwd_euser'});
84 }
85 delete($user->{'plainpass'});
86 delete($user->{'pass'});
87 &webmin_log("passwd", undef, $user->{'user'}, $user);
88 }
Thanks
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...] On Behalf Of Dave Isaacs
Sent: Friday, February 17, 2006 10:10 AM
To: 'web...@li...'
Subject: RE: [webmin-l] Change Password error
Here is the line from /etc/shadow
entconfig:FTtGqKpdrEpjg:13196:0:99999:7:::
In Users and Groups, the Pre-encrypted password shows up as FTtGqKpdrEpjg.
Thanks
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...
<mailto:web...@li...> ] On Behalf Of Jamie
Cameron
Sent: Friday, February 17, 2006 3:57 AM
To: web...@li...
Subject: RE: [webmin-l] Change Password error
Hi Dave,
That is definately a bug..
What does the user in question have in the password field of his entry in
/etc/passwd or /etc/shadow? Or more importantly, if you edit him in the
Users and Groups module, does his encrypted password show up properly?
- Jamie
-----Original Message-----
From: Dave Isaacs <dav...@en...>
Subj: RE: [webmin-l] Change Password error
Date: Fri 17 Feb 2006 6:53 am
Size: 2K
To: "'web...@li...'"
<web...@li...>
Sorry, I have to take that back. This doesn't work.
Yes, it allows me to change the password, but now I can put anything in the
"Old Password" field and have it work. That's bad.
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...
<mailto:web...@li...> ] On Behalf Of Dave
Isaacs
Sent: Wednesday, February 15, 2006 6:23 PM
To: 'web...@li...'
Subject: RE: [webmin-l] Change Password error
That works. Thanks!
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...
<mailto:web...@li...>
<mailto:web...@li...
<mailto:web...@li...> > ] On Behalf Of Jamie
Cameron
Sent: Wednesday, February 15, 2006 6:09 PM
To: web...@li...
Subject: RE: [webmin-l] Change Password error
Hi Dave,
Basically, all I did was change the function unix_crypt in the file
web-lib-funcs.pl to:
# unix_crypt(password, salt)
# Performs Unix encryption on a password, using crypt() or Crypt::UnixCrypt
sub unix_crypt { local ($pass, $salt) = @_;
return "" if (!$salt); # same as real crypt
local $rv = eval "crypt(\$pass, \$salt)";
local $err = $@;
return $rv if ($rv && !$@);
eval "use Crypt::UnixCrypt";
if (!$@) {
return Crypt::UnixCrypt::crypt($pass, $salt);
}
else {
&error("Failed to encrypt password : $err");
}
}
You could do the same thing by directly editing that file in your copy of
Webmin.
- Jamie
On 16/Feb/2006 00:54 Dave Isaacs wrote ..
> Is it possible to give me details (or at least hints) of what need to
> be fixed? I have to deliver a production system by the end of the
> month and I have no working change password feature.
>
> Thanks
>
> Dave I
>
> -----Original Message-----
> From: web...@li...
> [mailto:web...@li...
<mailto:web...@li...>
<mailto:web...@li...
<mailto:web...@li...> > ] On Behalf Of Jamie
> Cameron
> Sent: Tuesday, February 14, 2006 6:39 PM
> To: web...@li...
> Subject: RE: [webmin-l] Change Password error
>
>
> There is another way it could happen - but I will deal with that in
--- message truncated ---
-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems? Stop! Download the new AJAX search engine that makes
searching your log files as easy as surfing the web. DOWNLOAD SPLUNK!
http://sel.as-us.falkag.net/sel?cmd=lnk
<http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642>
&kid=103432&bid=230486&dat=121642
-
Forwarded by the Webmin mailing list at web...@li...
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
<http://lists.sourceforge.net/lists/listinfo/webadmin-list>
|
|
From: Dave I. <dav...@en...> - 2006-02-17 15:42:40
|
I think I found the problem.
Below is a snippet from passwd/save_passwd.cgi (shown with line numbers).
Note line 70, where $user gets assigned. I think this line should be up at
line 55. If I compare this version of save_passwd.cgi to one from an older
version of Webmin (v1.170 to be specific), in the older version the code to
assign $user does occur before the "# Validate inputs" comment.
I tried moving line 70 to line 55 as described above, and the problem I was
having validating the old password went away.
Unfortunately this did not fix my original problem (the "Failed to encrypt
password" error), so the tweak to the unix_crypt() subroutine you described
is still necessary.
53 # Update the config files directly via the useradmin module
54 &foreign_require("useradmin", "user-lib.pl");
55
56 # Validate inputs
57 if ($access{'old'} == 1 ||
58 $access{'old'} == 2 && $user->{'user'} ne $remote_user)
{
59 &unix_crypt($in{'old'}, $user->{'pass'}) eq
$user->{'pass'} ||
60 &error($text{'passwd_eold'});
61 }
62 if ($access{'repeat'}) {
63 $in{'new'} eq $in{'repeat'} ||
&error($text{'passwd_erepeat'});
64 }
65 $err = &useradmin::check_password_restrictions(
66 $in{'new'}, $in{'user'});
67 &error($err) if ($err);
68
69 # Find the user, either in local password file or LDAP
70 $user = &find_user($in{'user'});
71
72 if ($user) {
73 &can_edit_passwd([ $user->{'user'}, $user->{'pass'},
74 $user->{'uid'}, $user->{'gid'} ])
||
75 &error($text{'passwd_ecannot'});
76
77 # Actually do the change
78 &change_password($user, $in{'new'},
79 $access{'others'} == 1 ||
80 $access{'others'} == 2 && $in{'others'});
81 }
82 else {
83 &error($text{'passwd_euser'});
84 }
85 delete($user->{'plainpass'});
86 delete($user->{'pass'});
87 &webmin_log("passwd", undef, $user->{'user'}, $user);
88 }
Thanks
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...] On Behalf Of Dave Isaacs
Sent: Friday, February 17, 2006 10:10 AM
To: 'web...@li...'
Subject: RE: [webmin-l] Change Password error
Here is the line from /etc/shadow
entconfig:FTtGqKpdrEpjg:13196:0:99999:7:::
In Users and Groups, the Pre-encrypted password shows up as FTtGqKpdrEpjg.
Thanks
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...
<mailto:web...@li...> ] On Behalf Of Jamie
Cameron
Sent: Friday, February 17, 2006 3:57 AM
To: web...@li...
Subject: RE: [webmin-l] Change Password error
Hi Dave,
That is definately a bug..
What does the user in question have in the password field of his entry in
/etc/passwd or /etc/shadow? Or more importantly, if you edit him in the
Users and Groups module, does his encrypted password show up properly?
- Jamie
-----Original Message-----
From: Dave Isaacs <dav...@en...>
Subj: RE: [webmin-l] Change Password error
Date: Fri 17 Feb 2006 6:53 am
Size: 2K
To: "'web...@li...'"
<web...@li...>
Sorry, I have to take that back. This doesn't work.
Yes, it allows me to change the password, but now I can put anything in the
"Old Password" field and have it work. That's bad.
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...
<mailto:web...@li...> ] On Behalf Of Dave
Isaacs
Sent: Wednesday, February 15, 2006 6:23 PM
To: 'web...@li...'
Subject: RE: [webmin-l] Change Password error
That works. Thanks!
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...
<mailto:web...@li...>
<mailto:web...@li...
<mailto:web...@li...> > ] On Behalf Of Jamie
Cameron
Sent: Wednesday, February 15, 2006 6:09 PM
To: web...@li...
Subject: RE: [webmin-l] Change Password error
Hi Dave,
Basically, all I did was change the function unix_crypt in the file
web-lib-funcs.pl to:
# unix_crypt(password, salt)
# Performs Unix encryption on a password, using crypt() or Crypt::UnixCrypt
sub unix_crypt { local ($pass, $salt) = @_;
return "" if (!$salt); # same as real crypt
local $rv = eval "crypt(\$pass, \$salt)";
local $err = $@;
return $rv if ($rv && !$@);
eval "use Crypt::UnixCrypt";
if (!$@) {
return Crypt::UnixCrypt::crypt($pass, $salt);
}
else {
&error("Failed to encrypt password : $err");
}
}
You could do the same thing by directly editing that file in your copy of
Webmin.
- Jamie
On 16/Feb/2006 00:54 Dave Isaacs wrote ..
> Is it possible to give me details (or at least hints) of what need to
> be fixed? I have to deliver a production system by the end of the
> month and I have no working change password feature.
>
> Thanks
>
> Dave I
>
> -----Original Message-----
> From: web...@li...
> [mailto:web...@li...
<mailto:web...@li...>
<mailto:web...@li...
<mailto:web...@li...> > ] On Behalf Of Jamie
> Cameron
> Sent: Tuesday, February 14, 2006 6:39 PM
> To: web...@li...
> Subject: RE: [webmin-l] Change Password error
>
>
> There is another way it could happen - but I will deal with that in
--- message truncated ---
-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems? Stop! Download the new AJAX search engine that makes
searching your log files as easy as surfing the web. DOWNLOAD SPLUNK!
http://sel.as-us.falkag.net/sel?cmd=lnk
<http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642>
&kid=103432&bid=230486&dat=121642
-
Forwarded by the Webmin mailing list at web...@li...
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
<http://lists.sourceforge.net/lists/listinfo/webadmin-list>
|
|
From: Dave I. <dav...@en...> - 2006-02-17 15:09:53
|
Here is the line from /etc/shadow
entconfig:FTtGqKpdrEpjg:13196:0:99999:7:::
In Users and Groups, the Pre-encrypted password shows up as FTtGqKpdrEpjg.
Thanks
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...] On Behalf Of Jamie
Cameron
Sent: Friday, February 17, 2006 3:57 AM
To: web...@li...
Subject: RE: [webmin-l] Change Password error
Hi Dave,
That is definately a bug..
What does the user in question have in the password field of his entry in
/etc/passwd or /etc/shadow? Or more importantly, if you edit him in the
Users and Groups module, does his encrypted password show up properly?
- Jamie
-----Original Message-----
From: Dave Isaacs <dav...@en...>
Subj: RE: [webmin-l] Change Password error
Date: Fri 17 Feb 2006 6:53 am
Size: 2K
To: "'web...@li...'"
<web...@li...>
Sorry, I have to take that back. This doesn't work.
Yes, it allows me to change the password, but now I can put anything in the
"Old Password" field and have it work. That's bad.
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...] On Behalf Of Dave Isaacs
Sent: Wednesday, February 15, 2006 6:23 PM
To: 'web...@li...'
Subject: RE: [webmin-l] Change Password error
That works. Thanks!
Dave I
-----Original Message-----
From: web...@li...
[mailto:web...@li...
<mailto:web...@li...> ] On Behalf Of Jamie
Cameron
Sent: Wednesday, February 15, 2006 6:09 PM
To: web...@li...
Subject: RE: [webmin-l] Change Password error
Hi Dave,
Basically, all I did was change the function unix_crypt in the file
web-lib-funcs.pl to:
# unix_crypt(password, salt)
# Performs Unix encryption on a password, using crypt() or Crypt::UnixCrypt
sub unix_crypt { local ($pass, $salt) = @_;
return "" if (!$salt); # same as real crypt
local $rv = eval "crypt(\$pass, \$salt)";
local $err = $@;
return $rv if ($rv && !$@);
eval "use Crypt::UnixCrypt";
if (!$@) {
return Crypt::UnixCrypt::crypt($pass, $salt);
}
else {
&error("Failed to encrypt password : $err");
}
}
You could do the same thing by directly editing that file in your copy of
Webmin.
- Jamie
On 16/Feb/2006 00:54 Dave Isaacs wrote ..
> Is it possible to give me details (or at least hints) of what need to
> be fixed? I have to deliver a production system by the end of the
> month and I have no working change password feature.
>
> Thanks
>
> Dave I
>
> -----Original Message-----
> From: web...@li...
> [mailto:web...@li...
<mailto:web...@li...> ] On Behalf Of Jamie
> Cameron
> Sent: Tuesday, February 14, 2006 6:39 PM
> To: web...@li...
> Subject: RE: [webmin-l] Change Password error
>
>
> There is another way it could happen - but I will deal with that in
--- message truncated ---
-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems? Stop! Download the new AJAX search engine that makes
searching your log files as easy as surfing the web. DOWNLOAD SPLUNK!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642
-
Forwarded by the Webmin mailing list at web...@li...
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
|
|
From: Jamie C. <jca...@we...> - 2006-02-17 10:53:37
|
On 17/Feb/2006 16:49 Murray Trainer wrote .. > Hi Jamie, > > I am testing the LDAP User's and Groups module in 1.2.63 and I am > getting the error below: > > The user was saved successfully in the LDAP database, but an IMAP error > occurred : : Login failed: authentication failure > > It looks like the user and their Cyrus mailbox and LDAP addressbook are > being created OK. I did the tests below after creating the user which > confirm that they can authenticate to Cyrus OK. Not sure why the > authentication is failing? It seems to be OK shortly afterwards. Hi Murray, Are you seeing this when adding a new user with IMAP, or only when enabling it for an existing user? - Jamie |
|
From: Jamie C. <jca...@we...> - 2006-02-17 10:47:46
|
On 17/Feb/2006 17:09 Murray Trainer wrote .. > Hi Jamie, > > More testing shows that when I save an LDAP user with default LDAP > groups they appear as they should in the secondary groups list box on > the Add User screen but when the user is saved they are not added to the > appropriate LDAP groups. I tried it with a single word group name and > still have the problem. This might be a side-effect of the fix you did > to support groups with spaces like "Domain Users". That is odd, I am not seeing this on my system, even if I use groups with or without spaces in them. Are the groups selected when you add the user? Can you add the groups later when you re-edit the user? - Jamie |
|
From: Murray T. <mtr...@ce...> - 2006-02-17 06:09:25
|
Hi Jamie, More testing shows that when I save an LDAP user with default LDAP groups they appear as they should in the secondary groups list box on the Add User screen but when the user is saved they are not added to the appropriate LDAP groups. I tried it with a single word group name and still have the problem. This might be a side-effect of the fix you did to support groups with spaces like "Domain Users". Murray |
|
From: Jamie C. <jca...@we...> - 2006-02-17 06:03:48
|
That file should already exist somewhere under /etc on your system. It may be called something different too, like pam_ldap.conf - Jamie -----Original Message----- From: "Khan, Mohammed [SMO]" <MK...@fr...> Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan Date: Fri 17 Feb 2006 4:21 pm Size: 2K To: <web...@li...> I don't have that file so shall I create these files, just fyi my server linux AS2.1. If I do what shall I put in the file. -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Thursday, February 16, 2006 5:26 PM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Make sure that in your PAM LDAP config file (/etc/pam_ldap/auth_ldap.conf on my system) that the binddn and rootbinddn parameters are set to your LDAP administration user, and that the passwords in the bindpw parameter and /etc/ldap.secret file are set to match. Otherwise PAM will connect to LDAP as the user who is changing his password, which will generally not be allowed. - Jamie On 17/Feb/2006 11:43 Khan, Mohammed [SMO] wrote .. > Jamie, now i am getting this error: > Feb 16 16:36:29 dublx09 l/usermin/changepass/changepass.cgi: pam_ldap: > error trying to bind as user "uid=mkhan,ou=People, dc=noam,dc=corp,dc=frk,dc=com" > (Invalid credentials) > > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Friday, February 17, 2006 2:10 AM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > Hi, > That looks OK.. > Can LDAP users use the command-line passwd command to change their passwords? > > - Jamie > > -----Original Message----- > > From: "Khan, Mohammed [SMO]" <MK...@fr...> > Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan > Date: Fri 17 Feb 2006 10:07 am > Size: 2K > To: <web...@li...> > > Hi Jamie, > Here is my passwd file: Pls tell me what I am doing worng. > #%PAM-1.0 > password required pam_cracklib.so > password sufficient pam_ldap.so > password sufficient pam_unix.so > password required pam_deny.so > > > > Thanks > Mohammed > > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:46 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that > Usermin's > Change Password module is setup to use PAM. > > - Jamie > > On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > > Hello Jamie, > > Do you know how can I use usermin to change my ldap password. Please > need > > your help. > > > > Thanks > > Mohammed > > --- message truncated --- |
|
From: Murray T. <mtr...@ce...> - 2006-02-17 05:56:50
|
On Tue, 2006-02-14 at 19:02, Jamie Cameron wrote: > On 14/Feb/2006 18:47 Murray Trainer wrote .. > > Hi Jamie, > > > > I am trying out Webmin 1.260 and get the error below when I use the > > Delete Selected Users button. It works fine deleting users individually > > the normal way. > > > > Murray > > > > Deleting user test4 .. > > Deleting from other modules .. > > .. done > > > > Deleting LDAP user entry .. > > .. done > > > > Removing from groups .. > > .. done > > > > Deleting from addressbook .. > > HTTP/1.0 500 Perl execution failed Server: MiniServ/0.01 Date: > > Tue, 14 Feb 2006 07:43:35 GMT Content-type: text/html > > Connection: close > > > > > > Error - Perl execution failed > > Can't call method "delete" on an undefined value at /opt/webmin/ldap-useradmin/mass_delete_user.cgi > > line 203. > > This is a known bug in Webmin 1.260. However, it is fixed in the 1.263 development version, > available from http://www.webmin.com/devel.html Hi Jamie, My testing confirms this issue does appear to be fixed 1.2.63. Thanks Murray |
|
From: Murray T. <mtr...@ce...> - 2006-02-17 05:49:18
|
Hi Jamie, I am testing the LDAP User's and Groups module in 1.2.63 and I am getting the error below: The user was saved successfully in the LDAP database, but an IMAP error occurred : : Login failed: authentication failure It looks like the user and their Cyrus mailbox and LDAP addressbook are being created OK. I did the tests below after creating the user which confirm that they can authenticate to Cyrus OK. Not sure why the authentication is failing? It seems to be OK shortly afterwards. Murray # telnet imap.mydomain.net imap Trying 192.168.245.61... Connected to imap.mydomain.net. Escape character is '^]'. * OK ldap Cyrus IMAP4 v2.2.12 server ready . login mtrainer password . OK User logged in . logout * BYE LOGOUT received . OK Completed Connection closed by foreign host. # imtest -a mtrainer imap.mydomain.net S: * OK ldap Cyrus IMAP4 v2.2.12 server ready C: C01 CAPABILITY S: * CAPABILITY IMAP4 IMAP4rev1 ACL QUOTA LITERAL+ MAILBOX-REFERRALS NAMESPACE UIDPLUS ID NO_ATOMIC_RENAME UNSELECT CHILDREN MULTIAPPEND BINARY SORT THREAD=ORDEREDSUBJECT THREAD=REFERENCES ANNOTATEMORE IDLE X-NETSCAPE S: C01 OK Completed Please enter your password: C: L01 LOGIN mtrainer {9} S: + go ahead C: <omitted> S: L01 OK User logged in Authenticated. Security strength factor: 0 . logout * BYE LOGOUT received . OK Completed Connection closed. # |
|
From: Khan, M. [SMO] <MK...@fr...> - 2006-02-17 05:20:44
|
I don't have that file so shall I create these files, just fyi my server li= nux AS2.1. If I do what shall I put in the file. -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Thursday, February 16, 2006 5:26 PM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Make sure that in your PAM LDAP config file (/etc/pam_ldap/auth_ldap.conf on my system) that the binddn and rootbinddn parameters are set to your LDAP administration user, and that the passwords in the bindpw parameter and /etc/ldap.secret file are set to match. Otherwise PAM will connect to LDAP as the user who is changing his password, which will generally not be allow= ed. - Jamie On 17/Feb/2006 11:43 Khan, Mohammed [SMO] wrote .. > Jamie, now i am getting this error: > Feb 16 16:36:29 dublx09 l/usermin/changepass/changepass.cgi: pam_ldap: > error trying to bind as user "uid=3Dmkhan,ou=3DPeople, dc=3Dnoam,dc=3Dcor= p,dc=3Dfrk,dc=3Dcom" > (Invalid credentials) >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Friday, February 17, 2006 2:10 AM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Hi, > That looks OK.. > Can LDAP users use the command-line passwd command to change their passwo= rds? >=20 > - Jamie >=20 > -----Original Message----- >=20 > From: "Khan, Mohammed [SMO]" <MK...@fr...> > Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan > Date: Fri 17 Feb 2006 10:07 am > Size: 2K > To: <web...@li...> >=20 > Hi Jamie, > Here is my passwd file: Pls tell me what I am doing worng. > #%PAM-1.0 > password required pam_cracklib.so > password sufficient pam_ldap.so > password sufficient pam_unix.so > password required pam_deny.so >=20 >=20 >=20 > Thanks > Mohammed >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:46 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that > Usermin's > Change Password module is setup to use PAM. >=20 > - Jamie >=20 > On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > > Hello Jamie,=20 > > Do you know how can I use usermin to change my ldap password. Please > need > > your help. > >=20 > > Thanks > > Mohammed > >=20 > > -----Original Message----- > > From: web...@li... > > [mailto:web...@li...]On Behalf Of Jamie > > Cameron > > Sent: Thursday, February 16, 2006 2:28 PM > > To: web...@li... > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > >=20 > >=20 > > Did you set up /etc/pam.d/usermin as well? My last set of instructions > > only > > mentioned /etc/pam.d/webmin , sorry .. > >=20 > > - Jamie > >=20 > > On 17/Feb/2006 09:25 Khan, Mohammed [SMO] wrote .. > > > Hi Jamie,=20 > > > Sorry to bug u sir. I am still getting the same error when login usi= ng > > > ldap user into usermin. Here is error: > > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: check pass; user > unknown > > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: authentication fail= ure; > > > logname=3D uid=3D0 euid=3D0 tty=3D ruser=3D rhost=3D > > >=20 > > > And here is mt .ssh file > > > #%PAM-1.0 > > > auth required /lib/security/pam_securetty.so > > > auth required /lib/security/pam_nologin.so > > > auth required /lib/security/pam_env.so > > > auth sufficient /lib/security/pam_ldap.so > > > auth required /lib/security/pam_unix_auth.so use_first_pass # > set_secrpc > > > account required /lib/security/pam_unix.so > > > account required /lib/security/pam_nologin.so > > > session required /lib/security/pam_unix.so > > > session required /lib/security/pam_limits.so > > >=20 > > >=20 > > > Please lete me know.. > > >=20 > > > Thanks > > >=20 > > > -----Original Message----- > > > From: web...@li... > > > [mailto:web...@li...]On Behalf Of Jamie > > > Cameron > > > Sent: Friday, February 17, 2006 1:04 AM > > > To: web...@li... > > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > >=20 > > >=20 > > > Hi, >=20 > --- message truncated --- >=20 >=20 >=20 >=20 > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through log > files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D103432&bid=3D230486&dat= =3D121642 > - > Forwarded by the Webmin mailing list at web...@li....n= et > To remove yourself from this list, go to > http://lists.sourceforge.net/lists/listinfo/webadmin-list >=20 > Notice: All email and instant messages (including attachments) sent to > or from Franklin Templeton Investments (FTI) personnel may be retained, > monitored and/or reviewed by FTI and its agents, or authorized > law enforcement personnel, without further notice or consent. >=20 >=20 > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through log > files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd- > Forwarded by the Webmin mailing list at web...@li....n= et > To remove yourself from this list, go to > http://lists.sourceforge.net/lists/listinfo/webadmin-list ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D103432&bid=3D230486&dat=3D1= 21642 - Forwarded by the Webmin mailing list at web...@li... To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list Notice: All email and instant messages (including attachments) sent to or from Franklin Templeton Investments (FTI) personnel may be retained, monitored and/or reviewed by FTI and its agents, or authorized law enforcement personnel, without further notice or consent. |
|
From: Jamie C. <jca...@we...> - 2006-02-17 01:25:42
|
Make sure that in your PAM LDAP config file (/etc/pam_ldap/auth_ldap.conf on my system) that the binddn and rootbinddn parameters are set to your LDAP administration user, and that the passwords in the bindpw parameter and /etc/ldap.secret file are set to match. Otherwise PAM will connect to LDAP as the user who is changing his password, which will generally not be allowed. - Jamie On 17/Feb/2006 11:43 Khan, Mohammed [SMO] wrote .. > Jamie, now i am getting this error: > Feb 16 16:36:29 dublx09 l/usermin/changepass/changepass.cgi: pam_ldap: > error trying to bind as user "uid=mkhan,ou=People, dc=noam,dc=corp,dc=frk,dc=com" > (Invalid credentials) > > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Friday, February 17, 2006 2:10 AM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > Hi, > That looks OK.. > Can LDAP users use the command-line passwd command to change their passwords? > > - Jamie > > -----Original Message----- > > From: "Khan, Mohammed [SMO]" <MK...@fr...> > Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan > Date: Fri 17 Feb 2006 10:07 am > Size: 2K > To: <web...@li...> > > Hi Jamie, > Here is my passwd file: Pls tell me what I am doing worng. > #%PAM-1.0 > password required pam_cracklib.so > password sufficient pam_ldap.so > password sufficient pam_unix.so > password required pam_deny.so > > > > Thanks > Mohammed > > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:46 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that > Usermin's > Change Password module is setup to use PAM. > > - Jamie > > On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > > Hello Jamie, > > Do you know how can I use usermin to change my ldap password. Please > need > > your help. > > > > Thanks > > Mohammed > > > > -----Original Message----- > > From: web...@li... > > [mailto:web...@li...]On Behalf Of Jamie > > Cameron > > Sent: Thursday, February 16, 2006 2:28 PM > > To: web...@li... > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > > > > Did you set up /etc/pam.d/usermin as well? My last set of instructions > > only > > mentioned /etc/pam.d/webmin , sorry .. > > > > - Jamie > > > > On 17/Feb/2006 09:25 Khan, Mohammed [SMO] wrote .. > > > Hi Jamie, > > > Sorry to bug u sir. I am still getting the same error when login using > > > ldap user into usermin. Here is error: > > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: check pass; user > unknown > > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: authentication failure; > > > logname= uid=0 euid=0 tty= ruser= rhost= > > > > > > And here is mt .ssh file > > > #%PAM-1.0 > > > auth required /lib/security/pam_securetty.so > > > auth required /lib/security/pam_nologin.so > > > auth required /lib/security/pam_env.so > > > auth sufficient /lib/security/pam_ldap.so > > > auth required /lib/security/pam_unix_auth.so use_first_pass # > set_secrpc > > > account required /lib/security/pam_unix.so > > > account required /lib/security/pam_nologin.so > > > session required /lib/security/pam_unix.so > > > session required /lib/security/pam_limits.so > > > > > > > > > Please lete me know.. > > > > > > Thanks > > > > > > -----Original Message----- > > > From: web...@li... > > > [mailto:web...@li...]On Behalf Of Jamie > > > Cameron > > > Sent: Friday, February 17, 2006 1:04 AM > > > To: web...@li... > > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > > > > > > > Hi, > > --- message truncated --- > > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through log > files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 > - > Forwarded by the Webmin mailing list at web...@li... > To remove yourself from this list, go to > http://lists.sourceforge.net/lists/listinfo/webadmin-list > > Notice: All email and instant messages (including attachments) sent to > or from Franklin Templeton Investments (FTI) personnel may be retained, > monitored and/or reviewed by FTI and its agents, or authorized > law enforcement personnel, without further notice or consent. > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through log > files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd- > Forwarded by the Webmin mailing list at web...@li... > To remove yourself from this list, go to > http://lists.sourceforge.net/lists/listinfo/webadmin-list |
|
From: Khan, M. [SMO] <MK...@fr...> - 2006-02-17 00:43:31
|
Jamie, now i am getting this error: Feb 16 16:36:29 dublx09 l/usermin/changepass/changepass.cgi: pam_ldap: erro= r trying to bind as user "uid=3Dmkhan,ou=3DPeople, dc=3Dnoam,dc=3Dcorp,dc= =3Dfrk,dc=3Dcom" (Invalid credentials) -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Friday, February 17, 2006 2:10 AM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Hi, That looks OK.. Can LDAP users use the command-line passwd command to change their password= s? - Jamie -----Original Message----- From: "Khan, Mohammed [SMO]" <MK...@fr...> Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan Date: Fri 17 Feb 2006 10:07 am Size: 2K To: <web...@li...> Hi Jamie, Here is my passwd file: Pls tell me what I am doing worng. #%PAM-1.0 password required pam_cracklib.so password sufficient pam_ldap.so password sufficient pam_unix.so password required pam_deny.so Thanks Mohammed -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Thursday, February 16, 2006 2:46 PM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that Us= ermin's Change Password module is setup to use PAM. - Jamie On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > Hello Jamie,=20 > Do you know how can I use usermin to change my ldap password. Please need > your help. >=20 > Thanks > Mohammed >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:28 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Did you set up /etc/pam.d/usermin as well? My last set of instructions > only > mentioned /etc/pam.d/webmin , sorry .. >=20 > - Jamie >=20 > On 17/Feb/2006 09:25 Khan, Mohammed [SMO] wrote .. > > Hi Jamie,=20 > > Sorry to bug u sir. I am still getting the same error when login using > > ldap user into usermin. Here is error: > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: check pass; user unkn= own > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: authentication failur= e; > > logname=3D uid=3D0 euid=3D0 tty=3D ruser=3D rhost=3D > >=20 > > And here is mt .ssh file > > #%PAM-1.0 > > auth required /lib/security/pam_securetty.so > > auth required /lib/security/pam_nologin.so > > auth required /lib/security/pam_env.so > > auth sufficient /lib/security/pam_ldap.so > > auth required /lib/security/pam_unix_auth.so use_first_pass # set= _secrpc > > account required /lib/security/pam_unix.so > > account required /lib/security/pam_nologin.so > > session required /lib/security/pam_unix.so > > session required /lib/security/pam_limits.so > >=20 > >=20 > > Please lete me know.. > >=20 > > Thanks > >=20 > > -----Original Message----- > > From: web...@li... > > [mailto:web...@li...]On Behalf Of Jamie > > Cameron > > Sent: Friday, February 17, 2006 1:04 AM > > To: web...@li... > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > >=20 > >=20 > > Hi, --- message truncated --- ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D103432&bid=3D230486&dat=3D1= 21642 - Forwarded by the Webmin mailing list at web...@li... To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list Notice: All email and instant messages (including attachments) sent to or from Franklin Templeton Investments (FTI) personnel may be retained, monitored and/or reviewed by FTI and its agents, or authorized law enforcement personnel, without further notice or consent. |
|
From: Khan, M. [SMO] <MK...@fr...> - 2006-02-16 23:44:17
|
This what I am getting when changing password on usermin. Failed to change password : Your username was not found in the password fil= e=20 =20 -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Friday, February 17, 2006 2:10 AM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Hi, That looks OK.. Can LDAP users use the command-line passwd command to change their password= s? - Jamie -----Original Message----- From: "Khan, Mohammed [SMO]" <MK...@fr...> Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan Date: Fri 17 Feb 2006 10:07 am Size: 2K To: <web...@li...> Hi Jamie, Here is my passwd file: Pls tell me what I am doing worng. #%PAM-1.0 password required pam_cracklib.so password sufficient pam_ldap.so password sufficient pam_unix.so password required pam_deny.so Thanks Mohammed -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Thursday, February 16, 2006 2:46 PM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that Us= ermin's Change Password module is setup to use PAM. - Jamie On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > Hello Jamie,=20 > Do you know how can I use usermin to change my ldap password. Please need > your help. >=20 > Thanks > Mohammed >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:28 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Did you set up /etc/pam.d/usermin as well? My last set of instructions > only > mentioned /etc/pam.d/webmin , sorry .. >=20 > - Jamie >=20 > On 17/Feb/2006 09:25 Khan, Mohammed [SMO] wrote .. > > Hi Jamie,=20 > > Sorry to bug u sir. I am still getting the same error when login using > > ldap user into usermin. Here is error: > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: check pass; user unkn= own > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: authentication failur= e; > > logname=3D uid=3D0 euid=3D0 tty=3D ruser=3D rhost=3D > >=20 > > And here is mt .ssh file > > #%PAM-1.0 > > auth required /lib/security/pam_securetty.so > > auth required /lib/security/pam_nologin.so > > auth required /lib/security/pam_env.so > > auth sufficient /lib/security/pam_ldap.so > > auth required /lib/security/pam_unix_auth.so use_first_pass # set= _secrpc > > account required /lib/security/pam_unix.so > > account required /lib/security/pam_nologin.so > > session required /lib/security/pam_unix.so > > session required /lib/security/pam_limits.so > >=20 > >=20 > > Please lete me know.. > >=20 > > Thanks > >=20 > > -----Original Message----- > > From: web...@li... > > [mailto:web...@li...]On Behalf Of Jamie > > Cameron > > Sent: Friday, February 17, 2006 1:04 AM > > To: web...@li... > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > >=20 > >=20 > > Hi, --- message truncated --- ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D103432&bid=3D230486&dat=3D1= 21642 - Forwarded by the Webmin mailing list at web...@li... To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list Notice: All email and instant messages (including attachments) sent to or from Franklin Templeton Investments (FTI) personnel may be retained, monitored and/or reviewed by FTI and its agents, or authorized law enforcement personnel, without further notice or consent. |
|
From: Khan, M. [SMO] <MK...@fr...> - 2006-02-16 23:43:08
|
Yes they can. -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Friday, February 17, 2006 2:10 AM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Hi, That looks OK.. Can LDAP users use the command-line passwd command to change their password= s? - Jamie -----Original Message----- From: "Khan, Mohammed [SMO]" <MK...@fr...> Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan Date: Fri 17 Feb 2006 10:07 am Size: 2K To: <web...@li...> Hi Jamie, Here is my passwd file: Pls tell me what I am doing worng. #%PAM-1.0 password required pam_cracklib.so password sufficient pam_ldap.so password sufficient pam_unix.so password required pam_deny.so Thanks Mohammed -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Thursday, February 16, 2006 2:46 PM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that Us= ermin's Change Password module is setup to use PAM. - Jamie On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > Hello Jamie,=20 > Do you know how can I use usermin to change my ldap password. Please need > your help. >=20 > Thanks > Mohammed >=20 > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:28 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan >=20 >=20 > Did you set up /etc/pam.d/usermin as well? My last set of instructions > only > mentioned /etc/pam.d/webmin , sorry .. >=20 > - Jamie >=20 > On 17/Feb/2006 09:25 Khan, Mohammed [SMO] wrote .. > > Hi Jamie,=20 > > Sorry to bug u sir. I am still getting the same error when login using > > ldap user into usermin. Here is error: > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: check pass; user unkn= own > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: authentication failur= e; > > logname=3D uid=3D0 euid=3D0 tty=3D ruser=3D rhost=3D > >=20 > > And here is mt .ssh file > > #%PAM-1.0 > > auth required /lib/security/pam_securetty.so > > auth required /lib/security/pam_nologin.so > > auth required /lib/security/pam_env.so > > auth sufficient /lib/security/pam_ldap.so > > auth required /lib/security/pam_unix_auth.so use_first_pass # set= _secrpc > > account required /lib/security/pam_unix.so > > account required /lib/security/pam_nologin.so > > session required /lib/security/pam_unix.so > > session required /lib/security/pam_limits.so > >=20 > >=20 > > Please lete me know.. > >=20 > > Thanks > >=20 > > -----Original Message----- > > From: web...@li... > > [mailto:web...@li...]On Behalf Of Jamie > > Cameron > > Sent: Friday, February 17, 2006 1:04 AM > > To: web...@li... > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > >=20 > >=20 > > Hi, --- message truncated --- ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D103432&bid=3D230486&dat=3D1= 21642 - Forwarded by the Webmin mailing list at web...@li... To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list Notice: All email and instant messages (including attachments) sent to or from Franklin Templeton Investments (FTI) personnel may be retained, monitored and/or reviewed by FTI and its agents, or authorized law enforcement personnel, without further notice or consent. |
|
From: Jamie C. <jca...@we...> - 2006-02-16 23:12:22
|
Hi, That looks OK.. Can LDAP users use the command-line passwd command to change their passwords? - Jamie -----Original Message----- From: "Khan, Mohammed [SMO]" <MK...@fr...> Subj: RE: [webmin-l] Webmin Servers, Broadcast/scan Date: Fri 17 Feb 2006 10:07 am Size: 2K To: <web...@li...> Hi Jamie, Here is my passwd file: Pls tell me what I am doing worng. #%PAM-1.0 password required pam_cracklib.so password sufficient pam_ldap.so password sufficient pam_unix.so password required pam_deny.so Thanks Mohammed -----Original Message----- From: web...@li... [mailto:web...@li...]On Behalf Of Jamie Cameron Sent: Thursday, February 16, 2006 2:46 PM To: web...@li... Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan Just make sure that /etc/pam.d/passwd is setup to talk to LDAP, and that Usermin's Change Password module is setup to use PAM. - Jamie On 17/Feb/2006 09:42 Khan, Mohammed [SMO] wrote .. > Hello Jamie, > Do you know how can I use usermin to change my ldap password. Please need > your help. > > Thanks > Mohammed > > -----Original Message----- > From: web...@li... > [mailto:web...@li...]On Behalf Of Jamie > Cameron > Sent: Thursday, February 16, 2006 2:28 PM > To: web...@li... > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > Did you set up /etc/pam.d/usermin as well? My last set of instructions > only > mentioned /etc/pam.d/webmin , sorry .. > > - Jamie > > On 17/Feb/2006 09:25 Khan, Mohammed [SMO] wrote .. > > Hi Jamie, > > Sorry to bug u sir. I am still getting the same error when login using > > ldap user into usermin. Here is error: > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: check pass; user unknown > > Feb 16 14:23:08 dublx09 usermin(pam_unix)[32085]: authentication failure; > > logname= uid=0 euid=0 tty= ruser= rhost= > > > > And here is mt .ssh file > > #%PAM-1.0 > > auth required /lib/security/pam_securetty.so > > auth required /lib/security/pam_nologin.so > > auth required /lib/security/pam_env.so > > auth sufficient /lib/security/pam_ldap.so > > auth required /lib/security/pam_unix_auth.so use_first_pass # set_secrpc > > account required /lib/security/pam_unix.so > > account required /lib/security/pam_nologin.so > > session required /lib/security/pam_unix.so > > session required /lib/security/pam_limits.so > > > > > > Please lete me know.. > > > > Thanks > > > > -----Original Message----- > > From: web...@li... > > [mailto:web...@li...]On Behalf Of Jamie > > Cameron > > Sent: Friday, February 17, 2006 1:04 AM > > To: web...@li... > > Subject: RE: [webmin-l] Webmin Servers, Broadcast/scan > > > > > > Hi, --- message truncated --- |