Bug 667 - Openssh 3.7x, Windows ssh clients and Ldap don't play together
Summary: Openssh 3.7x, Windows ssh clients and Ldap don't play together
Status: CLOSED INVALID
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: PAM support (show other bugs)
Version: 3.7.1p1
Hardware: ix86 Linux
: P2 critical
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-09-18 06:30 AEST by Matthew Schick
Modified: 2004-04-14 12:24 AEST (History)
0 users

See Also:


Attachments
DEBUG3 Output (3.63 KB, text/plain)
2003-09-18 06:31 AEST, Matthew Schick
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Matthew Schick 2003-09-18 06:30:37 AEST
The 3.7 versions of Openssh will refuse to authenticate via password (didn't try
keys) for the ssh.com and Putty clients IF the server is using ldap
authentication.  Authentication isn't a problem if the openssh client is used
(even under cygwin), or if any windows client is used to connect to an openssh
server using passwd/shadow auth.
Comment 1 Matthew Schick 2003-09-18 06:31:23 AEST
Created attachment 417 [details]
DEBUG3 Output

Output logged on affected server...
Comment 2 Darren Tucker 2003-09-18 14:10:24 AEST
From the sshd_config man page:
UsePAM  Enables PAM authentication (via challenge-response) and session
     set up.  If you enable this, you should probably disable
     PasswordAuthentication.  If you enable then you will not be able
     to run sshd as a non-root user.

What happens if you disable PasswordAuthentication and use keyboard-interactive
on the clients?
Comment 3 Jason McCormick 2003-09-22 11:41:30 AEST
This bug caught my eye because I'm a big supporter of LDAP authentication.  If I
set PasswordAuthentication=No in sshd_config then PuTTY doesn't login regardless
of the UsePAM setting.  I tried using both an LDAP-served user and a
/etc/passwd|shadow user with UsePAM=yes and UsePAM=no and as long as
PasswordAuthentication=No then PuTTY won't log in.  Could this be an error with
PuTTY?  Just for fun I tried F-Secure's SSH client (for OpenVMS) and everything
worked fine with PasswordAuthentication=No and UsePAM=yes and F-Secure verbosely
prints it's using keyboard-interactive.  Interestingly though UsePAM=no and
PasswordAuthentcation=no breaks F-Secure.
Comment 4 Darren Tucker 2003-12-22 22:35:03 AEDT
Matthew:  no reply = closed bug.

Jason: make sure PuTTY is using SSHv2 (many versions default to SSHv1 if the
server supports both) or if using SSHv1 that you have "TIS/Cryptocard" auth
enabled (which is disabled by default).
Comment 5 Damien Miller 2004-04-14 12:24:19 AEST
Mass change of RESOLVED bugs to CLOSED