Bug 736 - issues authenticating 3.7p2 with novell directory server
Summary: issues authenticating 3.7p2 with novell directory server
Status: CLOSED INVALID
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: PAM support (show other bugs)
Version: -current
Hardware: SPARC Solaris
: P1 security
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-10-09 01:58 AEST by oscar sumano
Modified: 2004-04-14 12:24 AEST (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description oscar sumano 2003-10-09 01:58:38 AEST
We use novell directory services to authenticate users. We are running solaris 
8,7 and 6. Our current version  of ssh is "OpenSSH_3.4p1".. This works fine 
with nds but not the current version. When we do some traces in NDS we see that 
the user is hitting the nds server but we are not getting error messages from 
nds. As soon as we put the original version of ssh back.. authentication works. 

THe reason we are upgrading is because of all the security issues that have 
been posted. Please let me know how to proceed. 
I'm posting our pam.conf configuration for ssh. 





sshd  auth      sufficient  /usr/lib/security/pam_nds.so.0
sshd  account   sufficient  /usr/lib/security/pam_nds.so.0
sshd  session   sufficient  /usr/lib/security/pam_nds.so.0
sshd  password  required  /usr/lib/security/pam_nds.so.0

sshd  auth      required  /usr/lib/security/pam_unix.so.1  try_first_pass
sshd  account   required  /usr/lib/security/pam_unix.so.1
sshd  session   required  /usr/lib/security/pam_unix.so.1
sshd  password  sufficient  /usr/lib/security/pam_unix.so.1
Comment 1 Darren Tucker 2003-10-12 16:44:44 AEST
What do you mean by "we are not getting error messages from nds"?  Does the 
authentication work but you don't get messages from the session modules?  Or 
does it not authenticate?

Do you have "PasswordAuthentication no" and "ChallengeResponseAuthentication 
yes" in sshd_config?
Comment 2 Darren Tucker 2003-11-19 23:44:20 AEDT
Please try a recent snapshot (20031118 or later), there have been several PAM
fixes.  Also, please elaborate on "not getting error messages from nds".
Comment 3 Darren Tucker 2003-12-23 00:34:32 AEDT
No response = closed bug.  Please reopen if you have more info.
Comment 4 Damien Miller 2004-04-14 12:24:19 AEST
Mass change of RESOLVED bugs to CLOSED