Displaying 20 results from an estimated 11000 matches similar to: "issues with pam_winbind and ability to use old windows password"
2010 Jun 09
1
pam_winbind and krb5_auth
Hey list,
I'm wondering if there is any advantage to be gained by using kerberos with pam_winbind.
I've configured pam_winbind and enabled krb5_auth though apart from being granted a ticket, I'm unsure as to any advantage that would be gained by enabling Kerberos.
Thanks,
Matt Delves
-- 
---------------------------------------------
Matthew Delves
System Administrator
Information
2010 Jun 03
8
authenticating new nodes that are created by provisioning
Hey Folks,
I''m looking at doing automated provisioning of new servers and am trying to integrate puppet into this process. What I''m wondering though is what the best process for securely registering a new node is.
At the moment the first time puppet is run I have to then accept the certificate on the puppetmaster and then run puppet again.
What I would like to do is accept the
2009 Dec 17
12
puppet performance and inability to retrieve file metadata
Hey All,
I''m running into a problem whereby some nodes are struggling to retrieve the metadata for files. I''ve moved all the nodes across to 0.25.1 to try and eliminate version inconsistencies though they still appear. I''ve also started using asynchronous stored configs as well.
I''m wondering if this has anything to do with performance on the box and if there
2003 Dec 30
0
Winbind problem related with old libnss_winbind.so and pam_winbind.so version.
Hello,
In my log.winbind I'm getting several messages like this one:
[2003/12/30 18:19:00, 0] nsswitch/winbindd.c:process_loop(725)
  process_loop: Invalid request size from pid 12913: 1304 bytes sent, should
be 1568
  This usually means that you are running old wbinfo, pam_winbind or
libnss_winbind clients
I suppose that the problem may be cause by old version of pam_winbind and
2004 Oct 25
1
Samba and "running old wbinfo, pam_winbind or libnss_winbind clients"
I've just installed the Samba 3.0.7 on my FreeBSD box.
I am trying to authenticate it to the Active Directory (for my Squid
server).
When I go to a webpage using the squid server, I get this error from
Samba's Winbind:
Oct 25 15:33:39 eclipse winbindd[61830]: [2004/10/25 15:33:39, 0]
nsswitch/winbindd.c:process_loop(737)
Oct 25 15:33:39 eclipse winbindd[61830]:   process_loop: Invalid
2005 Jun 15
1
unable to build pam_winbind on Solaris 9
Greetings,
Still trying to get Samba 3.0.15pre2 built on a Solaris 9 box with PAM 
support.  I am using gcc 3.3.2 and I have openldap-2.2.24, krb5-1.4, and
Cyrus SASL 2.1.20 installed.
I have found other posting by people with problems building on Solaris 
as well as asking about the "_pam_macros.h" file that seems to be 
missing on Solaris.  Posting about problems, but not with
2012 May 05
1
samba-3.5.15 croaks linking pam_winbind
Samba is throwing this when trying to build version 3.5.15:
===================================================
Compiling ../nsswitch/pam_winbind.c
../nsswitch/pam_winbind.c: In function ?_pam_parse?:
../nsswitch/pam_winbind.c:440:76: warning: comparison between pointer
and integer
../nsswitch/pam_winbind.c:445:7: warning: comparison between pointer and integer
../nsswitch/pam_winbind.c:447:7:
2003 Mar 21
1
Compiling pam_winbind on Solaris 8
Greetings,
I am trying to compile pam_winbind.so under Solaris 8.  I have the source for samba 2.2.8 on the server.  When I issue a make nsswitch/pam_winbind.so, I receive many compiler warnings, such as:
Compiling nsswitch/pam_winbind.c with -fPIC
nsswitch/pam_winbind.c: In function `converse':
nsswitch/pam_winbind.c:72: warning: passing arg 3 of `pam_get_item' from incompa
tible
2007 Jan 08
0
pam_winbind + password never expires [re-post]
Sorry for the repost, but I've not gotten any response and the problem
persists.  Does anyone have any idea how to fix?
===================================
I read a few posts in the archives about this problem and that it was to
be fixed in 3.0.23c.  Currently I'm running 3.0.23d-2+b1 on a debian
system and am getting the following:
$ ssh -l testuser fileserver
Password:
Your password
2007 Jan 04
0
pam_winbind + password never expires
I read a few posts in the archives about this problem and that it was to 
be fixed in 3.0.23c.  Currently I'm running 3.0.23d-2+b1 on a debian 
system and am getting the following:
$ ssh -l testuser fileserver
Password:
Your password has expired
Here's what auth.log shows:
Jan  4 11:46:26 tmcsamba1 pam_winbind[14309]: user 'DOMAIN1+testuser' OK
Jan  4 11:46:26 tmcsamba1
2009 Mar 13
1
PAM_WINBIND problem with sambaPwdMustChange
Hi People!
	I use pam_winbind for authentication in my computer workstation using
Debian Lenny 5.0, Stable Version.
	I configure my user with this option "sambaPwdMustChange: 0", and I
logon in GDM without asking to change password. Who knows what can be?
	I use Samba PDC with Heimdal Kerberos, but, I configure PAM with only
pam_winbind for tests...
	Client versions:
	ii 
2017 Mar 13
1
pam_winbind with trusted domain
Hi,
I am having problems using pam_winbind to log in as a user in a trusted domain.  The arrangement is that Samba is joined to a local domain DOMLOCAL which has a trust setup with DOMREMOTE.  getent passwd/group correctly enumerates users and groups from DOMLOCAL.  
If I try getent passwd for the DOMREMOTE account no result is returned.  pam_winbind has a requirement that the user is a member of
2003 Jul 18
1
pam_winbind.so
Hi all,
I am having a problem with pam_winbind.so.  Is there
any documentation that tells exactly what each module
with pam_winbind.so does?  In other words, what does
the auth section do, what does the account section
do???  When I try to authenticate, the auth section in
login pam seems to pass successfully, but the account
section seems to fail.  Here is my login module
auth     required     
2005 Jan 03
0
pam_winbind troubles
Hi and happy New Year.
I test the integration of samba 3.0.10 on a fedora core 3 box in a Microsoft
Active Directory (Windows 2003) environment.
I already configure samba for the integration in the AD domain and it works fine
but I have a problem with the pam_winbind.
I can authenticate my AD domain users on the fedora box but I can?t change their
password with the passwd command.
For example, I
2010 Jan 14
1
pam_winbind WBC_ERR_AUTH_ERROR before even asking for a password
Pam.d/system-auth :
 
auth        required      pam_env.so
auth        sufficient    pam_winbind.so
auth        sufficient    pam_unix.so nullok
auth        required      pam_deny.so
 
account     sufficient    pam_winbind.so
account     required      pam_unix.so
account     required      pam_permit.so
 
password    sufficient    pam_winbind.so
password    sufficient    pam_unix.so
2009 Dec 07
0
pam_winbind adding "BUILTIN+users" secondary group to non-AD account?
I'm working on a PAM setup that will ignore winbind/AD completely for
users listed in /etc/passwd, and do the samba thing for all other
users.
Mostly it seems to work, but there's one weird side-effect.  For
non-AD users (only), an AD group "BUILTIN+users" is being added as a
secondary group.  If I kill winbind, it still gets added, although
only the gid is available (no name).
2006 Aug 01
2
[HELP] Samba 3.0.23a pam_winbind says password expired
hi,
i just do some tests with a fresh compiled samba 3.0.23a.
trying to authenticate against PAM with pam_winbind gives:
Aug  1 09:59:21 humevo36 pam_winbind[27853]: pam_winbind: 
pam_sm_authenticate (flags: 0x0000)
Aug  1 09:59:23 humevo36 pam_winbind[27853]: Verify user `gasch'
Aug  1 09:59:23 humevo36 pam_winbind[27853]: enabling cached login flag
Aug  1 09:59:23 humevo36
2009 Nov 05
3
ADS, pam_winbind and vsftpd
Greets ... I am not getting it.
I have samba (old one, 3.0.22-11-SUSE-CODE10) in an ADS-context, winbind
works OK ...
I am trying to connect vsftpd to winbind via PAM, this works TOO GOOD ;-)
currently I am able to login to vsftpd with ANY password, that's bad.
I am not understanding that PAM-stuff and I have some pressure to get
that ftp-server up, so please would someone help me out?
My
2024 Nov 27
1
pam_winbind Appears to need a Network Connection to Succeed at Offline Authentication
On Wed, 27 Nov 2024 10:19:48 -0500
"John R. Graham via samba" <samba at lists.samba.org> wrote:
> When I put winbindd in offline mode,
> 
>  ??? terra ~ # smbcontrol winbindd offline
>  ??? terra ~ # smbcontrol winbindd onlinestatus
>  ??? PID 20664: global:Offline BUILTIN:Online TERRA:Online
> HOME:Offline
> 
> I can successfully log in (with the test
2003 Oct 13
0
pam_winbind: Internal module error
Hiya,
I'm using Fedora Test 2 and Samba 3.0.0-15 packages from Redhat/Fedora rawhide
with a Windows 2003 Server. wbinfo -u and wbinfo -g work without any errors,
the
entries to nsswitch.conf were made.
I edited /etc/system-auth and added all necessary lines for pam_winbind as
described in the samba documentation.
Anyway, users that only exist within the Windows domain can't log on. Each