Account names can break LDAP logins?

I've successfully installed and patched (patches 118833-36, 119963-08 and 122032-05) my Solaris 10 system so it's using LDAP against the Sun Java System Directory Server Enterprise Edition 6.2.
On my test box, I have several test accounts setup.
On the one that is simply my last name, everything works fine. SSH logins, telnet logins, and password changes. SO I'm sure the pam.conf and nsswitch.conf works right.
On several other accounts, they work just as well.
However two accounts do not. getent -v | grep username shows the accounts. I can "su - account" from root and get in fine. However if I try to SSH or telnet in it rejects my password. The password being entered IS correct.
The one thing they have in common is that they are both contractor accounts, which due to corporate standards are
8 numeric digits starting with an 8, so something like 81234567 would be a contractor ID.
Renaming the bad contractor accounts in the LDAP editor (but NOT changing the password) allows me to SSH in.
Renaming the test account with my last name to a contractor style name breaks it.
I read "man -s 4 passwd" and couldn't find where our naming standard violates the Solaris system standard.
Thoughts?

From the Solaris 10 Basic System Admin Guide at: http://docs.sun.com/app/docs/doc/817-1985/6mhm8o5l8?a=view#userconcept-30
"User names � They should contain from two to eight letters and numerals. The first character should be a letter. At least one character should be a lowercase letter."
Sun probably should have used the word "must" instead of "should." ie. First letter must be a letter.
The system behavior you are describing seems to bear this out.

Similar Messages

  • TS3297 why I can't make a purchase on other itunes store I always get a message that "this account name can only make a purchase from the Qatari store" when I tried to change the store since the product is not available or only available in USA or Philipp

    why I can't make a purchase on other itunes store I always get a message that "this account name can only make a purchase from the Qatari store" when I tried to change the store since the product is not available or only available in USA or Philippines

    just call them...i bought my PB when it came out...but I had an issue recently and called them up and they helped me out....
    Sorry can't help you with any of the other problems...mine are working fine...

  • Authentication - same account name on 2 LDAP servers

    We have our mac clients set up to authenticate against 2 LDAP servers, one Open Directory, one eDirectory - to keep things easy for our users I want to use the same login username for both OD and eDirecotry users - we basically have users logging into both Windows and Macs, I want a specific set of users to have home directories on our Mac server (only when logging into the the Macs), and to pick up their Windows home directories when logging onto Windows machines. I have the Mac server set above the eDirectory server in the Directory Utility search policy (client machines), but when I log in with a network account I am prompted to choose which account to use (eDir or OD similar screen to having managed users in different groups where you are prompted to choose your profile at login). I thought that by specifying the order in the search policy the client machine would authenticate the first account found rather than prompting for which account to use. Any one know of a way to make this happen - ie set up identical accounts on both LDAP servers and have the macs authenticate the first account found on the server specified in the Directory search policy instead of offering a choice? I hope this makes sense. I know it would be easier to mount a network share on the mac server for certain users and have all the accounts authenticate via eDirectory, but I have to do it this way. Anyone have any advice??

    I am having exactly the same problem, also with an iMac and a MBP. My iMac is about 6 weeks old, and I migrated via Time Machine. I can read the files from the connected machine, but cannot write, regardless of which is the host. Permissions are all fine.
    I did notice one thing: the UUID number for the accounts is the same (accounts have same name as with darrylh). You can find this under System Preferenes>Accounts and right click or control-click on the account name after unlocking it. I am working with Apple support on this, but no resolution yet. I suspect that the UUID (Universally Unique ID) should not be the same on two machines, but I don't know the consequences of changing it or which one to change.
    Thanks.

  • Email Account Name can't be changed (at least it won't save)

    I've been trying to change the name of my personal email account on 3 different Tours now, and it won't save. It defaults to the email address. I can change it, and it says the account was updated, but it doesn't stick. It keeps showing the email address as the account name.
    Is this a bug in the software? Must be, since 3 Tours have done it.
    Any ideas? Thanks.

    Goto the Email set up, it will show you the Current Email accounts you have set up, there will be an option to "Edit" You can change the Display Name (what other's see in the From line) and Account Name, what shows up when you mouse over your email icon on your Blackberry.
    Brownie
    Tour 9630
    IT Professional

  • I want to use Icloud on my iphone, ipad, desktop and labtop, but 2 have different account names- can I merge my apple ids or find a way to connect them all?

    Hello Hello-
    I want to connect all of my computers together but over the years I must have created 2 accounts.  Is there a way to merge accounts or sign in in all of them the under the same account. 

    If by "merge accounts" you mean merge iTunes accounts (using your Apple ID), then the answer is no.  If you bought songs, apps, etc. using both accounts over time, then your are stuck.  You need to choose one account for your iTunes.

  • Attempt to deal with changing login account name issue

    Like many companies, we have on a regular basis people who change names due to life situations. I have tried a variety of things to deal with this in SharePoint.
    The changes start with the Active Directory admins, who create the user's new login during a night shift. I get an email about the change. When I look in the user profiles, I see that many of the fields for the user reflect the change. However, the
    actual account name attribute, which is read only to me, never changes during this period.
    So this morning, I once again web searched, found
    http://geekswithblogs.net/rgupta/archive/2011/02/16/change-accountnameloginname-for-a-sharepoint-user-spuser-again.aspx and tried the recommendation.
    I ran
    stsadm -o migrateuser -oldlogin mydomain\old -newlogin mydomain\new -ignoresidhistory
    The user does not exist or is not unique.
    PS C:\Users\sa_spfarm>
    This is the type of behavior I have gotten over time.
    For the longest time I didn't do anything since the user profile was mostly updated. Then an InfoPath programmer reported getting stale information when trying to get the user's login. After research we found that it was using the account name for the user
    rather than the login attribute (which is properly updated).
    Several times I went through adding all the people who had out of date info in their user profile.
    I recently tried to write some powershell that would at least produce a report for me of all  users in the farm whose account name differed from their logins - I was never able to get code that actually worked.
    Surely there is something simple that I am missing. I am hoping someone reads this who recognizes the problem and lets me know.
    The user profile sync is running - new user profiles appear in the system each day and as I said, in all the cases I have seen, the AD information in the profile has all been updated - except the account name (which I suspect must be an index key or something
    for the profiles).
    Thanks!
    About the only thing I have seen that works is to go into all dozen or more of our site collections and add the user's new login to an appropriate sharepoint permission group - that seems to force the account name update or at least removes the old entry
    and creates a new one (I am uncertain which it does).

    Hmm. Let me see if I can.
    Okay, so if you look at the 3 entries from the detailed user list of one of our site collections, you will see that most users are like the first and last one in this screen shot - where the login column and the user name column have the "same"
    name (one has a domain and the other doesn't... that isn't the issue to which I am referring).
    The middle person however has a user name which was the last login the user had, and has a login string with the correct domain and the correct login.
    When I go to Central Admin > manage service applications > User Profile Service Application > Manage User Profiles and I search for the old name, it is not found in either the missing or the active user profiles.
    When I search for the new name, a user profile is found. When I read through the user profile, there is no attribute which has the value of the old name.
    There are calls from users in this situation which lead us back to user list information like this.
    I have seen a user who was able to sign a document out for change in a doc library, but who could not sign it back in because "it was already out to another person" where the other person is the old name.
    Likewise, as I mentioned, if an InfoPath attempts to pull the user's information back from the sharepoint web service, there have been, at least for us, times when the old name is returned with certain methods instead of the new name.
    The interesting thing in this case is that normally I can fix these by adding the new login into a sharepoint group for the site collection. So far, that has not helped with this user.

  • Can't remember the account name and password which...

    Hi, i can't remember the account name and password which bind to my n8 mobile, therefore i can't download music any more. i tried to "forgot password", but cannot find back the account name. If I login with other account, I can't download music. what can i do? 

    Hi carolweiwei,
    Thank you for your post and welcome to the forums!
    If you cannot remember the user name and password you've used on Nokia Music, please visit this page, where you can use your mobile number to get a text message with your username and a password reset link. 
    Let us know if this helps,
    Puigchild
    If you find this post helpful, a click upon the white star at bottom would always be appreciated.
    If it also solves your problem, clicking ACCEPT AS SOLUTION below it will benefit other users!

  • Changed account name and old music files no longer can play

    I changed my account name to an e-mail address that I currently use. since I moved the old one I could no longer access any longer. Well they have a feature to do that so I took it so it would be easier to remember the account and password. thing is since I changed none of the songs that I purchased with the old account name can be played any longer. they need to be Reauthorized.
    No biggie right just type in the old account name and password and I'll be on my way. Wrong :P
    According to the music store the old account does not exist. Well of course not that is because I changed it. I check to see my account history under the NEW account and it has all the files I ever downloaded since I first installed iTunes! If this is the case why on earth can I not play the files purchased under my old account under the new accounts name! did I make a mistake by not deauthroizing my computer before changing account? because it is not mentioned in the instructions to do so! Grrr... normally I'd just say oh well but it's most of my iTunes library!
    Pleas help!

    Problem Resolved!
    I was sent back an e-mail stating that I did not make a second account but changed my account name from (accounts will be withheld for security) one to the other. Problem?
    Files downloaded from the other account name would not work with the one that I was currently using.
    Issues further complicating the matter. My computer recently was having Power supply issues and I reformated my computer several times. Not realizing that this left iTunes Music store saying that I had 5 computers authorized on my account because I had not deauthorized any of the computers each time. Couldn't really, windows crashed out and I couldn't get to it. So when I got everything ironed out on my computer. I couldn't play any of my songs becaus I had reached maximum authorizations! even Deauthorizing and reauthorizing didn't work.
    Solution:: Login to your (working) account and go to your account summary. Click on the button that says "Deauthorize ALL computers" This will wipe all computers that you had associated with your account to play your songs. Not that big of deal because all you have to do is log back in. (BIG deal to ppl that don't know your password, which they shouldn't be playing yoru songs anyway!)
    Once I resetted my authorization on all computers and logged back in everything was fine.
    Now I think the tech that sent me the e-mail did do one thing for me. He must have enabled my old account I used to have and linked it to my current one. Because instead of my old account saying it does not exist it says it works now! yet I still login to and access my account with my new e-mail account!
    So even though I would like to say everything was within my power to do myself the whole time. That is not the case. The tech did help me associate the two accounts from withing iTunes. So I can now listen to my songs at anytime I want and not be told I have 5+ computers when I only own 2 LOL

  • Ringtones and Old iTunes Account Name

    I tried to create a ringtone from a song I purchased when my account was a former email address. I could not purchase the ringtone with the email address my iTunes account now has as the account name. When I "get info" on the song I see the old email address as the account name. I cannot login to iTunes with that login name since it no longer exists. Is this making sense? Any suggestions?

    I did get good support by emailing Apple after a couple of tries. The person helping me did some digging and found out that I had two account names, neither of which matched up with the info on the purchased music.
    The current account name would not work. Even though my purchased music listed a third account name, they suggested I try the second account and sure enough it would allow me to purchase the ringtone.
    So if you can't get it to work you might try emailing Apple and asking that they check your history to see if there is an account that will work for your purchased music.

  • Offset account name field in general ledger

    Hi,
           The 'offset account name' field is blank in the general ledger.If the  offset a/c is of any BP ,its getting displayed.But if its other than that its not displayed in the general ledger.
    Pls help.
    Thanks,
    Smitha
    Edited by: Philip Eller on Jun 6, 2008 9:18 AM

    Hi Smitha,
    Would you please first clarify the version and patch level of your Business One, as there is several enhancement in this area, please check SAP Note 1045356 and 1061715.
    Based on the testing in the latest version, Offset account name can be displayed correctly no matter it is account or BP.
    Regards,
    Canna Mu
    SAP Business One Forums Team

  • FR for plannig - long account names

    Hi All,
    I am implementing HyS9P. The trouble is that the customer needs to see full account names (can be up to 350 characters long) in reporting.
    WOuld be grateful for any ideas on how it can be done.
    thanks,
    Andrei

    Hi Andrei
    No problem on the answring, glad I can be of some help.
    One solution that we have used previosuly is to store the "long" name as cell text against a specific member intersection, this can then be administered using a form following uploads etc. Then in FR use the GET CELLTEXT function (can't remember the exact function name) in a column. Then hide the actual account name column and use the cell text column as the account name.
    Good luck.
    Andy King
    www.analitica.co.uk

  • Editing User Account Names

    How do I edit a user account name, e.g. from "John Smith1" to simply "John Smith"? Can the short name be likewised edited? Does having a "John Smith" in the Deleted Users Folder affect this?
    Mike

    1) Changing the account name can be done from the System Preferences > Accounts prefpane.
    2) Changing the shortname is not a trivial task and is generally discouraged, but there are utilities such as ChangeShortName that will do it.
    3) No.

  • ApacheDS (LDAP) Network Accounts Never Can Login

    I have been fighting with LDAP via ApacheDS for days attempting to get Mavericks to actually authenticate against the LDAP server.
    Here is the path that I have taken:
    ApacheDS is setup with simple authentication (disabled everything else for the moment after attempting to login every which way).
    Here is an example of the LDAP setup:
    dc=example,dc=com
    ou=usersuid=username
    cn=Full Name
    sn=Name
    displayName=FullName
    userPassword=hash
    uid=username
    ou=groups
    cn=Users
    cn=Administrators
    Then I went to Users and Groups, Allow network users to login is checked
    Joined a Network Account Server
    (When looking at edit, it shows a green indicator)
    I setup a custom mapping under LDAPv3 which contains:
    Seach Base: ou=users,dc=example,dc=com
    Users: inetOrgPerson
    AuthenticationAuthority: uid
    NFSHomeDirectory: #/Users/$uid$
    PrimaryGroupID: #20
    RealName: cn
    RecordName: uid
    UniqueID: uid
    UserShell: #/bin/bash
    I can see the information in the Directory Editor from the LDAP server, Search Policy has the network accounts right after the local accounts.
    When attempting to login, it just shakes... Here is the only items that I can see in the opendirectoryd.log:
    2014-01-04 10:26:50.785452 CST - Loaded bundle at path '/System/Library/OpenDirectory/Modules/ldap.bundle'
    2014-01-04 10:27:06.734300 CST - 22.805 - Client: opendirectoryd, UID: 0, EUID: 0, GID: 0, EGID: 0
    2014-01-04 10:27:06.734300 CST - 22.805, Module: ldap - failed to retrieve LDAP server schema - LDAP error - 50
    2014-01-04 10:27:07.031977 CST - 22.823.826 - Client: opendirectoryd, UID: 0, EUID: 0, GID: 0, EGID: 0
    2014-01-04 10:27:07.031977 CST - 22.823.826, Node: /LDAPv3/example.com, Module: ldap - __odnode_copy_record_block_invoke: 4101 No predicates provided
    Anyone have any ideas?

    I was able to activate the debug log in the Leopard client machine, but I don't know how to look from another machine via SSH... Could you explain a bit the procedure? Is it possible to try to log in as a network user and then, after failure, log in as an admin account and check the log with Console?
    Today I found out that Snow Leopard clients are also not able to log in... Similar problem in Directory Utility:
    This is what I found in the log for this machine (tried to log in with two different accounts):
    25/04/12 20:09:17          SecurityAgent[321]          User info context values set for XXX
    25/04/12 20:09:18          authorizationhost[320]          Failed to authenticate user <XXX> (tDirStatus: -14103).
    25/04/12 20:09:25          SecurityAgent[321]          User info context values set for YYY
    25/04/12 20:09:25          authorizationhost[320]          Failed to authenticate user <YYY> (tDirStatus: -14103).
    Couldn't find much about this in Google.
    I'm starting to feel really disappointed about this!
    (sorry for the delay in answering, been abroad...)

  • I changed my name on MacBook pro, I could not log in after that though the password is unchanged but tHe name appeared on the login window is the original name?..how I can log in?

    I changed my name on MacBook pro, I could not log in after that though the password is unchanged but tHe name appeared on the login window is the original name?..how I can log in?

    Hmmm.  Maybe try this?
    OS X: Changing or resetting an account password

  • How can I change my iCloud account name ?

    Howe can I change my iCloud account name?

    I know this is a year later, but someone may want to know.  Go to http://appleid.apple.com login and you can change it there.

Maybe you are looking for

  • Internal hard drives are no longer appearing in the finder window

    Hi everyone, I'm a new macbook pro user and just noticed that my internal hard drives are no longer appearing in the sidebar of my Finder window.  I have searched this issue and checked that the correct preferences are selected, never received any er

  • Macbook pro 2014 with ASUS PB287Q and SAMSUNG U28D590D

    Hi I was wondering if my new macbook pro 15" 2014 2.5GHz Quad-core Intel Core i7 16GB 1600MHz DDR3L SDRAM 512GB Flash Storage Intel Iris Pro Graphics+Nvidia GT750m 2GB will work with the ASUS PB287Q 4K or the samsung U28D590D? I read that if u connec

  • IPlanet Web Proxy 3.6 Truncating some web pages

    I am having problems with a few pages that are being truncated by iPlanet Web Proxy Server 3.6. They work fine when not using a proxy and they work fine through the proxy if I download it and then post that page to one of my own servers. Here is an e

  • No stop in StartupShutdown, Unique prefix

    Hi all, I am porting my second PlugIn from CS6 to CC2014. The formal syntactic changes are made, but the PlugIn causes a crash of InDesign. So I took my newly successfully ported PlugIn, removed all unused c-files, and added some of the c-files of th

  • Slow Log out

    Hi all! I recently buy (1 month ago) a new Macbook Pro Retina (late 2013, without discrete graphics but 2,3 GHz and 16gb RAM) I've notice that the log out is very slow compared to my old white Macbook (late 2009) In my old macbook is nearly immediate