After jumpstart host doesn't prompt for root password

Hiya gang,
I am migrating my jumpstart functionality to a new server and while it would appear that 100% of things are identical on both (as far as my /jumpstart tree is concerned), when I jumpstart a host (V240, in this case, but I've seen it on a SunBlade 150 too) everything appears to go well, but after the host reboots at the very end and I attempt to log in on console as root I am not even prompted for a password.
I've booted to single user over the net and on the disk that was just jumpstarted I see what would appear to be a normal Solaris system. There are no indications that I can find of why it wouldn't prompt for password at all, and I'm not well enough versed with the way the login functionality works to know why this is.
My new jumpstart server is running Solaris 10 (08/07), and I'm trying to jump a host with the same version. The very same jumpstart using my old jumpstart server works just fine.
Thanks in advance,
pb

Darren,
Thanks for your reply. It got me in the right frame of mind for troubleshooting :)
I set up pam debugging for pam_ldap and got the following messages in /var/adm/messages:
Aug 29 10:13:46 testfoo login: [ID 293258 auth.warning] libsldap: Status: 2 Mesg: Unable to load configuration '/var/ldap/ldap_client_file' ('').
Aug 29 10:13:46 testfoo login: [ID 562097 auth.alert] open_module: Owner of the module /usr/lib/security/pam_mkhomedir.so is not root
Aug 29 10:13:46 testfoo login: [ID 487707 auth.error] load_modules: can not open module /usr/lib/security/pam_mkhomedir.so
Aug 29 10:13:46 testfoo svc.startd[7]: [ID 694882 daemon.notice] instance svc:/system/console-login:default exited with status 1
Aug 29 10:56:51 testfoo su[3209]: [ID 105162 auth.alert] open_pam_conf: Owner of /etc/pam.conf is not root
Aug 29 10:57:49 testfoo login[1225]: [ID 105162 auth.alert] open_pam_conf: Owner of /etc/pam.conf is not root
...so, I checked them out and /etc/pam.conf and /usr/lib/security/pam_mkhomedir.so are both owned nobody:nobody, which smelled like an NFS issue since both of those files are copied over to the hosts as part of a JASS_FILES variable, but during the finish script execution (they're copied by install-templates.fin). So, I did some digging there and found another Sun forum thread that had info on it:
http://forums.sun.com/thread.jspa?forumID=841&threadID=5100999
...so I made the requisite change to /etc/default/nfs (setting the max version to 3) and the next jumpstart I tested worked perfectly, password prompt and all. All files that were previously owned nobody:nobody had the correct ownership this time around.
Crazy!
Thanks again Darren for your input!

Similar Messages

  • I want to use wifi for Apple TV, but it doesn't prompt for a password, so never connects.  What am I missing?  Can I only use it via a non-password-protected wifi connection?

    I want to use wifi for Apple TV, but it doesn't prompt for a password, so never connects.  What am I missing?  Can I only use it via a non-password-protected wifi connection?

    Hi - you might want to post this question on the Apple TV area - you would probably get a quicker response - if you have a specific question relating to Apple routers then post back here

  • Shaman doesn't ask for root password. But gets root privileges!!

    As the title says:
    Shaman is launched as a reguler user, never asks for root password, but still i able to install and uninstall packages.
    Either something in my system is seriously fucked, or there is a major securiy problem with shaman.
    Running openbox, installed shaman while running gnome, if that has anythiung to say. Sudo is not installed.
    Output from running shaman in terminal:
    [gert@flyktig ~]$ shaman
    This process is currently running setuid or setgid.
    GTK+ does not allow this therefore Qt cannot use the GTK+ integration.
    Try launching your app using 'gksudo', 'kdesudo' or a similar tool.
    See http://www.gtk.org/setuid.html for more information.
    Translations are enabled.
    Loading translations from "/usr/share/shaman/translations/"
    Parsing "core"
    Parser exited
    Parsing "extra"
    Parser exited
    Parsing "community"
    Parser exited
    Parser exited
    Log File should be: ""
    "core" ---> "http://mirror.archlinux.no/core/os/i686"
    "extra" ---> "http://mirror.archlinux.no/extra/os/i686"
    "community" ---> "http://mirror.archlinux.no/community/os/i686"
    Root privileges retired.
    "/home/gert/.config/shaman/shaman.conf"
    >>
    >> Shaman 1.0.9
    >> Compiled against Qt 4.4.1
    >> Running with Qt 4.4.3
    >>
    >> Our website is @ http://shaman.iskrembilen.com/ , join in!!
    >> You can also find a bugtracker in the website, please use it.
    >>
    >> Have you found a bug? Help us solving it faster! Please read
    >> http://shaman.iskrembilen.com/trac/wiki/Debugging_Shaman
    >> and please follow these steps to report bugs effectively!
    >>
    >> Starting Up Shaman...
    User agent is: "shaman/1.0.9 (Linux i686) libalpm/3.1.1"
    Shaman registered on the System Bus as ":1.51"
    Service org.archlinux.shaman successfully exported on the System Bus.
    --> UNSETENV HTTP_PROXY
    --> UNSETENV FTP_PROXY
    Populating Repo column
    Log file is: /var/log/pacman.log
    refinePkgView
    The left TextBox is over, let's do the ComboBox
    Show all packages
    Remove Package
    "Uninstall package: alunn"
    "alunn"
    "community"
    Process Queue
    Queue Dialog started
    Queue signals connected
    Starting Package Removal
    Root Privileges granted.
    Uid is: 1000
    Received Event Callback
    Alpm Thread Waiting.
    Entering Queue Lock
    Releasing Queue Lock
    Alpm Thread awake.
    Received Event Callback
    Alpm Thread Waiting.
    Entering Queue Lock
    Releasing Queue Lock
    Alpm Thread awake.
    Received Event Callback
    Alpm Thread Waiting.
    Entering Queue Lock
    No scriptlet for package alunn
    Releasing Queue Lock
    Alpm Thread awake.
    Received Event Callback
    Alpm Thread Waiting.
    Entering Queue Lock
    No scriptlet for package alunn
    Releasing Queue Lock
    Alpm Thread awake.
    /sbin/ldconfig: Can't create temporary cache file /etc/ld.so.cache~: Ikke tilgang
    Root privileges retired.
    Transaction Completed Successfully
    refinePkgView
    refinePkgView
    The left TextBox is over, let's do the ComboBox
    Show all packages
    [gert@flyktig ~]$

    The point of this thread was that you don't need to enter the root password at all. Not the first time, not ever.
    As far as I understand, it is supposed to work like this: When you first use shaman too install anything, it asks for the root password You can tick a "Do not ask me again"-box, so you don't have to enter the password again. If you tick the box and enter the password, shaman add the lines
    [auth]
    askforpwd=false
    to the users shaman.conf-file (~./config/shaman/shaman.conf) The next time shaman is run, it checks the config file, and if the askforpwd value is set to false, it grants itself root privileges (with some nifty setuuid root-thingy, I imagine) This is not the problem - this is the feature.
    The bug is this:
    the fact that any user can add the lines
    [auth]
    askforpwd=false
    to his own shaman.conf file, without ever entering the root password in shaman. The next time shaman is run, it checks the config file, and if the askforpwd value is set to false, it grants itself root privileges - even though the user has never entered the root password.
    This works for any unprivileged user on the system.
    If that is indeed a feature intended by any sane person, then I'm Mother Mary. And that can't be, seeing as I don't have breasts.

  • Thunderbird doesn't prompt for a password

    I have several email accounts in Thunderbird. Most are IMAP-types. I recently changed the password (using my webmail cPanel) for one of them. Since then, Thunderbird can't send or receive messages from this account. But it doesn't prompt me for a password.
    I deleted the password in "Options -> Security for this email account, but no change. I still can't receive or send emails via Thunderbird. When I try and send an email, Thunderbird eventually pops up an error message saying "server timed out".
    I can access the email account just fine via webmail.
    Any suggestions?

    Thank you very much for your time and trouble, Toad-Hall.
    Problem solved.
    For your information, I accessed Tools >options > Security > Passwords
    and deleted ALL the passwords (both ingoing and outgoing) associated with the mail accounts for which I had changed the password directly via cPanel. (Because the 3 accounts are on the same domain, Thunderbird was unable to download or write to all 3 of them, as I had changed the passwords.)
    I then closed Thunderbird and restarted my COMPUTER (merely closing and restarting Thunderbird was insufficient for Thunderbird to bring up the password prompt window).
    Doing both those things solved the problem. I opened Thunderbird, selected each account in turn and clicked "Get mail". Pop-up window asking for the password came up, I input and was able to write and download messages. I repeated for the other 2 accounts, and now all works fine.
    Thanks so much for your help.

  • Snow Leopard Finder always prompting for root password

    I've just 'upgraded' to Snow Leopard from Tiger on my Macbook Pro, only because increasing numbers of applications wouldn't install on Tiger. Snow Leopard is significantly slower than Tiger (2 gig plainly isn't enough for SL) and it's knackered a few of my installed applications, but that's not the main irritation. Now, when I carry out any move or delete operations in the Applications folder in Finder, I'm repeatedly prompted for the root password, even though I'm logged in as the root user. As it's quite a long password, for security reasons, this is a real PITA. Under Tiger, I was never so prompted. Can anyone suggest why Leopard's producing this prompt, and what can be done about it? Other than de-install SL and re-install Tiger, that is...
    Fred

    William Boyd, Jr. wrote:
    Is running as "root" your normal mode of operation? If so, why? For several reasons that's recommended.
    Fred Riley wrote:
    Ok, I suppose I should be a bit more accurate. I login as user 'fredriley' which is a user with superuser rights. I don't login as 'root' because that's pretty bad practice in the Unix world (and rightly so), so my original message was inaccurate.
    I'm guessing that's a mistype and should say "For several reasons that's not recommended" since in OS X root is disabled by default. What you were really getting a prompt for is the admin password. But you know that.
    Now, though, I find some apps that would work under Tiger not working under SL, and I see no real functionality gain from 10.4 to 10.6. Ho hum.
    Only because the application versions you have were written for an OS that was superseded almost four years ago. The current versions of those apps are likely better than ever.
    As for "no functionality gain" ...look harder. For me, Tiger was a good solid OS with a few annoyances, Leopard was even more solid with the refinement and removal of most of the Tiger annoyances, and Snow Leopard is a further optimization.
    Some people complain about new versions of various apps and OSs only getting loaded down with feature bloat. Well, with OS X you also get a lot of refinement and optimization. If a new version appears to have "no functionality gain," would that not imply that most of the work went into substance (performance, efficiency, workflow) rather than style (feature bloat and eye candy)? Just trying to help you keep an open mind. Personally, I would not want to go back to Tiger because I would miss the subtle but positive adjustments that were made since then. Tiger would just annoy me now.

  • ICloud has my old Apple ID and is prompting for a password, but I want to put in the new id, I can't because it is grey and there is no edit option.  I'm prompted for a password to an account that doesn't exist

    iCloud has my old Apple ID and is prompting for a password, but I want to put in the new id, I can't because it is grey and there is no edit option.  I'm prompted for a password to an account that doesn't exist.  Anyone know what I can do to fix this or why this is happening.?  I had no issue putting in my new Apple ID everywhere else, I could sign out of the old and inactive account and then sign back in using my new and proper one.  However, after the update to 7.3 it did a whole welcome to yr iPad and a set up thing and it went to set up iCloud and had my old Apple ID in grey where I can't change or edit it, it wants the password, when I put in the old password, it say yr Apple ID is incorrect but yet it won't let me change it??????? Anyone???

    Sign out and back into your apple id from Settings>iTunes and App stores>(Your apple ID)>Sign Out and then sign in again with the new address. Close app store from running in the background (or restart the phone if your unsure how to do this). If when trying to update any apps they are still asking for the old apple ID, delete and re-install those apps.

  • How to prompt for root/sudo credentials with Gnome

    With other distros like Ubuntu, Gnome prompts for root/sudo authentication whenever applications like Gnome services are run from the Desktop menu.  How do you enable that feature in Arch?  I have tried different variations of gksude -u root, gksudo -S....  Nothing seems to work.
    Thanks

    msmail000 wrote:I have gksu installed...  my user id is in the sudoers file "username ALL=(ALL) ALL".  I execute gksu services-admin.  I am prompted for the password.  The Services window appears and the Unlock button is active.  When I depress the Unlock button, nothing happens, all of the available services remain unselectible.
    Yeah, that's a known issue with the system tools. No bug report filed for it, though, I don't think. The buttons/services should work properly, though, if you were to try through a regular user and then unlocking after that.

  • [SOLVED] Encryption hook doesn't prompt for key

    I'm trying to dual boot an encrypted arch (64bit luks encryption without lvm) and windows 8 on uefi. Everything installs pretty smoothly until it tries to decrypt the root partition, it doesn't prompt for the passphrase. Using a g55vw laptop, there's a wiki page for it apparently which I've been trying to follow. When I search for related problems most people solve it by moving the encrypt hook around but I've found that doesn't help
    (yes I run mkinitpio -p linux).
    My output when grub loads arch:
    :: running early hook [udev]
    :: running hook [udev]
    :: Triggering uevents...
    :: running hook [keymap]
    :: loading keymap . . . done
    :: running hook [encrypt]
    Waiting 10 seconds for device /dev/mapper/root ...
    Waiting 10 seconds for device /dev/mapper/root ...
    ERROR: device '/dev/mapper/root' not found. Skipping fsck
    ERROR: Unable to find root device '/dev/mapper/root'
    You are being dropped to a recovery shell
    Type 'exit' to try and continue booting
    sh: can't access tty: job control turned off
    /etc/default/grub
    GRUB_CMDLINE_LINUX_DEFAULT="quiet"
    GRUB_CMDLINE_LINUX="cryptsetup=/dev/sda2:root"
    GRUB_DISABLE_LINUX_UUID=true
    /etc/mkinitcpio.conf
    MODULES=""
    BINARIES=""
    FILES=""
    HOOKS="base udev autodetec modconf block keymap keyboard encrypt filesystems fsck"
    Last edited by DakotaTheGiraffe (2014-09-29 04:31:21)

    wow I tried that last install and it didn't work but it solved it this time. Thanks for your quick response

  • Crystal Report doesn't prompt for SAP credentials / errors out on refresh

    2 Environments tested with same results:
    <p>
    BOE XI 3.1 SP2 & BOE XI 3.1 SP2 FP2.5<br>
    SAP Intg Kit on mirrored SP/FP levels in each environment.
    <p>
    We've been successfully creating Crystal Reports against BEx queries in BW for months now as well as ECC master data.  We've also built universes and have WebI reports actively working against similar BEx queries in the same.  However, we're getting some curious behavior when we refresh the Crystal Reports against BEx queries in BW.  Verified all necessary transports and authorizations have been provided for both authoring, as well as refreshing/viewing on demand, etc.
    <p>
    We've setup all the Crystal Reports we're testing to:
    <p>
    a) Use custom database logon information specified here.<br>
    b) Specify a custom driver, leveraging the crdb_bwmdx driver<br>
    c) Prompt the user for database login
    <p>
    We have not enabled SNC as of yet.
    <p>
    1) When we refresh a WebI report hitting a BEx query with security applied, it doesn't prompt for the credentials, but we confirmed through tracing on the SAP side that if the user hits a paramater it has access to, the data comes through and when we hit a paramater they do not have access to, we can clearly see SAP reject it and it spits out a logical error on the BO side in InfoView and in the WebI logs on the BO server. 
    <p>
    2) When we refresh a Crystal Report hitting ECC data, we are prompted for the SAP credentials and everything works as expected
    <p>
    However:
    <p>
    3) When we refresh a Crystal Report hitting a BEx query in BW, we are not promtped for SAP credentials.  We immediately get the "LOV" prompts.  Now, if we use a test user in SAP that has NO SECURITY restrictions at all and open access to the query, the data comes through.  However, as soon as any security is applied to the query level, even if it is SAP ALL, we cannot retrieve the data.  Tracing is also strange, as we can see on the SAP side it buffer the selected paramaters, but unlike with the WebI reports, it never shows it reaching the point where it checks each paramater against what the role has access to.  An error is then spit back.  We run the same queries with the same users within SAP and get normal behavior.  It's as though as soon as we apply security to the query the mdx driver doesn't like it.  Dependant on the type of InfoView viewer we use, the errors we consistently get on the BO side are:
    <p>
    Interactive Viewer: "Error in File %reportname%: Encapsulating Page Failed"<br>
    Java Viewer:  "Error in File %reportname%: Database Connection Error"
    <p>
    Nothing glaring in the event logs on the BO servers or in the Crystal logs that I can see, however just because it isn't spitting a specific error in the crystal logs doesn't mean I'm not missing something because I don't know what to look for behavior wise. To reduce the liklihood that it has to do with the way the report was built, we've tried against the same query by building a report using standard methods, as well as the SAP Toolbar using a very plain jane report.  Same behavior.
    <p>
    Thoughts?
    Edited by: Jay Riddle on Mar 1, 2010 8:55 PM

    Hi,
    1) When we refresh a WebI report hitting a BEx query with security applied, it doesn't prompt for the credentials, but we confirmed through tracing on the SAP side that if the user hits a paramater it has access to, the data comes through and when we hit a paramater they do not have access to, we can clearly see SAP reject it and it spits out a logical error on the BO side in InfoView and in the WebI logs on the BO server.
    >> Which authentication are you using to logon to InfoView ? Whats the configuration in the Universe Connection for Authentication ?
    2) When we refresh a Crystal Report hitting ECC data, we are prompted for the SAP credentials and everything works as expected
    >> The user is using which authentication ? and against which system does he log on ?
    However:
    3) When we refresh a Crystal Report hitting a BEx query in BW, we are not promtped for SAP credentials. We immediately get the "LOV" prompts. Now, if we use a test user in SAP that has NO SECURITY restrictions at all and open access to the query, the data comes through. However, as soon as any security is applied to the query level, even if it is SAP ALL, we cannot retrieve the data. Tracing is also strange, as we can see on the SAP side it buffer the selected paramaters, but unlike with the WebI reports, it never shows it reaching the point where it checks each paramater against what the role has access to. An error is then spit back. We run the same queries with the same users within SAP and get normal behavior. It's as though as soon as we apply security to the query the mdx driver doesn't like it. Dependant on the type of InfoView viewer we use, the errors we consistently get on the BO side are:
    >> The user is using which authentication ? and against which system does he log on ?
    >> You mentioned security restrictions and I assume we talk about BI authorizations in form of data level security. If so - does the BW query include the authorization variables ?
    Ingo

  • I purchased and downloaded Lightroom 5.5. After installing it, I was prompted for the serial number. When I entered it an error message appeared saying it was an upgrade serial number and I need to enter my original purchase number. This was my original p

    I purchased and downloaded Lightroom 5.5. After installing it, I was prompted for the serial number. When I entered it an error message appeared saying it was an upgrade serial number and I need to enter my original purchase number. This was my original purchase, not an upgrade. Now what do I do?

    It sounds like you bought an upgrade from Adobe. How much did you pay? The upgrade is about $80, and the non-upgrade is about $150. If you bought an upgrade version and had no previous version, you would see what you're seeing.
    If that is the case and I were you, I'd call Adobe, and arrange for a refund and to order the correct version.
    Hal

  • Error while signing in. No prompt for Master Password.

    Firefox 3.6.15 (Mozilla/5.0 (Windows; U; Windows NT 5.1; sv-SE; rv:1.9.2.15) Gecko/20110303 )
    Firefox sync 1.7
    Sync NEVER works automatically. In a new FF session it always reports "Error While Signing In". If I try to connect manually I must go through the set-up dialogue and enter my Master Password etc and then it works (during that session).
    I have a Master Password defined.
    Sync doesn't prompt for that before trying to connect. So the connection fails and sync concludes that a set-up must be performed.
    Useless extension in current state.

    Hi,
    as per the error message is:
    "... The part /soap:Envelope/soap:Body was required to be signed by the policy with the transformations [], but the signature was not accepted. (Info: number of valid signatures: 1, number of accepted signer certificates: 0.) ..."
    I guess the cert. setup either on your side or the other system's side is not fully correct. Check whether all cert., priv keys and public keys are exchanged propperly and setup as trusted certs.
    Regards,
    Kai
    Edited by: Kai Lerch-Baier on Jul 9, 2009 1:24 PM

  • Since upgrading to iOS 6 I am not getting prompted for my password when I update apps. Why is this?

    When I updated apps on my ipad2 and iphone4S I used to get prompted for my password within a certain time.  So I could update a couple and then 10 minutes later if I wanted to download or update something else I would need to put in my password again. Since I upgraded to iOS6, I don't believe I am prompted for my password the same amount of times. I updated an app this am after not using iPad through the night and it just updated, no password required. This has me concerned now because sometimes I bump buttons by accident and now I will be charged for these accidents. What has happened to Apple's brilliant security?

    They've changed it in iOS and updates (and updates ONLY) do not require a password since it is really unnecessary as they have it on record that you were the one who bought the app. Why is more security needed, you aren't going to be charged for anything?
    Next time you update and app go to the App Store and try to buy something. You will be asked for your password.

  • I tried downloading adobe flash but it prompts for a password, which i don't have. any suggestions?

    i tried downloading adobe flash but it prompts for a password. none of the passwords i have (including that which i use with apple) works. any suggestions?

    You are prompted for a password before installing Flash? If so, this is your Mac's admin password, which doesn't have anything to do with your Apple ID unless you chose to use the same password for your computer admin login account as is used for your Apple ID.

  • HT1595 My apple tv stuck at setting date and time. Also when connecting yo network doesn't ask for network password

    My apple tv stuck at setting date and time. Also when connecting yo network doesn't ask for network password

    I just went through this last night. (Aug 15, 2013)
    What I did to get back up and running. This is not the first time I have lost the network connection with my Apple TV 3
    Products effected: Apple TV 3 and Home Sharing (My Apple TV 1 was not effected)
    Power down (unplug) the Apple TV and power down your router ( in my case, it is a FIOS router, flipping the on/off works fine).
    Power both items back up.
    At this point, I usually can reenter my Apple ID and PW. and reconnect Home Sharing.  But for some reason I was unable to reconnect last night but was able to get it reconnected in the morning. I was jut to tired to deal with it last night.
    A new issue that is was able to fix after a good nights sleep.
    I did figure out, (after trying to reenter my ID and PW many times and having it tell me that my ID and PW was wrong), that when using the Apple TV on screen keypad to type in the user ID. DO NOT use the ".com" keypad button. Instead type out each character for .com. ( or what ever ending you use for your ID account.)
    Once I typed out my full ID and PW. everything is back to 100%

  • HT1595 In a hilton hotel and the honors internet is recognized by my apple tv but it doesn't ask for the password.  It says it's connected but it won't bring up iTunes because it's not really connected.  help!

    I'm in a Hampton Inn trying to connect my apple tv to the wifi.  Apple TV recognizes and says it's connected but doesn't ask for the password and is not actually connected because it can't download Itunes.  How can I get the Apple TV to ask for a password.  I noticed another wifi connection from someone in another room and when I clicked on that the Apple TV asked for the password, but doesn't for the hhonors wifi.  Anyone know what to do? 

    Thanks vazandrew.  I had to call the provider, but they have 24/7 service.  They had to manually add the device.  Thanks for your help. 
    Hank

Maybe you are looking for