Solaris pam_ldap and passwordless logins

Dear all,
http://docs.sun.com/app/docs/doc/816-4556/6maort2te?a=view
states:
After you enable pam_ldap account management, all users must provide a password any time they log in to the system. A login password is required for authentication. Therefore, nonpassword-based logins using tools such as rsh, rlogin, or ssh will fail.
Can somebody confirm that this is really true?
Background:
We are using shosts.equiv, which worked fine with NIS. Now we switched to LDAP and everything works fine -- except passwordless logins. Password-based logins work fine. But passwordless (publickey or shosts) gives this message in /var/adm/messages:
sshd[9023]: [ID 778364 auth.warning] libsldap: server xx.xx.xx.xx does not provide account information without passwordDoes anybody see a chance of getting passwordless logins with pam_ldap to work at all?
Cheers,
Jan

I don't know if LPK (LDAP Public Key) helps, pls try and let us know.
http://www.opendarwin.org/en/projects/openssh-lpk/
(google "ldap public key")
Gary

Similar Messages

  • Pam_ldap and nss_ldap

    hello !
    i made and put two packages in incoming: pam_ldap and nss_ldap
    LDAP authentication is now possible with Arch !
    Comete
    # Contributor: Comete <[email protected]>
    pkgname=pam_ldap
    pkgver=167
    pkgrel=1
    pkgdesc="The pam_ldap module provides the means for Solaris and Linux workstations to authenticate against LDAP directories, and to change
    their passwords in the directory."
    url="http://www.padl.com/OSS/pam_ldap.html"
    depends=('pam')
    makedepends=('pam')
    conflicts=()
    replaces=()
    backup=('/etc/pam_ldap.conf')
    install=
    source=(http://www.padl.com/download/$pkgname.tgz)
    md5sums=()
    build() {
    cd $startdir/src/$pkgname-$pkgver
    ./configure
    --libdir=/lib
    --with-ldap-conf-file=/etc/pam_ldap.conf
    make || return 1
    make prefix=$startdir/pkg/usr install
    md5sums=('05bc1ae27087583e20d948659c6b0d61')
    # Contributor: Comete <[email protected]>
    pkgname=nss_ldap
    pkgver=212
    pkgrel=1
    pkgdesc="The nss_ldap module provides the means for Linux and Solaris workstations to resolve the entities defined in RFC 2307 from LDAP d
    irectories."
    url="http://www.padl.com/OSS/nss_ldap.html"
    depends=('pam')
    makedepends=('pam')
    conflicts=()
    replaces=()
    backup=('/etc/libnss-ldap.conf')
    install=
    source=(http://www.padl.com/download/$pkgname.tgz)
    md5sums=()
    build() {
    cd $startdir/src/$pkgname-$pkgver
    ./configure
    --with-ldap-conf-file=/etc/libnss-ldap.conf
    --with-ldap=openldap
    --libdir=/lib
    --enable-schema-mapping
    --enable-rfc2307bis
    make || return 1
    make prefix=$startdir/pkg/usr install
    md5sums=('707869f5bde25145d29f84f7ff591d9f')

    Also make sure to start nscd on bootup. Otherwise your LDAP server will get many queries. A simple ls -la in your homedirectory will generate a query for each file in it.
    Also, if you don't run nscd, pacman will segfault on synching packagelists, because it's statical linked to NSS.

  • Hi I do not want iTunes to open up automatically when I turn on my macbook pro.  I tried going to System Preferences Users and Groups Login Items and then I took iTunes off the list but it still opens up automatically when I turn on my laptop.

    Hi I do not want iTunes to open up automatically when I turn on my macbook pro.  I tried going to System Preferences>Users and Groups>Login Items and then I took iTunes off the list but it still opens up automatically when I turn on my laptop. What should I do?

    Hi r,
    Make sure you close iTunes before shutdown.  And you're quite welcome.

  • I am trying to stop programs from opening automatically when I turn my computer on.  I tried system preferences users and groups login items...then I deleted them from the list but it did nothing.

    I am trying to stop programs from opening automatically when I turn my computer on.  I tried system preferences>users and groups>login items...then I deleted them itunes and emial from the list but it did nothing.  They continue to open up every time I turn on my Macbook Pro.

    Hi r,
    It sounds like you're running Lion?
    Have you tried running Verify and/or Repair Disk?
    Have you tried running Repair Permissions?
    Do you have at least 15% free space available on your HD?

  • I'm new to Solaris 10 and need help to setup ftp server

    hello!
    I just installed Solaris 10 and I'm trying to setup an ftp server (with ftpd) but I don't know how to do that
    my server doesn't need any security or authentication
    I'm looking for the default shared files directory
    Also wondering what to change in what configuration file...
    This OS looks quite similar to some linux I used before but the differencies are big enough to drive me crazy
    anyway thanks for your help.
    Any advice is welcome :-)

    cd /etc/ftpd
    vi ftpusers
    put a # in front of root and any other users that you wish to be able to ftp
    then svcadm restart ftp
    If you want to set up an anonymous ftp server, there is a little more involvement

  • Screen Sharing and Remote Login suddenly stopped working

    I have had Screen Sharing and Remote Login turned on on my iMac for several weeks and they have been working fine up until now. I have been accessing the computer via VNC programs and command-line ssh logins from other computers on the same local network. When I tried to connect today, i was given the following error message.
    ssh: connect to host xxx.xxx.xxx.xxx port 22: No route to host
    I have all of the required settings turned on in System preferences and there are no firewalls or router settings blocking it. I connected the two computers together via ethernet cable and the error message still occurred.
    I can ssh from the machine to 127.0.0.1, so the ssh server is running. I can ssh to other locations from the laptop i am attempting to connect with, so that's not the problem either. I just spent an hour on the phone with the apple tech support line and they couldn't figure anything out either. Can anybody figure something out?

    have you tried the obvious - restarting the computers involved and the router?

  • How to find out the version of the SFK that is installed on Solaris 9 and 8

    On Solaris 8 and 9, I would I like to find out the version of the SFK and the leadville driver that is installed.
    Is it possible to find out this information ? Thanks.

    DatabaseMetaData.getDriverVersion()
    http://java.sun.com/j2se/1.4.2/docs/api/java/sql/DatabaseMetaData.html#getDriverVersion()

  • Error on install of 125136-18 and 125137-18 on jdk-6u16 on Solaris 9 and 10

    We have jdk-6u16 installed on Solaris 9/10 (sparc and sparcv9). When trying to install the patches to update to 6u17 (125136-18 and 125137-18) the patches error with the following below, and leave SUNWj6cfg and SUNWj6rtx in I-Lock status.
    Any suggestions?
    # patchadd 125136-18
    Checking installed patches...
    Verifying sufficient filesystem capacity (dry run method)...
    Installing patch packages...
    Pkgadd failed. See /var/tmp/125136-18.log.5887 for details
    Patchadd is terminating.
    # cat 125136-18.log.5887
    /var/sadm/pkg/SUNWj6cfg/install/postinstall: /var/tmp/125136-18.SUNWj6cfg: does not exist
    pkgadd: ERROR: postinstall script did not complete successfully
    Installation of <SUNWj6cfg> failed.

    On Solaris 9, its state is either cpu0 or cpu1,
    depending on the time I call 'top'. Does that mean
    it is actually running on either cpu0 or cpu1?Should be.
    What
    is the difference between the 'cpu0' state and the
    'run' state?A thread can be sleeping (it doesn't have anything to do), or runnable. Although it's runnable, it doesn't mean that it's running right at that instant.
    Note that it's difficult to get a good view of the situation with 'top' (or almost any other program). Because whenever 'top' looks, 'top' will always be running, even though it's only running a fraction of the time.
    And does it mean all 4 threads are
    running/assigned to cpu0 (or cpu1)? No. Each thread is independently executed. But since you only have 2 processors, and since 'top' has to be running when it runs, you'll only ever see your process on at most one other cpu.
    You might want to use 'prstat' and 'prstat -L'. The first shows one line per process, the second one line per thread.
    On Solaris 10, the state shows 'cpu'. Does it mean
    it is running? And does it mean that each thread may
    run on a different CPU therefore the state does not
    show any particular CPU number? Is it correct that
    Solaris 9 assign the CPU on a per-process basis and
    Solaris 10 on a per-thread basis?I don't know exactly what top does or doesn't do. You might try 'prstat' instead.
    There is no difference at this level between Solaris 9 and 10. All will schedule on a per-thread basis.
    Darren

  • How do I install dual-boot Solaris 8 and Solaris 9 on one hard disk ?

    I tried to install Solaris 8 and Solaris 9 on same disk using CDs, but
    the second installation overwrote the first Solaris which was installed
    previoudly on the half-disk size partition of same disk.
    How do I install two Solarises on one hard disk ?
    Thanks
    Yakov

    There are no tricks to get Solaris to dual boot on the same drive. Just allocate and pick the free slices not used by the first Solaris install when you put in the second install. Technically speaking there is nothing preventing you from running seven separately bootable Solaris instances on the same drive (one of 8 available slices is overlap -- slice 2) provided you use a swap file on a root partition instead of reserving a whole slice for swap.

  • ESR and ID login issue in Clustered SAP PI 7.3 environment

    Hi PI Gurus,
    We currently have issue for login in ESR and ID of PI 7.3 systems from desktop which is in customer VLAN.
    Please find below status for PI systems :
    Development and Quality PI systems as standalone : ESR and ID login works fine
    Regression and Production PI systems as clustered : ESR and ID login does not work.
    Client Java Web start version : 1.6
    PI system JVM version : 1.6
    Please find attached screenshot for error that we get while login.
    Request you to provide your inputs to resolve this issue.
    Thanks in Advance.
    Regards,
    Hanumant

    Hi Pavan,
    Thank you for details,
    I checked hostname for all PI systems and FQDN are maintained for them in "hosts" file.
    Also one more point, it shows exeception when clicked on ESR or ID links:
    java.io.IOException: Authentication failure
        at sun.net.www.protocol.http.HttpURLConnection.getInputStream(Unknown Source)
        at java.net.HttpURLConnection.getResponseCode(Unknown Source)
        at com.sun.deploy.net.BasicHttpRequest.doRequest(Unknown Source)
    Do you have any Idea which authentication is failing here?
    Regards,
    Hanumant

  • Best Practice in maintaining multiple apps and user logins

    Hi,
    My company is just starting to use APEX, and none of us (the developers) have worked on this before either. It is greatly appreciated if we can get some help here.
    We have developed quite a few applications in the same workspace. Now, we are going to setup UAT and PRD environments and also trying to understand what the best practice is to maintain multiple apps and user logins.
    Many of you have already worked on APEX environment for sometime, can you please provide some input?
    Should we create multiple apps(projects) for one department or should we create one app for one department?
    Currently we have created multiple apps for one department, but, we are not sure if a user can login once and be able to access to all the authenticated apps.
    Thank you,
    LC

    LC,
    I am not sure how much of this applies to your situation - but I will share what I have done.
    I built a single 700+ page application for my department - other areas create separate smaller applications.
    The approach I chose is flexible enough to accomdate both.
    I built a separate access control application(Control) in its own schema.
    We use database authenication fo this app - an oracle account is required.
    We prefer to use LDAP for authentication for the user applications.
    For users that LDAP is not option - an encrypted password is stored - reset via email.
    We use position based security - priviliges are based on job functions.
    We have applications, appilcations have roles , roles have access to components(tabs,buttons,unmasked card numbers,etc.)
    We have positions that are granted application roles - they inherit access to the role components.
    Users have a name, a login, a position, and a site.
    We have users on both the East Coast and the West Coast, we use the site in a sys_context
    and views to emulate VPD. We also use the role components,sys_contexts and views to mask/unmask
    card numbers without rewriting the dependent objects(querys,reports,views,etc.)
    The position based security has worked well, when someone moves,
    we change the position they are assigned to and they immediately have the privileges they need.
    If you are interested I can rpovide more detail.
    Bill

  • Auto policy updates from DC1 to DC2 work but break user and admin login in DC2.

    Auto policy updates from DC1 to DC2 work but break user and admin login in DC2.
    Is there any solution to this ?

    You will need to update your transformation rules to match the URL/hosts for dc2.

  • Sapinst not started for PI 7.1 on Solaris 1064bit and Oracle10

    Hello,
    We are running NW 7.10 PI 7.1 installation on Sun Solaris 10 and Oracle 10.2.0.4 platform. We are using the following installation DVDs for installing PI.
    Installation Master   = 51033240_21
    Java Component = 51033242
    UC Kernel = 51033245
    We are doing following to run ./sapinst
    1. log on as root
    2. set JAVA_HOME, TEMP and DISPLAY
    3. go to master DVD and run ./sapinst
    The instgui is not showing any error Problematicc sentence structure ./SAPinst is just getting frozen. We used another script ./sapinstgui from the same directory and it shows us some logon screen with port 21212 in the GUI. However, when we try clicking logon it does nothing.
    We've ensured that port 21212 or any other port that supposed to be used by SAPinst are not blocked on the firewall or not used by any other application. Host and DNSfiles are also okay. Based on one of the previous forum   /etc/nss*.conf files also exist in our PI host.  Not sure why the SAPinst GUI is not started.
    We've also ensured that we need any new SAPinst support pach from marketplace, however current installation master dvd is the latest one release in March 09 and there are no further patches released by SAP.
    Please help if anyone of you have faced this issue before.
    Harshal

    I tried ./sapinst SAPINST_DIALOG_PORT=<free_port_number> as well as the default port number. Both of them fails.
    normally  ./sapinst itself should establish all the port automatically that it uses. Which currently is not happening.
    Do you want me to copy installation master dvd for Solaris on windows work station from where i'm initiating it through Xmanager session and try running ?  The installation master dvd that i'm currenty using is for Solaris platform which meanase ./sapinst is compiled for Solaris, how will it be supported by Windows ?
    Harshal

  • Need Pre_requisites to install Solution Manager in Solaries 9 and Oracle 10

    Hi Administrators,
    In my project, we have planned to implement Solution Manager 7.0 in O/S Solaries 9 and Database Oracle 10.2.
    We are implementing this Solution Manager in already existing SAP server.
    We have server like TSAPNGN, In this server already our QAS ECC 5.0 and QAS BW 3.5 are exist and running in this server.
    I need information like, What is the pre_requisites to install SAP application, where already another SAP exist in Server.
    Appreciate ur help.
    Thanks & Regards,
    Jagan.

    Hello
    There is no difference whether you are installing the Solution Manager on a separate server or an existing server already containing the DEV system. you will get some idea from these Notes
    21960 Several instances/systems on one UNIX computer
    28392 Two R/3 Systems on one Windows NT Server
    322653 DB6: Two or several systems on a host
    I think, you should go for Central System installtion for the Solman, with it's own database.
    and what do you mean by 'standalone solman' here ?
    Just go 'installation and upgrades' -> My application components -> SAP Solution Manager -> Solman 7.0 or EHp1 -> Installation and upgrades
    For installation guide
    installation and upgrade guiedes -> SAP components -> SAP Solution manager -> Select solman version

  • My macbook wont except my administrator name even after i reset my admin pasword and keychain login password so I am unable to install or make any account changes. Suggestions anyone? I've been at this for hours now....

    My macbook wont except my administrator name even after I reset my admin pasword and keychain login password so I am unable to install or make any account changes. I can't even install any software. Suggestions anyone? I've been at this for hours now....

    Try Resetting the PRAM

Maybe you are looking for

  • OBIEE 11G BI publisher?

    Hello Experts, I have two questions 1) I am trying to create a BI publisher report by using analysis. i tried to create a data model with the analysis and when i clicked it i am getting a window shared and users and when i click on the shared i am no

  • Vendors Payment Before Due Date

    Dear All, We could like to restric the release of Vendor payment before the due date. We feel there is a system in SAP by which it should give a Error/ warining message (pop up) if any payment is made before the due date. Do suggest. Regards,

  • Double click on icon to run java application

    Hello, I want to write a code in java so that if i double click on icon the program will start showing the window as it appears when we double click acrobat and the we get the main screen. How this can be achieved? Thank you

  • Trouble connecting to MySQL

    I am new to this software and am trying to connect to a MySQL database on my webhost. I download the MySQL connector and created the server type. I go to add datasource and test the connection and am getting connection refused:connect. My connection

  • Very Slow Save for Web in CS3 Mac

    I have Photoshop CS3 Extended 10.0.1 running on a 2.16GHz Intel MacBook running 10.4.11 with 2Gb of installed RAM and around 30% free hard disk space. Regardless of file size or dimension, Save For Web is painfully slow to load and to save out. Optim