Unix Technical Forum

ssh & LDAP users (AIX 5.2 ML2)

This is a discussion on ssh & LDAP users (AIX 5.2 ML2) within the AIX Operating System forums, part of the Unix Operating Systems category; --> Hi, I've configured my server with LDAP, so all users (except system users) are authenticated in the LDAP server. ...


Go Back   Unix Technical Forum > Unix Operating Systems > AIX Operating System

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-04-2008, 10:40 PM
Javier
 
Posts: n/a
Default ssh & LDAP users (AIX 5.2 ML2)

Hi,

I've configured my server with LDAP, so all users (except system
users) are authenticated in the LDAP server.

The LDAP server is IBM Directory Server 4.1.

A LDAP user (e.g. jferruz) can login in the system if I use telnet or
console, but if I use ssh I get the next error message

Permission denied (publickey,password,keyboard-interactive)

Why? Have I configure anything in the ssh server? Have I configure
anything in AIX?

Thanks in advance,
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 01-04-2008, 10:40 PM
Erik C.J. Laan
 
Posts: n/a
Default Re: ssh & LDAP users (AIX 5.2 ML2)

Javier wrote:
> I've configured my server with LDAP, so all users (except system
> users) are authenticated in the LDAP server.
>
> The LDAP server is IBM Directory Server 4.1.
>
> A LDAP user (e.g. jferruz) can login in the system if I use telnet or
> console, but if I use ssh I get the next error message
>
> Permission denied (publickey,password,keyboard-interactive)
>
> Why? Have I configure anything in the ssh server? Have I configure
> anything in AIX?


I (and my collegea's) have the experience that SSH is more picky about
the password-expiration. Please check the people-entries in your LDAP
server have the 'shadowAccount' objectclass (when using the 2307 of
2307+AIX schema) or you have a uid=default account with the correct
settings in you LDAP server (when using the AIX schema).

HTH, Erik.
--
---------------------------------------------------------------------------
Erik C.J. Laan elaan at dds.nl
Please reply below the message, please cut unrelevant pieces from a reply.
---------------------------------------------------------------------------
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 05:18 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com