Unix Technical Forum

SEO

vBulletin Search Engine Optimization


Go Back   Unix Technical Forum > Unix Operating Systems > HP-UX Operating System

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-17-2008, 06:04 AM
jda
 
Posts: n/a
Default Kerberos not allowing the network password for some users

Production server rp7410 hp11v2, Test server rp5450 hp11v2 both have
Dec '07 Quality Pack installed. Both up to date on patches. Network
is a Windows Active Directory (AD).

The Test server is a clone of the Production server, and I've been
working with HP support on a couple of sambaclient problems. We have
been using the Test server to try solutions and when we are confident
the changes/patches works on the Test sever I do the same changes on
the Production server.

Before I started to make any changes on the Production server users
could use either their 'network' or their 'unix' (local) passwords
when logging in. However somewhere along the way this stopped working
on the Production server for thoses people that their network and
local unix passwords are different, it still works on the Test server.

syslogs does show this, when some with different passwords ties
network password first:

Mar 12 14:33:02 leto sshd[12931]: while verifying tgt[Unknown code
____ 255]
Mar 12 14:33:02 leto sshd[12931]: [Authentication failed] Password not
valid
Mar 12 14:33:08 leto sshd[12931]: error: PAM: Authentication failed
for User1 from uaxxxx.graceland.edu
Mar 12 14:33:11 leto sshd[12931]: [Authentication failed] Password not
valid
Mar 12 14:33:11 leto sshd[12931]: Accepted password for User1 from
10.125.xx.xx port 4891 ssh2
Mar 12 14:33:11 leto sshd[12931]: Pam Creds are not available


To the best of my knowledge both servers are configured the same for
Kerberos and PAM. I have checked /etc/krb5.conf & /etc/pam.krb5 on
both systems and they are identical. (HP support wanted me to change
which AD server we point to) Changing the file back has no affect.

Besides /etc/krb5.conf what other files might I look at so see if
there is some slight difference between the two servers that Kerberos
uses?

John

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 03-17-2008, 06:04 AM
Tom Smith
 
Posts: n/a
Default Re: Kerberos not allowing the network password for some users

Are your clocks synchronized?

jda wrote:
> Production server rp7410 hp11v2, Test server rp5450 hp11v2 both have
> Dec '07 Quality Pack installed. Both up to date on patches. Network
> is a Windows Active Directory (AD).
>
> The Test server is a clone of the Production server, and I've been
> working with HP support on a couple of sambaclient problems. We have
> been using the Test server to try solutions and when we are confident
> the changes/patches works on the Test sever I do the same changes on
> the Production server.
>
> Before I started to make any changes on the Production server users
> could use either their 'network' or their 'unix' (local) passwords
> when logging in. However somewhere along the way this stopped working
> on the Production server for thoses people that their network and
> local unix passwords are different, it still works on the Test server.
>
> syslogs does show this, when some with different passwords ties
> network password first:
>
> Mar 12 14:33:02 leto sshd[12931]: while verifying tgt[Unknown code
> ____ 255]
> Mar 12 14:33:02 leto sshd[12931]: [Authentication failed] Password not
> valid
> Mar 12 14:33:08 leto sshd[12931]: error: PAM: Authentication failed
> for User1 from uaxxxx.graceland.edu
> Mar 12 14:33:11 leto sshd[12931]: [Authentication failed] Password not
> valid
> Mar 12 14:33:11 leto sshd[12931]: Accepted password for User1 from
> 10.125.xx.xx port 4891 ssh2
> Mar 12 14:33:11 leto sshd[12931]: Pam Creds are not available
>
>
> To the best of my knowledge both servers are configured the same for
> Kerberos and PAM. I have checked /etc/krb5.conf & /etc/pam.krb5 on
> both systems and they are identical. (HP support wanted me to change
> which AD server we point to) Changing the file back has no affect.
>
> Besides /etc/krb5.conf what other files might I look at so see if
> there is some slight difference between the two servers that Kerberos
> uses?
>
> John
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 03-17-2008, 06:04 AM
jda
 
Posts: n/a
Default Re: Kerberos not allowing the network password for some users

On Mar 12, 2:59*pm, Tom Smith <sm...@cag.zko.hp.com> wrote:
> Are your clocks synchronized?
>


Yes, well within a second or two . The two HPUX servers seem to be
dead on and the windows server 1-2 seconds faster.

John

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 09:30 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62