From:
[email protected]
Package: libpam-ldap
Version: 164-2
Severity: grave
Tags: sarge security
When I configure /etc/pam_ldap.conf to use the host attribute (set 'pam_check_host_attr yes') and use the 'login' pam.d file from the
examples directory in /usr/share/doc/libpam-ldap/examples/pam.d, users
that are not allowed to login can still login. The "Access denied for
this host" is shown but not effective.
Users that are not supposed to be able to login on my server can still
login.
Transcript:
-----------
Login: fedora
Password:
Access denied for this host
Last login: Fri Aug 20 11:15:40 2004 from sarge
[fedora@sarge Fedora]$
The correct behaviour would be to disallow access to the system.
My /etc/pam.d/login file:
-------------------------
#%PAM-1.0
auth required /lib/security/pam_securetty.so
auth required /lib/security/pam_nologin.so
auth sufficient /lib/security/pam_ldap.so
auth required /lib/security/pam_unix_auth.so try_first_pass
account sufficient /lib/security/pam_ldap.so
account required /lib/security/pam_unix_acct.so
password required /lib/security/pam_cracklib.so
password required /lib/security/pam_ldap.so
password required /lib/security/pam_pwdb.so use_first_pass
session required /lib/security/pam_unix_session.so
#session optional /lib/security/pam_console.so
My /etc/nsswitch.conf file:
---------------------------
passwd: files ldap
group: files ldap
shadow: files ldap
hosts: files dns ldap
networks: files
protocols: db files
services: db files
ethers: db files
rpc: db files
netgroup: files ldap
automount: files ldap
aliases files ldap
libnss-ldap is also installed and configured to use LDAP.
I am using Debian 3.1 (sarge), kernel 2.6.7-1-686-smp
Version of dependencies of libpam-ldap:
sarge:~# COLUMNS=120 dpkg -l | egrep '(libc6|libldap2|libpam0g)'
ii libc6 2.3.2.ds1-13
ii libc6-dev 2.3.2.ds1-13
ii libgpmg1 1.19.6-12.1
ii libgpmg1-dev 1.19.6-12.1
ii libldap2 2.1.30-2
ii libldap2-dev 2.1.30-2
ii libpam0g 0.76-22
ii libpam0g-dev 0.76-22
--
Rik Theys
----------------------------------------------------------------
<<Any errors in spelling, tact or fact are transmission errors>>
--
To UNSUBSCRIBE, email to
[email protected]
with a subject of "unsubscribe". Trouble? Contact
[email protected]
--- SoupGate-Win32 v1.05
* Origin: you cannot sedate... all the things you hate (1:229/2)