sshd authentication with pam

From: Victor Engle (sunmanager_at_summerseas.com)
Date: 01/31/05

  • Next message: Jeremy Ahl: "SUMMARY: RSC console hangs"
    Date: Mon, 31 Jan 2005 10:51:12 -0500
    To: sunmanagers@sunmanagers.org
    
    

    Hello List,

    I have a Sun One Directory server version 5.2 configured as a naming
    service for solaris 8 and 9 machines. Everything worked smoothly until I
    tried to enforce passwd expiration and account lockout via the directory
    server.

    I changed this line in the pam stack for sshd from this

    sshd account required pam_unix_account.so.1

    to this

    sshd account required pam_unix_account.so.1 server_policy

    Then I logged in with a user ID whose account would expire soon and the
    system printed the " account expiration" warning as expected. Account
    lockout worked as well. The problem is that if I try to login using
    public key authentication the login fails. If I remove the server_policy
    parameter from the pam.conf line above then public key and password
    logins succeed but fail to print the expiration warning and ignore
    lockout settings.

    Telnet logins work as expected but we would really like to have ssh
    logins work correctly with password expiration and account lockout. We
    are using the most recent openssh version, 3.9p1 from sunfreeware.com.
    The only change made to sshd_config was the UsePAM parameter was set to
    'yes'.

    Any ideas?

    Thanks,
    Vic
    _______________________________________________
    sunmanagers mailing list
    sunmanagers@sunmanagers.org
    http://www.sunmanagers.org/mailman/listinfo/sunmanagers


  • Next message: Jeremy Ahl: "SUMMARY: RSC console hangs"

    Relevant Pages

    • sshd authentication via pam with ldap
      ... I tried to enforce passwd expiration and account lockout via the ... Then I logged in with a user ID whose account would expire soon and the ... Telnet logins work as expected but we would really like to have ssh ... logins work correctly with password expiration and account lockout. ...
      (comp.unix.solaris)
    • Re: Set Account Expiration Date for group in domain.
      ... I want to have each user from group_3 get disabled his account every 3 ... I think you mean password expiration date rather than account expiration ... applies to all users (if their passwords expire). ... would also have to be done with a script that runs on that day. ...
      (microsoft.public.windows.server.scripting)
    • Re: Account lockouts
      ... for reusable passwords and the AAA infrastructures that rely upon them? ... In that context, account lockout policy -- duration, threshold, lockout ... > cracking attacks. ...
      (microsoft.public.security)
    • Re: User accounts are being locked out
      ... Password Policy and Account Lockout Policy are both domain-wide policies, ... machineA and machineB. ... download updated signature files located on a network share. ...
      (microsoft.public.windows.server.general)
    • Re: Set Account Expiration Date for group in domain.
      ... I want to have each user from group_3 get disabled his account every 3 ... An account can have only one expiration date, ... applies to all users (if their passwords expire). ... would also have to be done with a script that runs on that day. ...
      (microsoft.public.windows.server.scripting)