HPUX PAM Authentication configuration problems
Posted in 2005
We have a new HPUX server that we will be migrating our production IDS
database and software to. In this migrations we will be also migrating
from IDs 7.31 to IDS 9.4. In our testing everything went well with the
upgrade to IDS 9.4, but we are trying to get PAM authentication working
now and having no luck.
The new server is an HPUX 9000 rp7410 running B.11.11, running Kerberos
5.1 it looks like and running IDS 9.4.HC3.
What is happening is that if a person has their local(UNIX) password
the same as their network password (Windows 2000 Active Directory),
everything seems to be working for them. If the person has different
password the local will allow them in but the network will
not and sometimes crash the IDS engine. Working with IBM, we think we
may have the fixed the crashing but have not yet for all the ducks in a
line for this to work for everyone.
Does anyone have an idea what we have mis-configured? or willing to
send me their working conf files?
John David Adamski
Information Systems Specialist
Graceland University
---------------------------------------------------------------------------------
/etc/services
istarcarsi 1001/tcp # Port for istar connection
....
#
# Kerberos (Project Athena/MIT) services
#
kerberos5 88/udp kdc # Kerberos 5 kdc
klogin 543/tcp # Kerberos rlogin -kfall
kshell 544/tcp krcmd # Kerberos remote shell -kfall
ekshell 545/tcp krcmd # Kerberos encrypted remote
shell -kfall
kerberos 750/udp kdc # Kerberos (server) udp -kfall
kerberos 750/tcp kdc # Kerberos (server) tcp -kfall
kerberos_master 751/tcp kadmin # Kerberos kadmin
krbupdate 760/tcp kreg # Kerberos registration -kfall
kpasswd 761/tcp kpwd # Kerberos "passwd" -kfall
eklogin 2105/tcp # Kerberos encrypted rlogin
-kfall
---------------------------------------------------------------------------------
/etc/pam.conf
#
# Authentication management
#
login auth sufficient /usr/lib/security/libpam_krb5.1
login auth required /usr/lib/security/libpam_unix.1
#login auth required /usr/lib/security/libpam_unix.1
try_first_pass
sshd auth sufficient /usr/lib/security/libpam_krb5.1
sshd auth required /usr/lib/security/libpam_unix.1
#sshd auth required /usr/lib/security/libpam_unix.1
try_first_pass
su auth sufficient /usr/lib/security/libpam_krb5.1
su auth required /usr/lib/security/libpam_unix.1
#su auth required /usr/lib/security/libpam_unix.1
try_first_pass
dtlogin auth sufficient /usr/lib/security/libpam_krb5.1
dtlogin auth required /usr/lib/security/libpam_unix.1
#dtlogin auth required /usr/lib/security/libpam_unix.1
try_first_pass
dtaction auth sufficient /usr/lib/security/libpam_krb5.1
dtaction auth required /usr/lib/security/libpam_unix.1
#dtaction auth required /usr/lib/security/libpam_unix.1
try_first_pass
ftp auth sufficient /usr/lib/security/libpam_krb5.1
ftp auth required /usr/lib/security/libpam_unix.1
#ftp auth required /usr/lib/security/libpam_unix.1
try_first_pass
OTHER auth sufficient /usr/lib/security/libpam_krb5.1
OTHER auth required /usr/lib/security/libpam_unix.1
#OTHER auth required /usr/lib/security/libpam_unix.1
try_first_pass
---------------------------------------------------------------------------------
/etc/krb5.conf
[libdefaults]
default_realm = GRACELAND.EDU
default_tkt_enctypes = DES-CBC-MD5
default_tgs_enctypes = DES-CBC-MD5
cache_type = 2
[realms]
GRACELAND.EDU = {
kdc = xxxx.graceland.edu:88
admin_server = xxxx.graceland.edu:749
}
[domain_realm]
.graceland.edu = GRACELAND.EDU
[logging]
kdc = FILE:/var/adm/krb5kdc.log
admin_server = FILE:/var/adm/kadmin.log
default = FILE:/var/adm/krb5lib.log
---------------------------------------------------------------------------------
/opt/informix/etc/sqlhosts
#leto onipcshm leto leto
#carsitcp onsoctcp leto istarcarsi
leto onipcshm leto leto s=4,pam_serv=(OTHER),pamauth=(challenge)
carsitcp onsoctcp leto istarcarsi
s=4,pam_serv=(OTHER),pamauth=(challenge)