<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Fri, May 12, 2017 at 3:31 PM,  <span dir="ltr"><<a href="mailto:wouter.hummelink@kpn.com" target="_blank">wouter.hummelink@kpn.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



<div bgcolor="#FFFFFF">
<div>The shell is shown correctly as ksh in lsuser, so that doesnt appear to be an issue for the ID view. </div></div></blockquote><div><br></div><div>My advice would be to start simple ,prove that your authentication works and you can develop a more elaborated setup afterwards. If you combine them all together it will be a trial and error which eventually will work at some point. <br></div><div>Do you have the correct keytabs in /etc/krb5/krb5.keytab ? can you run kinit (with password and with the keytab) from aix and get a ticket from Kerberos ? can you su to an IPA account ? do you have GSSAPIAuthentication enabled in sshd_config  ? <br><br></div><div>From what you've described i would suspect that your keytab is not correct , but that should be confirmed only by answering the questions above.  <br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div bgcolor="#FFFFFF">
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div id="m_-2572230151460738881composer_signature">
<div dir="auto" style="font-size:88%;color:#364f67">Verzonden vanaf mijn Samsung-apparaat</div>
</div>
<br>
<br>
-------- Oorspronkelijk bericht --------<br>
Van: Luiz Fernando Vianna da Silva <<a href="mailto:luiz.vianna@tivit.com.br" target="_blank">luiz.vianna@tivit.com.br</a>> <br>
Datum: 12-05-17 15:03 (GMT+01:00) <br>
Aan: "Hummelink, Wouter" <<a href="mailto:wouter.hummelink@kpn.com" target="_blank">wouter.hummelink@kpn.com</a>>, <a href="mailto:freeipa-users@redhat.com" target="_blank">freeipa-users@redhat.com</a> <br>
Onderwerp: Re: [Freeipa-users] IPA Compat + ID Views + AIX 7.1 <br><div><div class="h5">
<br>
<div>
<p><font face="Arial">Hello Wouter.</font></p>
<p><font face="Arial">It may seem silly, but try installing bash on one AIX server and test authenticating against that one.</font></p>
<p><font face="Arial">Its a single rpm with no dependencies. For me it did the trick and I ended up doing that on all my AIX servers.</font></p>
<p><font face="Arial">Let me know how it goes or if you have any issues.</font><br>
</p>
<div class="m_-2572230151460738881moz-signature">
<div class="m_-2572230151460738881WordSection1">
<p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:normal">
<span>Best <span class="m_-2572230151460738881SpellE">Regards</span></span><span></span></p>
<p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:normal">
<b><span>______________________________<wbr>____________</span></b><span></span></p>
<p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:normal">
<b><span>Luiz Fernando Vianna da Silva</span></b><span></span></p>
<p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:normal">
<span><br>
</span><span></span></p>
</div>
</div>
<div class="m_-2572230151460738881moz-cite-prefix">Em 12-05-2017 09:47, <a class="m_-2572230151460738881moz-txt-link-abbreviated" href="mailto:wouter.hummelink@kpn.com" target="_blank">
wouter.hummelink@kpn.com</a> escreveu:<br>
</div>
<blockquote type="cite">
<div class="m_-2572230151460738881WordSection1">
<p class="MsoNormal">Hi All, </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">We’re running a POC to integrate IPA and AIX using AIX KRB5LDAP compound module.
</p>
<p class="MsoNormal">All the moving parts seem to be working on their own, however logging in doesn’t work with SSH on AIX reporting Failed password for user <xxx></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">We’re using ID views to overwrite the user shell and home dirs. (Since AIX will refuse a login with a nonexisting shell (like bash))</p>
<p class="MsoNormal">AIXs lsuser command is able to find all of the users it’s supposed to and su to IPA users works.</p>
<p class="MsoNormal">Also when a user tries to log in I can see a successful Kerberos conversation to our IPA server.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Tips for troubleshooting would be much appreciated, increasing SSH log level did not produce any meaningful logging.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">=============== Configuration Excerpt ==============================<wbr>==============================<wbr>====</p>
<p class="MsoNormal">/etc/security/ldap/ldap.cfg:</p>
<p class="MsoNormal">ldapservers:<a href="http://ipaserver.example.org" target="_blank">ipaserver.example.<wbr>org</a></p>
<p class="MsoNormal">binddn:uid=srvc-aixservice,cn=<wbr>users,cn=accounts,dc=example,<wbr>dc=org</p>
<p class="MsoNormal">bindpwd:{DESv2}<redacted></p>
<p class="MsoNormal">authtype:ldap_auth</p>
<p class="MsoNormal">useSSL:TLS</p>
<p class="MsoNormal">ldapsslkeyf:/etc/security/<wbr>ldap/example.kdb</p>
<p class="MsoNormal">ldapsslkeypwd:{DESv2}<wbr>4688216124E33174C03FBBB420 88FA8 932F219867AA7C2C552A12BEEC0CC6<wbr>7</p>
<p class="MsoNormal">useKRB5:yes</p>
<p class="MsoNormal">krbprincipal:host/<a href="http://aixlpar.example.org" target="_blank">aixlpar.<wbr>example.org</a></p>
<p class="MsoNormal">krbkeypath:/etc/krb5/krb5.<wbr>keytab</p>
<p class="MsoNormal">userattrmappath:/etc/security/<wbr>ldap/2307user.map</p>
<p class="MsoNormal">groupattrmappath:/etc/<wbr>security/ldap/2307group.map</p>
<p class="MsoNormal">userbasedn:cn=users,cn=<wbr>aixtest,cn=views,cn=compat,dc=<wbr>example,dc=org</p>
<p class="MsoNormal">groupbasedn:cn=groups,cn=<wbr>aixtest,cn=views,cn=compat,dc=<wbr>example,dc=org</p>
<p class="MsoNormal">netgroupbasedn:cn=ng,cn=<wbr>compat,dc=example,dc=org</p>
<p class="MsoNormal">automountbasedn:cn=default,cn=<wbr>automount,dc=example,dc=org</p>
<p class="MsoNormal">etherbasedn:cn=computers,cn=<wbr>accounts,dc=example,dc=org</p>
<p class="MsoNormal">userclasses:posixaccount,<wbr>account,shadowaccount</p>
<p class="MsoNormal">groupclasses:posixgroup</p>
<p class="MsoNormal"><span lang="NL">ldapport:389</span></p>
<p class="MsoNormal"><span lang="NL">searchmode:ALL</span></p>
<p class="MsoNormal"><span lang="NL">defaultentrylocation:LDAP</span></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">/etc/security/user default:</p>
<p class="MsoNormal">SYSTEM = KRB5LDAP or compat</p>
<p class="MsoNormal"><b><span>/etc/methods.cfg</span></b></p>
<div style="border:none;border-left:solid windowtext 1.0pt;padding:0cm 0cm 0cm 4.0pt;margin-left:1.0cm;margin-right:0cm">
<p class="m_-2572230151460738881CodeBlockCxSpFirst" style="margin-left:11.35pt">LDAP:<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/LDAP<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 =/usr/lib/security/LDAP64<span> </span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">NIS:<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/NIS<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 = /usr/lib/security/NIS_64<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">DCE:<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/DCE<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">KRB5:<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/KRB5<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 = /usr/lib/security/KRB5_64<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">       options = authonly,is_kadmind_compat=no,<wbr>tgt_verify=yes,kadmind=no,<wbr>keep_creds=yes,allow_expired_<wbr>pwd=no<span></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt"><span> </span></p>
<p class="m_-2572230151460738881CodeBlockCxSpMiddle" style="margin-left:11.35pt">KRB5LDAP:<span style="font-size:10.0pt"></span></p>
<p class="m_-2572230151460738881CodeBlockCxSpLast" style="margin-left:11.35pt">       options = auth=KRB5,db=LDAP<span></span></p>
</div>
<p class="MsoNormal"> </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><span lang="NL">Met vriendelijke groet,</span></p>
<div style="border:none;border-bottom:solid windowtext 1.0pt;padding:0cm 0cm 1.0pt 0cm">
<p class="MsoNormal" style="border:none;padding:0cm"><span lang="NL">Wouter Hummelink</span></p>
</div>
<p class="MsoNormal"><span style="color:#1f497d" lang="NL">Technical Consultant - Enterprise Webhosting / Tooling & Automation</span></p>
<p class="MsoNormal"><span style="color:#1f497d" lang="NL">T: <a href="tel:+31%206%2012882447" value="+31612882447" target="_blank">+31-6-12882447</a></span></p>
<p class="MsoNormal"><span style="color:#1f497d" lang="NL">E: <a href="mailto:wouter.hummelink@kpn.com" target="_blank">
wouter.hummelink@kpn.com</a></span></p>
<p class="MsoNormal"> </p>
</div>
</blockquote>
<br>
</div>
</div></div></div>

<br>--<br>
Manage your subscription for the Freeipa-users mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" rel="noreferrer" target="_blank">https://www.redhat.com/<wbr>mailman/listinfo/freeipa-users</a><br>
Go to <a href="http://freeipa.org" rel="noreferrer" target="_blank">http://freeipa.org</a> for more info on the project<br></blockquote></div><br></div></div>