<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Fri, May 12, 2017 at 2:32 PM,  <span dir="ltr"><<a href="mailto:wouter.hummelink@kpn.com" target="_blank">wouter.hummelink@kpn.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US">
<div class="gmail-m_7926556652586221045WordSection1">
<p class="MsoNormal">Hi All, <u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">We’re running a POC to integrate IPA and AIX using AIX KRB5LDAP compound module.
<u></u><u></u></p>
<p class="MsoNormal">All the moving parts seem to be working on their own, however logging in doesn’t work with SSH on AIX reporting Failed password for user <xxx><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">We’re using ID views to overwrite the user shell and home dirs. (Since AIX will refuse a login with a nonexisting shell (like bash))</p></div></div></blockquote><div> </div><div>Why don't you just use the /bin/sh as default shell in IPA  ? In aix 
/bin/sh is the same as /bin/ksh and in linux it is a symlink to 
/bin/bash .  <br><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div lang="EN-US"><div class="gmail-m_7926556652586221045WordSection1"><p class="MsoNormal"><u></u><u></u></p>
<p class="MsoNormal">AIXs lsuser command is able to find all of the users it’s supposed to and su to IPA users works.<u></u><u></u></p>
<p class="MsoNormal">Also when a user tries to log in I can see a successful Kerberos conversation to our IPA server. <br></p></div></div></blockquote><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div lang="EN-US"><div class="gmail-m_7926556652586221045WordSection1"><p class="MsoNormal"><u></u><u></u></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Tips for troubleshooting would be much appreciated, increasing SSH log level did not produce any meaningful logging.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">=============== Configuration Excerpt ==============================<wbr>==============================<wbr>====<u></u><u></u></p>
<p class="MsoNormal">/etc/security/ldap/ldap.cfg:<u></u><u></u></p>
<p class="MsoNormal">ldapservers:ipaserver.example.<wbr>org<u></u><u></u></p>
<p class="MsoNormal">binddn:uid=srvc-aixservice,cn=<wbr>users,cn=accounts,dc=example,<wbr>dc=org<u></u><u></u></p>
<p class="MsoNormal">bindpwd:{DESv2}<redacted><u></u><u></u></p>
<p class="MsoNormal">authtype:ldap_auth<u></u><u></u></p>
<p class="MsoNormal">useSSL:TLS<u></u><u></u></p>
<p class="MsoNormal">ldapsslkeyf:/etc/security/<wbr>ldap/example.kdb<u></u><u></u></p>
<p class="MsoNormal">ldapsslkeypwd:{DESv2}<wbr>4688216124E33174C03FBBB420 88FA8 932F219867AA7C2C552A12BEEC0CC6<wbr>7<u></u><u></u></p>
<p class="MsoNormal">useKRB5:yes<u></u><u></u></p>
<p class="MsoNormal">krbprincipal:host/aixlpar.<wbr><a href="http://example.org">example.org</a><u></u><u></u></p>
<p class="MsoNormal">krbkeypath:/etc/krb5/krb5.<wbr>keytab<u></u><u></u></p>
<p class="MsoNormal">userattrmappath:/etc/security/<wbr>ldap/2307user.map<u></u><u></u></p>
<p class="MsoNormal">groupattrmappath:/etc/<wbr>security/ldap/2307group.map<u></u><u></u></p>
<p class="MsoNormal">userbasedn:cn=users,cn=<wbr>aixtest,cn=views,cn=compat,dc=<wbr>example,dc=org<u></u><u></u></p>
<p class="MsoNormal">groupbasedn:cn=groups,cn=<wbr>aixtest,cn=views,cn=compat,dc=<wbr>example,dc=org<u></u><u></u></p>
<p class="MsoNormal">netgroupbasedn:cn=ng,cn=<wbr>compat,dc=example,dc=org<u></u><u></u></p>
<p class="MsoNormal">automountbasedn:cn=default,cn=<wbr>automount,dc=example,dc=org<u></u><u></u></p>
<p class="MsoNormal">etherbasedn:cn=computers,cn=<wbr>accounts,dc=example,dc=org<u></u><u></u></p>
<p class="MsoNormal">userclasses:posixaccount,<wbr>account,shadowaccount<u></u><u></u></p>
<p class="MsoNormal">groupclasses:posixgroup<u></u><u></u></p>
<p class="MsoNormal"><span lang="NL">ldapport:389<u></u><u></u></span></p>
<p class="MsoNormal"><span lang="NL">searchmode:ALL<u></u><u></u></span></p>
<p class="MsoNormal"><span lang="NL">defaultentrylocation:LDAP<u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">/etc/security/user default:<u></u><u></u></p>
<p class="MsoNormal">SYSTEM = KRB5LDAP or compat</p></div></div></blockquote><div> </div><div>I am using the following settings in in /etc/security/user:<br></div><div>SYSTEM = KRB5LDAP<br></div><div>registry = KRB5LDAP<br></div><div>it works for AIX5,6 and 7 in my setup. <br> <br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div lang="EN-US"><div class="gmail-m_7926556652586221045WordSection1"><p class="MsoNormal"><u></u><u></u></p>
<p class="MsoNormal"><b><span style="font-size:12pt;font-family:"times new roman","serif"">/etc/methods.cfg<u></u><u></u></span></b></p>
<div style="border-width:medium medium medium 1pt;border-style:none none none solid;border-color:currentcolor currentcolor currentcolor windowtext;padding:0cm 0cm 0cm 4pt;margin-left:1cm;margin-right:0cm">
<p class="gmail-m_7926556652586221045CodeBlockCxSpFirst" style="margin-left:11.35pt">LDAP:<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/LDAP<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 =/usr/lib/security/LDAP64<span style="font-size:12pt;font-family:"times new roman","serif""> <u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">NIS:<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/NIS<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 = /usr/lib/security/NIS_64<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">DCE:<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/DCE<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">KRB5:<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/KRB5<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 = /usr/lib/security/KRB5_64<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">       options = authonly,is_kadmind_compat=no,<wbr>tgt_verify=yes,kadmind=no,<wbr>keep_creds=yes,allow_expired_<wbr>pwd=no<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt"><span style="font-size:12pt;font-family:"times new roman","serif""><u></u> <u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpMiddle" style="margin-left:11.35pt">KRB5LDAP:<span style="font-size:10pt"><u></u><u></u></span></p>
<p class="gmail-m_7926556652586221045CodeBlockCxSpLast" style="margin-left:11.35pt">       options = auth=KRB5,db=LDAP<span style="font-size:12pt;font-family:"times new roman","serif""><u></u><u></u></span></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><span lang="NL">Met vriendelijke groet,<u></u><u></u></span></p>
<div style="border-width:medium medium 1pt;border-style:none none solid;border-color:currentcolor currentcolor windowtext;padding:0cm 0cm 1pt">
<p class="MsoNormal" style="border-width:medium;border-style:none;border-color:currentcolor;padding:0cm"><span lang="NL">Wouter Hummelink<u></u><u></u></span></p>
</div>
<p class="MsoNormal"><span style="color:rgb(31,73,125)" lang="NL">Technical Consultant - Enterprise Webhosting / Tooling & Automation<u></u><u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)" lang="NL">T: <a value="+31612882447">+31-6-12882447</a><u></u><u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)" lang="NL">E: <a>
wouter.hummelink@kpn.com</a><u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>

<br>--<br>
Manage your subscription for the Freeipa-users mailing list:<br>
<a href="https://www.redhat.com/">https://www.redhat.com/</a><wbr>mailman/listinfo/freeipa-users<br>
Go to <a href="http://freeipa.org">http://freeipa.org</a> for more info on the project<br></blockquote></div><br></div></div>