<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body bgcolor="#FFFFFF">
<div>The shell is shown correctly as ksh in lsuser, so that doesnt appear to be an issue for the ID view. </div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div id="composer_signature">
<div dir="auto" style="font-size:88%; color:#364f67">Verzonden vanaf mijn Samsung-apparaat</div>
</div>
<br>
<br>
-------- Oorspronkelijk bericht --------<br>
Van: Luiz Fernando Vianna da Silva <luiz.vianna@tivit.com.br> <br>
Datum: 12-05-17 15:03 (GMT+01:00) <br>
Aan: "Hummelink, Wouter" <wouter.hummelink@kpn.com>, freeipa-users@redhat.com <br>
Onderwerp: Re: [Freeipa-users] IPA Compat + ID Views + AIX 7.1 <br>
<br>
<div>
<p><font face="Arial">Hello Wouter.</font></p>
<p><font face="Arial">It may seem silly, but try installing bash on one AIX server and test authenticating against that one.</font></p>
<p><font face="Arial">Its a single rpm with no dependencies. For me it did the trick and I ended up doing that on all my AIX servers.</font></p>
<p><font face="Arial">Let me know how it goes or if you have any issues.</font><br>
</p>
<div class="moz-signature"><link rel="File-List" href="Assinatura_arquivos/filelist.xml"><link rel="themeData" href="Assinatura_arquivos/themedata.thmx"><link rel="colorSchemeMapping" href="Assinatura_arquivos/colorschememapping.xml"><style>
<!--
@font-face
        {font-family:"Cambria Math"}
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin-top:0cm;
        margin-right:0cm;
        margin-bottom:10.0pt;
        margin-left:0cm;
        line-height:115%;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif"}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline}
span.SpellE
        {}
.MsoChpDefault
        {font-family:"Calibri","sans-serif"}
.MsoPapDefault
        {margin-bottom:10.0pt;
        line-height:115%}
@page WordSection1
        {margin:70.85pt 3.0cm 70.85pt 3.0cm}
div.WordSection1
        {}
-->
</style>
<div class="WordSection1">
<p class="MsoNormal" style="margin-bottom:0cm; margin-bottom:.0001pt; line-height:normal">
<span style="">Best <span class="SpellE">Regards</span></span><span style=""></span></p>
<p class="MsoNormal" style="margin-bottom:0cm; margin-bottom:.0001pt; line-height:normal">
<b><span style="">__________________________________________</span></b><span style=""></span></p>
<p class="MsoNormal" style="margin-bottom:0cm; margin-bottom:.0001pt; line-height:normal">
<b><span style="">Luiz Fernando Vianna da Silva</span></b><span style=""></span></p>
<p class="MsoNormal" style="margin-bottom:0cm; margin-bottom:.0001pt; line-height:normal">
<span style=""><br>
</span><span style=""></span></p>
</div>
</div>
<div class="moz-cite-prefix">Em 12-05-2017 09:47, <a class="moz-txt-link-abbreviated" href="mailto:wouter.hummelink@kpn.com">
wouter.hummelink@kpn.com</a> escreveu:<br>
</div>
<blockquote type="cite"><style>
<!--
@font-face
        {font-family:Calibri}
@font-face
        {font-family:Consolas}
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif"}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline}
span.EmailStyle17
        {font-family:"Calibri","sans-serif";
        color:windowtext}
span.CodeBlockChar
        {font-family:Consolas}
p.CodeBlock, li.CodeBlock, div.CodeBlock
        {margin-top:6.0pt;
        margin-right:0cm;
        margin-bottom:6.0pt;
        margin-left:39.7pt;
        text-indent:-11.35pt;
        border:none;
        padding:0cm;
        font-size:11.0pt;
        font-family:Consolas}
p.CodeBlockCxSpFirst, li.CodeBlockCxSpFirst, div.CodeBlockCxSpFirst
        {margin-top:6.0pt;
        margin-right:0cm;
        margin-bottom:0cm;
        margin-left:39.7pt;
        margin-bottom:.0001pt;
        text-indent:-11.35pt;
        border:none;
        padding:0cm;
        font-size:11.0pt;
        font-family:Consolas}
p.CodeBlockCxSpMiddle, li.CodeBlockCxSpMiddle, div.CodeBlockCxSpMiddle
        {margin-top:0cm;
        margin-right:0cm;
        margin-bottom:0cm;
        margin-left:39.7pt;
        margin-bottom:.0001pt;
        text-indent:-11.35pt;
        border:none;
        padding:0cm;
        font-size:11.0pt;
        font-family:Consolas}
p.CodeBlockCxSpLast, li.CodeBlockCxSpLast, div.CodeBlockCxSpLast
        {margin-top:0cm;
        margin-right:0cm;
        margin-bottom:6.0pt;
        margin-left:39.7pt;
        text-indent:-11.35pt;
        border:none;
        padding:0cm;
        font-size:11.0pt;
        font-family:Consolas}
.MsoChpDefault
        {font-family:"Calibri","sans-serif"}
@page WordSection1
        {margin:72.0pt 72.0pt 72.0pt 72.0pt}
div.WordSection1
        {}
-->
</style>
<div class="WordSection1">
<p class="MsoNormal">Hi All, </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">We’re running a POC to integrate IPA and AIX using AIX KRB5LDAP compound module.
</p>
<p class="MsoNormal">All the moving parts seem to be working on their own, however logging in doesn’t work with SSH on AIX reporting Failed password for user <xxx></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">We’re using ID views to overwrite the user shell and home dirs. (Since AIX will refuse a login with a nonexisting shell (like bash))</p>
<p class="MsoNormal">AIXs lsuser command is able to find all of the users it’s supposed to and su to IPA users works.</p>
<p class="MsoNormal">Also when a user tries to log in I can see a successful Kerberos conversation to our IPA server.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Tips for troubleshooting would be much appreciated, increasing SSH log level did not produce any meaningful logging.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">=============== Configuration Excerpt ================================================================</p>
<p class="MsoNormal">/etc/security/ldap/ldap.cfg:</p>
<p class="MsoNormal">ldapservers:ipaserver.example.org</p>
<p class="MsoNormal">binddn:uid=srvc-aixservice,cn=users,cn=accounts,dc=example,dc=org</p>
<p class="MsoNormal">bindpwd:{DESv2}<redacted></p>
<p class="MsoNormal">authtype:ldap_auth</p>
<p class="MsoNormal">useSSL:TLS</p>
<p class="MsoNormal">ldapsslkeyf:/etc/security/ldap/example.kdb</p>
<p class="MsoNormal">ldapsslkeypwd:{DESv2}4688216124E33174C03FBBB420 88FA8 932F219867AA7C2C552A12BEEC0CC67</p>
<p class="MsoNormal">useKRB5:yes</p>
<p class="MsoNormal">krbprincipal:host/aixlpar.example.org</p>
<p class="MsoNormal">krbkeypath:/etc/krb5/krb5.keytab</p>
<p class="MsoNormal">userattrmappath:/etc/security/ldap/2307user.map</p>
<p class="MsoNormal">groupattrmappath:/etc/security/ldap/2307group.map</p>
<p class="MsoNormal">userbasedn:cn=users,cn=aixtest,cn=views,cn=compat,dc=example,dc=org</p>
<p class="MsoNormal">groupbasedn:cn=groups,cn=aixtest,cn=views,cn=compat,dc=example,dc=org</p>
<p class="MsoNormal">netgroupbasedn:cn=ng,cn=compat,dc=example,dc=org</p>
<p class="MsoNormal">automountbasedn:cn=default,cn=automount,dc=example,dc=org</p>
<p class="MsoNormal">etherbasedn:cn=computers,cn=accounts,dc=example,dc=org</p>
<p class="MsoNormal">userclasses:posixaccount,account,shadowaccount</p>
<p class="MsoNormal">groupclasses:posixgroup</p>
<p class="MsoNormal"><span lang="NL">ldapport:389</span></p>
<p class="MsoNormal"><span lang="NL">searchmode:ALL</span></p>
<p class="MsoNormal"><span lang="NL">defaultentrylocation:LDAP</span></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">/etc/security/user default:</p>
<p class="MsoNormal">SYSTEM = KRB5LDAP or compat</p>
<p class="MsoNormal" style=""><b><span style="">/etc/methods.cfg</span></b></p>
<div style="border:none; border-left:solid
          windowtext 1.0pt; padding:0cm 0cm 0cm
          4.0pt; margin-left:1.0cm; margin-right:0cm">
<p class="CodeBlockCxSpFirst" style="margin-left:11.35pt">LDAP:<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/LDAP<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 =/usr/lib/security/LDAP64<span style=""> </span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">NIS:<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/NIS<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 = /usr/lib/security/NIS_64<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">DCE:<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/DCE<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">KRB5:<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program = /usr/lib/security/KRB5<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">       program_64 = /usr/lib/security/KRB5_64<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">       options = authonly,is_kadmind_compat=no,tgt_verify=yes,kadmind=no,keep_creds=yes,allow_expired_pwd=no<span style=""></span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt"><span style=""> </span></p>
<p class="CodeBlockCxSpMiddle" style="margin-left:11.35pt">KRB5LDAP:<span style="font-size:10.0pt"></span></p>
<p class="CodeBlockCxSpLast" style="margin-left:11.35pt">       options = auth=KRB5,db=LDAP<span style=""></span></p>
</div>
<p class="MsoNormal"> </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><span lang="NL">Met vriendelijke groet,</span></p>
<div style="border:none; border-bottom:solid
          windowtext 1.0pt; padding:0cm 0cm 1.0pt 0cm">
<p class="MsoNormal" style="border:none; padding:0cm"><span lang="NL">Wouter Hummelink</span></p>
</div>
<p class="MsoNormal"><span lang="NL" style="color:#1F497D">Technical Consultant - Enterprise Webhosting / Tooling & Automation</span></p>
<p class="MsoNormal"><span lang="NL" style="color:#1F497D">T: +31-6-12882447</span></p>
<p class="MsoNormal"><span lang="NL" style="color:#1F497D">E: <a href="mailto:wouter.hummelink@kpn.com">
wouter.hummelink@kpn.com</a></span></p>
<p class="MsoNormal"> </p>
</div>
</blockquote>
<br>
</div>
</body>
</html>