From: | "Jason Tesser" <JTesser(at)nbbc(dot)edu> |
---|---|
To: | <pgsql-general(at)postgresql(dot)org> |
Subject: | Re: pam authentication for postgres |
Date: | 2003-11-27 02:11:38 |
Message-ID: | 04875CB4331F0240A0AD66F970978651160A2D@paul |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-general |
> Please post a comprehensive description of what you're trying to do
> together with the configuration files you use.
I thought I did that sorry. I am trying to get Postgres to authenticate through Pam so I can authenticate to Active
Directory on our network. All the steps I took are posted below. If you notice the messages I pasted from my logs
you will see that winbind is authenticating ok but for some reason Postgres still denies access.
<snip>
>
> here is the messages I have is the log from trying to log in
>
> Nov 26 08:55:16 localhost postgresql(pam_unix)[22693]: authentication failure; logname= uid=26 euid=26 tty= ruser= rhost= user=cherring
> Nov 26 08:55:16 localhost pam_winbind[22693]: user 'cherring' granted acces
>
> as you can see winbind is actually granting access but fro some reason poasgres still denies it.
> weird. any ideas.
>
<snip> postgresql/linux/pam setup.
>>
>> 0) configure postgresql for pam, for example
>>
>> [root ( at ) omega tmp]# grep pam /usr/local/pgsql/data/pg_hba.conf
>> host all all 137.75.0.0 255.255.0.0 pam
>>
>> 1) create a /etc/pam.d/postgresql entry, here's how i did mine
>>
>> [root ( at ) omega tmp]# cp /etc/pam.d/passwd /etc/pam.d/postgresql
>>
>> i don't know if it's the best setup, but it works! mine looks like this
>>
>> [root ( at ) omega tmp]# cat /etc/pam.d/postgresql
>> #%PAM-1.0
>> auth required /lib/security/pam_stack.so service=system-auth
>> account required /lib/security/pam_stack.so service=system-auth
>> password required /lib/security/pam_stack.so service=system-auth
>
From | Date | Subject | |
---|---|---|---|
Next Message | Nicholas Walker | 2003-11-27 02:21:38 | Executing Shell Command |
Previous Message | Alex Satrapa | 2003-11-27 01:49:39 | Re: disaster recovery |