From: "Mad-Max-Traveller@yandex.ru" <Mad-Max-Traveller@yandex.ru>
To: community@lists.altlinux.org
Subject: Re: [Comm] Ввод в домен на базе Win 2003 рабочей станции под управлением Simply Linux
Date: Mon, 23 Aug 2010 17:07:45 +0700
Message-ID: <4C724871.9040606@yandex.ru> (raw)
In-Reply-To: <4C6CD705.8090800@yandex.ru>
19.08.2010 14:02, Mad-Max-Traveller@yandex.ru пишет:
>
> Но не знаю как правильно настроить PAM. Плохо понимаю структуру
> этого файла,
> а толковую документацию на русском не нашел.
> В /etc/pam.d есть симлинк system-auth на system-auth-local. Если
> пересоздать симлинк system-auth на system-auth-winbind то в систему
> невозможно залогинится, ни доменными пользователями, ни локальными.
>
> Содержимое /etc/pam.d/system-auth-winbind
> #%PAM-1.0
> auth required pam_tcb.so shadow fork prefix=$2a$ count=8
> nullok
> auth optional pam_mount.so
> auth sufficient pam_winbind.so use_first_pass
>
> account required pam_tcb.so shadow fork
> account sufficient pam_succeed_if.so uid< 500 quiet
> account [default=bad success=ok user_unknown=ignore]
> pam_winbind.so
>
> password required pam_passwdqc.so config=/etc/passwdqc.conf
> password required pam_tcb.so use_authtok shadow fork
> prefix=$2a$ count=8 nullok write_to=tcb
>
> session required pam_tcb.so
> session required pam_mktemp.so
> session required pam_limits.so
> session optional pam_mount.so
> # We use pam_mkhomedir to create home dirs for incoming domain users
> # Note used umask, it will result in rwxr-x--x access rights
> session required pam_mkhomedir.so skel=/etc/skel/ umask=0026
> session include system-auth
>
> Прошу вашей помощи в настройке. Заранее спасибо.
>
Неужели ни кто не знает?
next prev parent reply other threads:[~2010-08-23 10:07 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-08-19 7:02 Mad-Max-Traveller
2010-08-23 10:07 ` Mad-Max-Traveller [this message]
2010-08-23 12:57 ` Michael Shigorin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4C724871.9040606@yandex.ru \
--to=mad-max-traveller@yandex.ru \
--cc=community@lists.altlinux.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
ALT Linux Community general discussions
This inbox may be cloned and mirrored by anyone:
git clone --mirror http://lore.altlinux.org/community/0 community/git/0.git
# If you have public-inbox 1.1+ installed, you may
# initialize and index your mirror using the following commands:
public-inbox-init -V2 community community/ http://lore.altlinux.org/community \
mandrake-russian@linuxteam.iplabs.ru community@lists.altlinux.org community@lists.altlinux.ru community@lists.altlinux.com
public-inbox-index community
Example config snippet for mirrors.
Newsgroup available over NNTP:
nntp://lore.altlinux.org/org.altlinux.lists.community
AGPL code for this site: git clone https://public-inbox.org/public-inbox.git