Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Openldap with PAM and sssd, cant login to cluster #226

Open
maneshmistry8 opened this issue Jan 15, 2025 · 1 comment
Open

Openldap with PAM and sssd, cant login to cluster #226

maneshmistry8 opened this issue Jan 15, 2025 · 1 comment

Comments

@maneshmistry8
Copy link

I'm a bit at wits end with this and I cant figure it out. I have a k3s cluster that is running a slurm stack. On the slurm stack there is a login pod that has a metalLB provided external IP address. I've loaded in a set of ldif files that work on my previous cluster and have a PAM config that works on my home lab. If i remove the option that doesn't deny access on incorrect password everyone can login

On login ldap is being queried but then all users just get permission denied when you try and ssh to the cluster. I can su - user on the pod and getent user and getent group both work I can even do an ldapsearch on the pod I just cant login with my ldap password. My last thought was that the certificate on the openldap stack is expired so maybe its quietly failing becasue of this. I'll post the version of this we are using when I'm off this train its about a year or so old.

Thanks any help would be appreciated.

@maneshmistry8
Copy link
Author

The version we are using is 2.6.6 and the below is the error I'm getting from openldap-0

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant