Advertisement
Guest User

201503 SSH+PAM+Kerberos

a guest
Mar 13th, 2015
252
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 13.58 KB | None | 0 0
  1. ::::: /var/log/debug.log :::::
  2.  
  3. 1 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_dispatch(): calling pam_sm_authenticate() in /usr/lib/pam_krb5.so.5
  4. 2 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_user(): entering
  5. 3 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_USER
  6. 4 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  7. 5 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_user(): returning PAM_SUCCESS
  8. 6 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_sm_authenticate(): Got user: user2
  9. 7 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_RUSER
  10. 8 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  11. 9 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_sm_authenticate(): Got ruser: (null)
  12. 10 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_SERVICE
  13. 11 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  14. 12 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_sm_authenticate(): Got service: sshd
  15. 13 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_sm_authenticate(): Context initialised
  16. 14 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_sm_authenticate(): Done krb5_cc_register()
  17. 15 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): entering: 'auth_as_self'
  18. 16 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): returning NULL
  19. 17 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_sm_authenticate(): Created principal: user2
  20. 18 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_sm_authenticate(): Done krb5_parse_name()
  21. 19 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_sm_authenticate(): Got principal: user2@REALM.LOCAL
  22. 20 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_authtok(): entering
  23. 21 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_RHOST
  24. 22 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  25. 23 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_HOST
  26. 24 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  27. 25 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_OLDAUTHTOK
  28. 26 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  29. 27 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): entering: 'try_first_pass'
  30. 28 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): returning ''
  31. 29 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_AUTHTOK
  32. 30 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  33. 31 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): entering: 'use_first_pass'
  34. 32 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): returning NULL
  35. 33 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): entering: 'authtok_prompt'
  36. 34 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): returning NULL
  37. 35 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_subst(): entering: 'Password:'
  38. 36 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_subst(): returning PAM_SUCCESS
  39. 37 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): entering: 'echo_pass'
  40. 38 Mar 14 00:51:20 nfs-client sshd[2790]: in openpam_get_option(): returning NULL
  41. 39 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_vprompt(): entering
  42. 40 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_CONV
  43. 41 Mar 14 00:51:20 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  44. 42 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_vprompt(): returning PAM_SUCCESS
  45. 43 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_set_item(): entering: PAM_AUTHTOK
  46. 44 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_set_item(): returning PAM_SUCCESS
  47. 45 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_AUTHTOK
  48. 46 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  49. 47 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_authtok(): returning PAM_SUCCESS
  50. 48 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Got password
  51. 49 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_get_option(): entering: 'no_user_check'
  52. 50 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_get_option(): returning NULL
  53. 51 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_get_option(): entering: 'no_user_check'
  54. 52 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_get_option(): returning NULL
  55. 53 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Done getpwnam()
  56. 54 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_get_option(): entering: 'forwardable'
  57. 55 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_get_option(): returning ''
  58. 56 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Credential options initialised
  59. 57 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Got TGT
  60. 58 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Credentials stashed
  61. 59 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_get_option(): entering: 'debug'
  62. 60 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_get_option(): returning ''
  63. 61 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Credentials stash verified
  64. 62 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_data(): entering: 'ccache'
  65. 63 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_data(): returning PAM_NO_MODULE_DATA
  66. 64 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Credentials stash not pre-existing
  67. 65 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_set_data(): entering: 'ccache'
  68. 66 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_set_data(): returning PAM_SUCCESS
  69. 67 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Credentials stash saved
  70. 68 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Done cleanup
  71. 69 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Done cleanup2
  72. 70 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_sm_authenticate(): Done cleanup3
  73. 71 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_dispatch(): /usr/lib/pam_krb5.so.5: pam_sm_authenticate(): success
  74. 72 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_dispatch(): calling pam_sm_acct_mgmt() in /usr/local/lib/pam_ldap.so
  75. 73 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_user(): entering
  76. 74 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_USER
  77. 75 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  78. 76 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_user(): returning PAM_SUCCESS
  79. 77 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_data(): entering: 'PAM_LDAPD_CTX'
  80. 78 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_data(): returning PAM_NO_MODULE_DATA
  81. 79 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_set_data(): entering: 'PAM_LDAPD_CTX'
  82. 80 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_set_data(): returning PAM_SUCCESS
  83. 81 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_SERVICE
  84. 82 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  85. 83 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_RUSER
  86. 84 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  87. 85 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_RHOST
  88. 86 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  89. 87 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): entering: PAM_TTY
  90. 88 Mar 14 00:51:23 nfs-client sshd[2790]: in pam_get_item(): returning PAM_SUCCESS
  91. 89 Mar 14 00:51:23 nfs-client sshd[2790]: nslcd authorisation; user=user2
  92. 90 Mar 14 00:51:23 nfs-client sshd[2790]: authorization succeeded
  93. 91 Mar 14 00:51:23 nfs-client sshd[2790]: in openpam_dispatch(): /usr/local/lib/pam_ldap.so: pam_sm_acct_mgmt(): success
  94. 92 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/lib/pam_krb5.so.5
  95. 93 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_get_option(): entering: 'no_ccache'
  96. 94 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_get_option(): returning NULL
  97. 95 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_get_option(): entering: 'no_user_check'
  98. 96 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_get_option(): returning NULL
  99. 97 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_sm_setcred(): Establishing credentials
  100. 98 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_get_item(): entering: PAM_USER
  101. 99 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_get_item(): returning PAM_SUCCESS
  102. 100 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_sm_setcred(): Got user: user2
  103. 101 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_sm_setcred(): Context initialised
  104. 102 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_sm_setcred(): Got euid, egid: 0 0
  105. 103 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_get_data(): entering: 'ccache'
  106. 104 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_get_data(): returning PAM_NO_MODULE_DATA
  107. 105 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_sm_setcred(): Done cleanup3
  108. 106 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_sm_setcred(): Done seteuid() & setegid()
  109. 107 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_dispatch(): /usr/lib/pam_krb5.so.5: pam_sm_setcred(): failed to retrieve user credentials
  110. 108 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/local/lib/pam_ldap.so
  111. 109 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_dispatch(): /usr/local/lib/pam_ldap.so: pam_sm_setcred(): success
  112. 110 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/lib/pam_unix.so.5
  113. 111 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_dispatch(): /usr/lib/pam_unix.so.5: pam_sm_setcred(): success
  114. 112 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_dispatch(): calling pam_sm_open_session() in /usr/local/lib/pam_mkhomedir.so
  115. 113 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_get_user(): entering
  116. 114 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_get_item(): entering: PAM_USER
  117. 115 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_get_item(): returning PAM_SUCCESS
  118. 116 Mar 14 00:51:23 nfs-client sshd[2769]: in pam_get_user(): returning PAM_SUCCESS
  119. 117 Mar 14 00:51:23 nfs-client sshd[2769]: in openpam_dispatch(): /usr/local/lib/pam_mkhomedir.so: pam_sm_open_session(): success
  120. 118 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/lib/pam_krb5.so.5
  121. 119 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_get_option(): entering: 'no_ccache'
  122. 120 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_get_option(): returning NULL
  123. 121 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_get_option(): entering: 'no_user_check'
  124. 122 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_get_option(): returning NULL
  125. 123 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_sm_setcred(): Establishing credentials
  126. 124 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_get_item(): entering: PAM_USER
  127. 125 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_get_item(): returning PAM_SUCCESS
  128. 126 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_sm_setcred(): Got user: user2
  129. 127 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_sm_setcred(): Context initialised
  130. 128 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_sm_setcred(): Got euid, egid: 0 0
  131. 129 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_get_data(): entering: 'ccache'
  132. 130 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_get_data(): returning PAM_NO_MODULE_DATA
  133. 131 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_sm_setcred(): Done cleanup3
  134. 132 Mar 14 00:51:23 nfs-client sshd[2791]: in pam_sm_setcred(): Done seteuid() & setegid()
  135. 133 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_dispatch(): /usr/lib/pam_krb5.so.5: pam_sm_setcred(): failed to retrieve user credentials
  136. 134 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/local/lib/pam_ldap.so
  137. 135 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_dispatch(): /usr/local/lib/pam_ldap.so: pam_sm_setcred(): success
  138. 136 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/lib/pam_unix.so.5
  139. 137 Mar 14 00:51:23 nfs-client sshd[2791]: in openpam_dispatch(): /usr/lib/pam_unix.so.5: pam_sm_setcred(): success
  140. 138 Mar 14 00:51:50 nfs-client sshd[2769]: in openpam_dispatch(): calling pam_sm_close_session() in /usr/local/lib/pam_mkhomedir.so
  141. 139 Mar 14 00:51:50 nfs-client sshd[2769]: in openpam_dispatch(): /usr/local/lib/pam_mkhomedir.so: pam_sm_close_session(): success
  142. 140 Mar 14 00:51:50 nfs-client sshd[2769]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/lib/pam_krb5.so.5
  143. 141 Mar 14 00:51:50 nfs-client sshd[2769]: in openpam_dispatch(): /usr/lib/pam_krb5.so.5: pam_sm_setcred(): success
  144. 142 Mar 14 00:51:50 nfs-client sshd[2769]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/local/lib/pam_ldap.so
  145. 143 Mar 14 00:51:50 nfs-client sshd[2769]: in openpam_dispatch(): /usr/local/lib/pam_ldap.so: pam_sm_setcred(): success
  146. 144 Mar 14 00:51:50 nfs-client sshd[2769]: in openpam_dispatch(): calling pam_sm_setcred() in /usr/lib/pam_unix.so.5
  147. 145 Mar 14 00:51:50 nfs-client sshd[2769]: in openpam_dispatch(): /usr/lib/pam_unix.so.5: pam_sm_setcred(): success
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement