[tac_plus] tac_plus with pam-ldap to AD implementation

Linda Slater lslater at yorku.ca
Mon Mar 17 18:58:55 UTC 2014


Hi 

I have read and tried many of the information listed in the many postings 
but I am still having an issue. 

I am running on ubuntu 12.04lts.   I want my users to log into the Cisco 
router devices using their AD credentials  The server that TACplus is 
running on has been joined to the AD test domain.  I have also confirmed 
that I can bind to the remote LDAP server.    Note I have also tested this 
with krb5 _kerboros) and that also works.

My tacacs.conf file for my tacplus user pointing to PAM  login = PAM. When 
my test user tries to login to the Cisco router , the username and 
password that is accepted happens to be the username and password that is 
in the /etc/passwd file on the ubuntu server rather than the AD username 
and password?   How do I get PAM to communicate with the remote LDAP 
server?    Note I have configured my ldap files per the posting by Adam.

I get the following error message 

pam_ldap: reconnecting to LDAP server...
 pam_ldap: reconnecting to LDAP server (sleeping 1 seconds)...

note: AD and LDAP server are functioning and respond when I use the 
ldapsearch command. kerberos , kinit,klist ,etc.

Regards
Lin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.shrubbery.net/pipermail/tac_plus/attachments/20140317/8896605b/attachment.html>


More information about the tac_plus mailing list