LDAP PAM configuration fails authentication (pam_acct_mgmt returns permission denied)

Bug #865093 reported by Angelo P. Castellani
26
This bug affects 4 people
Affects Status Importance Assigned to Milestone
Light Display Manager
Incomplete
Medium
Unassigned
lightdm (Ubuntu)
Expired
Medium
Unassigned
Precise
Expired
Medium
Unassigned

Bug Description

The greeter is not started for the following error:
[+0.88s] DEBUG: pam_acct_mgmt(0x9f9fde8, 0) -> 6 (Permission denied)

Full lightdm.log is attached.

Got on Ubuntu Oneiric Ocelot with latest updates installed:
$ dpkg -l lightdm
ii lightdm 1.0.0-0ubuntu4 Display Manager

Revision history for this message
Angelo P. Castellani (ang3l0) wrote :
Revision history for this message
Robert Ancell (robert-ancell) wrote :

What distribution are you using?

Changed in lightdm:
status: New → Incomplete
Revision history for this message
Angelo P. Castellani (ang3l0) wrote :

I am using Ubuntu Oneiric Ocelot with the latest updates installed.

Changed in lightdm:
status: Incomplete → New
description: updated
description: updated
Revision history for this message
Sebastien Bacher (seb128) wrote :

is there anything special in your pam setup? do you get the issue every time? can you log in from a vt?

Revision history for this message
Angelo P. Castellani (ang3l0) wrote :

> is there anything special in your pam setup?

Yes, I do have ldap authentication configured.

I will try to use lightdm after disabling ldap authetication.

> do you get the issue every time?

Yes.

> can you log in from a vt?

Yes, both using a vt and using gdm.

Revision history for this message
Angelo P. Castellani (ang3l0) wrote :

> I will try to use lightdm after disabling ldap authetication.

Even after disabling LDAP authentication using pam-auth-update, the lightdm does not start with the reported error.

I have just tested it on a second machine with a similar setup, and after upgrading at Oneiric I have this bug.

Revision history for this message
Sebastien Bacher (seb128) wrote :

Ok, I will let Robert comment but nobody else is getting that issue so far so it's likely something specific in the pam configuration of your machines that trigger the bug

Revision history for this message
Angelo P. Castellani (ang3l0) wrote :

My machines are configured with LDAP authentication following the Ubuntu Server guide:
https://help.ubuntu.com/11.04/serverguide/C/openldap-server.html#openldap-auth-config

You may want to try reproducing that configuration...

Revision history for this message
Robert Ancell (robert-ancell) wrote :

This is probably due to bug 863630 which is fixed in 1.0.2

Changed in lightdm (Ubuntu):
status: New → Triaged
Changed in lightdm:
status: New → Triaged
importance: Undecided → High
importance: High → Medium
Changed in lightdm (Ubuntu):
importance: Undecided → Medium
summary: - pam_acct_mgmt error prevents lightdm to start
+ LDAP PAM configuration fails authentication (pam_acct_mgmt returns
+ permission denied)
Revision history for this message
Angelo P. Castellani (ang3l0) wrote :

I can test 1.0.2.. there exists a packaged version of it?

Today I tested 1.0.1, but the bug is still present in it.

Revision history for this message
Sebastien Bacher (seb128) wrote :

1.0.2 sould get a SRU to Oneiric soon

Revision history for this message
Mose (olivier-caspari) wrote :

hello !!
bug around.
before the login in grphique
start a text interface: "ctrl+alt+F1" login you.
and make,

sudo service gdm reload

bye

Revision history for this message
Robert Ancell (robert-ancell) wrote :

Could you please test this in lightdm 1.1.6 (precise)? There has been a change to the way PAM is handled that should resolve this issue.

Changed in lightdm:
status: Triaged → Incomplete
Changed in lightdm (Ubuntu Precise):
status: Triaged → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for lightdm (Ubuntu Precise) because there has been no activity for 60 days.]

Changed in lightdm (Ubuntu Precise):
status: Incomplete → Expired
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for lightdm (Ubuntu) because there has been no activity for 60 days.]

Changed in lightdm (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.