sshd cannot mount cifs shares

Bug #367918 reported by baum
This bug affects 2 people
Affects Status Importance Assigned to Milestone
libpam-mount (Ubuntu)
Won't Fix

Bug Description

release: intrepid
libpam-mount package version: 0.41-1

after an update in intrepid libpam-mount does not mount cifs shares anymore.
the update process asked if i wanted to use pam-auth-update to update my /etc/pam.d/common-* files. the answer was no.
now im unable to mount cifs shares.

here is the debug output from /var/log/auth.log

Apr 27 13:01:25 pc-cs sshd[14780]: Accepted publickey for username from port 44243 ssh2
Apr 27 13:01:25 pc-cs sshd[14780]: pam_mount(pam_mount.c:459) Entered pam_mount session stage
Apr 27 13:01:25 pc-cs sshd[14780]: pam_mount(pam_mount.c:480) back from global readconfig
Apr 27 13:01:25 pc-cs sshd[14780]: pam_mount(pam_mount.c:482) per-user configurations not allowed by pam_mount.conf.xml
Apr 27 13:01:25 pc-cs sshd[14780]: pam_mount(pam_mount.c:511) error trying to retrieve authtok from auth code
Apr 27 13:01:25 pc-cs sshd[14780]: pam_mount(pam_mount.c:195) enter read_password
Apr 27 13:01:25 pc-cs sshd[14780]: pam_mount(pam_mount.c:163) conv->conv(...): Conversation error
Apr 27 13:01:25 pc-cs sshd[14780]: pam_mount(pam_mount.c:514) error trying to read password
Apr 27 13:01:25 pc-cs sshd[14780]: pam_mount(pam_mount.c:547) done opening session (ret=7)
Apr 27 13:01:25 pc-cs sshd[14780]: pam_unix(sshd:session): session opened for user username by (uid=0)

#######pam configuration#########
account [new_authtok_reqd=done authinfo_unavail=ignore user_unknown=ignore default=done]
account sufficient
account [success=ignore default=1] uid > 10000
account [authinfo_unavail=ignore default=done]
account requisite
account requisite

auth required
auth [success=ignore default=1]
auth [success=done new_authtok_reqd=done default=2] likeauth nullok_secure shadow nodelay
auth [authinfo_unavail=1 success=ignore default=2]
auth [default=done] action=store use_first_pass
auth [success=done default=die] action=validate use_first_pass
auth [default=ignore] Delete cached password
auth [default=bad] action=update
auth required

password required difok=2 minlen=8 dcredit=2 ocredit=2 try_first_pass retry=3
password sufficient nullok use_authtok shadow md5 try_first_pass
password sufficient use_authtok use_first_pass
password required

session required
session required
session required skel=/etc/skel/ umask=0066
session required

auth optional use_first_pass
session optional use_first_pass

/etc/pam.d/sshd (either way if at the top or the bottom it doesnt work. it worked with ssh before the update with the 2 lines at the top)
#auth optional use_first_pass
#session optional use_first_pass
@include common-auth
@include common-account
@include common-password
@include common-session
@include common-pammount

####sshd configuration######
Port 22
Protocol 2
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key
UsePrivilegeSeparation yes
KeyRegenerationInterval 3600
ServerKeyBits 768
SyslogFacility AUTH
LogLevel INFO
LoginGraceTime 120
PermitRootLogin yes
StrictModes yes
RSAAuthentication yes
PubkeyAuthentication yes
IgnoreRhosts yes
RhostsRSAAuthentication no
HostbasedAuthentication no
PermitEmptyPasswords no
ChallengeResponseAuthentication no
PasswordAuthentication yes
X11Forwarding yes
X11DisplayOffset 10
PrintMotd no
PrintLastLog yes
TCPKeepAlive yes
AcceptEnv LANG LC_*
Subsystem sftp /usr/lib/openssh/sftp-server
UsePAM yes

the umount errors also there. but that has been opened long time ago and isnt fixed.

is my problem this a bug or is just the configuration after the update wrong.
i tried several setups but with no postive result.

Revision history for this message
James Page (james-page) wrote :

Marking 'Won't Fix' as Intrepid is no longer supported.

Changed in libpam-mount (Ubuntu):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.