On Thu, Apr 04, 2013 at 01:43:12AM -0000, ClaudeD wrote:
> Steve's comment is interesting : our setup is with PBIS 7 (the successor
> of likewise-open) and it was installed with the PowerBroker package.
> However we are not using ecryptfs.
I understand; the issue is that the structure of these pam files must be
*generic* and work with any PAM modules you might choose to enable,
including either or both of lsass and ecryptfs. However, it doesn't because
the lsass module config is short-circuiting the stack.
> In /etc/pam.d/common-session, "session sufficient pam_lsass.so" should
> be replaced by what? optional?
It should be replaced by [success=ok default=ignore].
On Thu, Apr 04, 2013 at 01:43:12AM -0000, ClaudeD wrote:
> Steve's comment is interesting : our setup is with PBIS 7 (the successor
> of likewise-open) and it was installed with the PowerBroker package.
> However we are not using ecryptfs.
I understand; the issue is that the structure of these pam files must be
*generic* and work with any PAM modules you might choose to enable,
including either or both of lsass and ecryptfs. However, it doesn't because
the lsass module config is short-circuiting the stack.
> In /etc/pam. d/common- session, "session sufficient pam_lsass.so" should
> be replaced by what? optional?
It should be replaced by [success=ok default=ignore].