Authentication AD and local scalix user

Discuss the Scalix Server software

Moderators: ScalixSupport, admin

rudi
Posts: 289
Joined: Mon Nov 22, 2004 6:53 am

Authentication AD and local scalix user

Postby rudi » Mon Apr 30, 2007 8:42 am

Hi,

I integrated Scalix in an AD environment. The authentication against AD and SWA works. But with an user only in scalix, not in AD, the auth. doesn't work. Here is my ual.remote:

auth sufficient om_krb5 use_first_pass
auth required pam_deny
account required om_auth
password required om_auth nullok
auth required om_auth nullok
auth sufficient om_krb5
auth required om_admin
auth required om_auth user_first_pass nullok
account required om_auth
password required om_auth nullok

Thanks for help!!!!!!!

florian
Scalix
Scalix
Posts: 3852
Joined: Fri Dec 24, 2004 8:16 am
Location: Frankfurt, Germany
Contact:

Postby florian » Tue May 01, 2007 2:07 am

First of all, all lines of a given type, in this case, auth, are taken to be relevant, independent of them being intermixed with other lines.

therefore, what you really need is one block, similar to

auth sufficient om_krb5
auth sufficient om_auth
auth required pam_deny

this will allow either login to succeed or then fail. If using other variations, you might want to read the comments in the ual.remote template and the man om_krb5 manpage, especially with regards to the

user_unknown=ignore
If the user is unknown to Kerberos, tell Scalix PAM to ignore this module.

option.

Florian.
Florian von Kurnatowski, Die Harder!


Return to “Scalix Server”



Who is online

Users browsing this forum: No registered users and 3 guests