Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 28990

Summary: Openssh 3.7x, Windows and Ldap don't play together
Product: Gentoo Linux Reporter: Matthew Schick <matt>
Component: Current packagesAssignee: Daniel Ahlberg (RETIRED) <aliz>
Status: RESOLVED CANTFIX    
Severity: blocker CC: lcars, vapier
Priority: High    
Version: unspecified   
Hardware: x86   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---
Attachments: DEBUG3 output

Description Matthew Schick 2003-09-17 09:44:32 UTC
The 3.7 versions of Openssh will refuse to authenticate via password (didn't try
keys) for the ssh.com and Putty clients IF the server is using ldap
authentication.  I used the 3.6.1_p2-r3 ebuild and applied the patch from the
openssh site and all is well.

I'll be submitting the bug to the openssh bugzilla as soon as I get a password...

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Matthew Schick 2003-09-17 09:46:46 UTC
Created attachment 17895 [details]
DEBUG3 output

This is a dump from my logs of the failed login attempt from windows clients...
Comment 2 Andrea Barisani (RETIRED) gentoo-dev 2003-09-17 23:55:39 UTC
New OpenSSH version now is also incompatible when using PAM and 
PasswordAuthentication off with old ssh UNIX clients and older version of putty.

Note that when using PAM now setting PasswordAuthentication off is required, otherwise users can bypass PAM authentication...

:(
Comment 3 Daniel Ahlberg (RETIRED) gentoo-dev 2003-09-18 04:28:55 UTC
http://bugzilla.mindrot.org/show_bug.cgi?id=669 discuss this issue. Does it 
work if you upgrade the client? 
Comment 4 Matthew Schick 2003-09-18 06:24:11 UTC
Nope...  same problem occurs with the latest putty and ssh.com clients...  I haven't had any problems with the windows clients connecting to a server using the  "normal" passwd/shadow auth, which I find to be quite odd.
Comment 5 Daniel Ahlberg (RETIRED) gentoo-dev 2003-10-10 02:45:43 UTC
Reported in upstream bugzilla:
http://bugzilla.mindrot.org/show_bug.cgi?id=667
Comment 6 Daniel Ahlberg (RETIRED) gentoo-dev 2004-01-03 06:00:20 UTC
This is out of my hand. Closing becuse upstream closed bug.