https://bugzilla.novell.com/show_bug.cgi?id=776600 https://bugzilla.novell.com/show_bug.cgi?id=776600#c0 Summary: pam winbind settings are only set if we join a windows domain using Yast as a client Classification: openSUSE Product: openSUSE 12.2 Version: RC 2 Platform: i586 OS/Version: openSUSE 12.2 Status: NEW Severity: Enhancement Priority: P5 - None Component: Samba AssignedTo: samba-maintainers@SuSE.de ReportedBy: lynn@steve-ss.com QAContact: samba-maintainers@SuSE.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/22.0.1190.0 Safari/537.1 SUSE/22.0.1190.0 If we are ourselves the domain controller such as with Samba4 AD, we have no way of setting pam winbind in /etc/pam.d Reproducible: Always Steps to Reproduce: 1.Install Samba4 DC 2.call the samba binary 3.edit /etc/nsswitch.conf to contain passwd: and group: to contain winbind 4.attempt to login on the DC Actual Results: We are authenticated correctly via Kerberos but we cannot login: The pam settings for winbind are not set. Expected Results: We can login. The workaround is not to use winbind on the Samba4 DC. e.g. nss-pam-ldapd works fine This is discussed in this thread: http://lists.opensuse.org/opensuse/2012-08/msg00476.html -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.