Bug 223664

Summary: Samba-authenticated users missing some permissions
Product: [openSUSE] openSUSE 10.2 Reporter: James Mason <james>
Component: OtherAssignee: Ludwig Nussel <lnussel>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Major    
Priority: P5 - None CC: samba-maintainers
Version: RC 1   
Target Milestone: ---   
Hardware: i686   
OS: SUSE Other   
Whiteboard:
Found By: Beta-Customer Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Attachments: Error message when accessing disc
Kmix configuration window
Error message when starting Amarok

Description James Mason 2006-11-24 18:53:01 UTC
When I authenticate against my AD server, I am unable to mount/view the contents of CDs/DVDs, access the sound server, and burn CDs.

If I log in as a local user (root or non-root) I can perform these tasks.
Comment 1 James Mason 2006-11-24 18:58:41 UTC
Created attachment 106896 [details]
Error message when accessing disc
Comment 2 James Mason 2006-11-24 18:59:08 UTC
Created attachment 106897 [details]
Kmix configuration window
Comment 3 James Mason 2006-11-24 18:59:33 UTC
Created attachment 106898 [details]
Error message when starting Amarok
Comment 4 Ludwig Nussel 2006-11-27 08:33:02 UTC
please run the following two commands and attach the output:
/sbin/resmgr sessions
id

please also attach /var/log/messages if it contains any resmgr or pam related error messages
Comment 5 Ludwig Nussel 2006-11-27 09:12:43 UTC
found the problem. it's a quoting problem in resmgr.
Comment 6 James Mason 2006-11-28 18:32:31 UTC
/sbin/resmgr sessions
status code 200
server message follows:
no sessions

id
uid=10000(YAMATOENGINES\jammason) gid=10000(YAMATOENGINES\domain users) groups=10000(YAMATOENGINES\domain users),10001(YAMATOENGINES\hrprograms-editors),10002(YAMATOENGINES\vacation-suspensioncreators),10003(YAMATOENGINES\catalog-editors),10004(YAMATOENGINES\meetingnotes-attendees),10005(YAMATOENGINES\employeeaccess-dataentries),10006(YAMATOENGINES\workinstructions-trainers),10007(YAMATOENGINES\pistonprotrusion-editors),10008(YAMATOENGINES\ows_3373472680_admin),10009(YAMATOENGINES\workinstructions-editors),10010(YAMATOENGINES\catalog-exporters),10011(YAMATOENGINES\vacation-fmlacreators),10012(YAMATOENGINES\processchange-reviewers),10013(YAMATOENGINES\workinstructions-evaluators),10014(YAMATOENGINES\safety team),10015(YAMATOENGINES\mas200),10016(YAMATOENGINES\imglibraryedit),10017(YAMATOENGINES\bomchange-requesters),10018(YAMATOENGINES\notices-editors),10019(YAMATOENGINES\holidays-editors),10020(YAMATOENGINES\is),10021(YAMATOENGINES\tsc),10022(YAMATOENGINES\quality),10023(YAMATOENGINES\vpn access)
Comment 7 James Mason 2006-11-28 18:36:43 UTC
cat /var/log/messages|grep resmgr
Nov 24 13:36:14 dexter-l resmgr[2562]: rejected connection from uid 0/gid 10000: group doesn't exist
Nov 24 13:36:14 dexter-l kdm: :0[3361]: resmgr: communication failure: Connection reset by peer
Nov 24 13:36:14 dexter-l kdm: :0[3361]: pam_resmgr: resmgr logout failed

cat /var/log/messages|grep pam
Nov 24 09:47:52 dexter-l kdm: :0[9865]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 09:47:52 dexter-l kdm: :0[9865]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 09:47:52 dexter-l kdm: :0[9865]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 09:52:41 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/3 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 10:14:38 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/3 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 10:41:30 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/1 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 10:55:42 dexter-l kcheckpass: pam_winbind(kcheckpass:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 11:03:44 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/4 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 11:42:39 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/1 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 11:43:00 dexter-l kdm: :0[9865]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 11:43:27 dexter-l kdm: :0[29448]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 11:43:27 dexter-l kdm: :0[29448]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 11:43:27 dexter-l kdm: :0[29448]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 11:48:23 dexter-l kdm: :0[29448]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 11:48:44 dexter-l kdm: :0[31169]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 11:48:44 dexter-l kdm: :0[31169]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 11:48:44 dexter-l kdm: :0[31169]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 11:49:08 dexter-l kdm: :0[31169]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 11:49:19 dexter-l kdm: :0[31536]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 11:49:19 dexter-l kdm: :0[31536]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 11:49:19 dexter-l kdm: :0[31536]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 11:54:18 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/1 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 11:57:06 dexter-l kdm: :0[31536]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 11:58:54 dexter-l kdm: :0[3361]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 11:58:54 dexter-l kdm: :0[3361]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 11:58:54 dexter-l kdm: :0[3361]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 12:03:49 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/1 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 12:04:28 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/1 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 12:24:14 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/1 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 13:32:16 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/2 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 13:36:13 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: Error in service module ; TTY=pts/4 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 13:36:14 dexter-l kdm: :0[3361]: pam_resmgr: resmgr logout failed
Nov 24 13:36:14 dexter-l kdm: :0[3361]: pam_setcred(DELETE_CRED) failed: User not known to the underlying authentication module
Nov 24 13:39:33 dexter-l kdm: :0[3388]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 13:39:33 dexter-l kdm: :0[3388]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 13:39:33 dexter-l kdm: :0[3388]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 13:42:16 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/4 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 13:56:53 dexter-l kcheckpass: pam_winbind(kcheckpass:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 14:32:01 dexter-l kcheckpass: pam_winbind(kcheckpass:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 14:44:06 dexter-l su: pam_winbind(su:auth): request failed: No such user, PAM error was User not known to the underlying authentication module (10), NT error was NT_STATUS_NO_SUCH_USER
Nov 24 15:14:06 dexter-l su: pam_winbind(su:auth): request failed: No such user, PAM error was User not known to the underlying authentication module (10), NT error was NT_STATUS_NO_SUCH_USER
Nov 24 15:41:12 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/1 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 15:41:48 dexter-l kdm: :0[3388]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 15:42:09 dexter-l kdm: :0[31430]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 15:42:09 dexter-l kdm: :0[31430]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 15:42:09 dexter-l kdm: :0[31430]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 15:44:19 dexter-l kdm: :0[31430]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 15:44:29 dexter-l kdm: :0[32282]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 15:44:29 dexter-l kdm: :0[32282]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 15:44:29 dexter-l kdm: :0[32282]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 15:45:54 dexter-l kdm: :0[32282]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 15:46:04 dexter-l kdm: :0[539]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 15:46:04 dexter-l kdm: :0[539]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 15:46:04 dexter-l kdm: :0[539]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 15:55:54 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/1 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 16:05:15 dexter-l kdm: :0[539]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 16:05:36 dexter-l login[1984]: pam_winbind(login:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 16:05:36 dexter-l login[1984]: pam_winbind(login:account): user 'YAMATOENGINES\jammason' OK
Nov 24 16:05:36 dexter-l login[1984]: pam_winbind(login:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 16:06:14 dexter-l kdm: :0[5202]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 16:06:14 dexter-l kdm: :0[5202]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 16:06:14 dexter-l kdm: :0[5202]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 16:19:18 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/2 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 16:19:51 dexter-l kdm: :0[5202]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 16:20:02 dexter-l kdm: :0[8549]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 16:20:02 dexter-l kdm: :0[8549]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 16:20:02 dexter-l kdm: :0[8549]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 16:31:34 dexter-l sudo: YAMATOENGINES\jammason : pam_authenticate: User not known to the underlying authentication module ; TTY=pts/2 ; PWD=/home/YAMATOENGINES/jammason ; USER=root ; COMMAND=/opt/kde3/bin/kdesu_stub -
Nov 24 16:33:20 dexter-l kdm: :0[8549]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 24 16:33:31 dexter-l kdm: :0[11672]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 24 16:33:31 dexter-l kdm: :0[11672]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 24 16:33:31 dexter-l kdm: :0[11672]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 24 16:35:22 dexter-l kdm: :0[11672]: pam_winbind(xdm:setcred): user 'YAMATOENGINES\jammason' OK
Nov 28 08:30:03 dexter-l kdm: :0[3370]: pam_winbind(xdm:auth): user 'YAMATOENGINES\jammason' granted access
Nov 28 08:30:03 dexter-l kdm: :0[3370]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' OK
Nov 28 08:30:03 dexter-l kdm: :0[3370]: pam_winbind(xdm:account): user 'YAMATOENGINES\jammason' granted access
Nov 28 08:45:39 dexter-l kcheckpass: pam_winbind(kcheckpass:auth): user 'YAMATOENGINES\jammason' granted access
Nov 28 09:06:40 dexter-l kcheckpass: pam_winbind(kcheckpass:auth): user 'YAMATOENGINES\jammason' granted access
Comment 8 Ludwig Nussel 2006-11-29 14:15:35 UTC
Fixed. resmgr and hal-resmgr packages for testing are available from
http://www.suse.de/~lnussel/resmgr

aj: ok for 10.2 maintenance update?
Comment 9 Andreas Jaeger 2006-11-29 14:50:48 UTC
OK.
Comment 10 James Mason 2006-11-29 20:37:11 UTC
I installed the 2 rpms, and ran SuSEconfig, but I'm still experiencing the problem.  Is these something else I need to do?

/sbin/resmgr sessions
status code 200
server message follows:
no sessions

cat /var/log/messages|grep resmgr
Nov 29 11:46:07 dexter-l resmgr[2593]: rejected connection from uid 0/gid 10000: group doesn't exist
Nov 29 11:46:07 dexter-l kdm: :0[3353]: resmgr: communication failure: Connection reset by peer
Nov 29 11:46:07 dexter-l kdm: :0[3353]: pam_resmgr: resmgr logout failed

Comment 11 James Mason 2006-11-29 21:35:41 UTC
resmgr sessions
:0 YAMATOENGINESjammason

I notice that the "resmgr sessions" output does not have the '\' between domain
and username.  If I log in at a bash prompt, I have to use the form
'DOMAIN\username'.
Comment 12 Ludwig Nussel 2006-11-30 12:20:45 UTC
indeed there still was bug in the pam module, sorry for the inconvenience. Try again with resmgr-1.1.0_SVNr123-9.1.i586.rpm (just copied there, might take a moment to sync)
Comment 13 James Mason 2006-11-30 18:49:44 UTC
Perfect!

resmgr sessions
:0 YAMATOENGINES\jammason

id
uid=10000(YAMATOENGINES\jammason) ...

Thanks!
Comment 14 Anja Stock 2006-12-12 09:59:42 UTC
released