Project

General

Profile

Bug #2965

Samba SWAT fails PAM authentication due to missing symbol

Added by Siegfried Leonard over 8 years ago. Updated over 7 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
OS/Net (Kernel and Userland)
Target version:
-
Start date:
2012-07-05
Due date:
% Done:

100%

Estimated time:
Difficulty:
Medium
Tags:
needs-triage

Description

After installing samba and enabling its service and swat, I tried to go to http://localhost:901 and login as root. I noticed this in /var/samba/log/log.swat:

[2012/07/04 18:35:29.130860, 0] auth/pampass.c:577()
smb_pam_account: PAM: User root is NOT permitted to access system at this time
[2012/07/04 18:35:29.131133, 0] auth/pampass.c:829()
smb_pam_passcheck: PAM: smb_pam_account failed - Rejecting User root !

Looking at the system log, I also noticed this:

Jul 4 18:15:07 Serve swat2770: [ID 825731 auth.error] dlsym failed pam_sm_authenticate: error ld.so.1: swat: fatal: nspr_use_zone_allocator: can't find symbol
Jul 4 18:15:21 Serve mDNSResponder: [ID 702911 daemon.error] ERROR: getOptRdata - unknown opt 4
Jul 4 18:15:32 Serve swat2775: [ID 825731 auth.error] dlsym failed pam_sm_acct_mgmt: error ld.so.1: swat: fatal: nspr_use_zone_allocator: can't find symbol
Jul 4 18:15:32 Serve swat2775: [ID 264585 auth.error] load_modules[0:/etc/pam.conf]: pam_sm_acct_mgmt() missing

And I am unable to login with root, it gives me 401. The problem is reproducible every time. I hope the above is enough detail, if you need any more info, let me know.

#1

Updated by Jon Tibble over 8 years ago

  • Status changed from New to Feedback

I think that is correct behaviour as root is a role not a user and I can log in with a normal user account fine and see the same as you do in swat.log for root.

I also don't seem to get any of those auth errors. Could you provide information about the version you're running please.

cat /etc/release
uname -a
pkg list | grep incorporation

#2

Updated by Siegfried Leonard over 8 years ago

cat /etc/release
uname -a
pkg list | grep incorporation

Here you go. I can login with a normal user account fine also, but not root, which is the account necessary to make any changes in swat, otherwise swat is kind of useless...

$ cat /etc/release
OpenIndiana Development oi_151.1.5 X86 (powered by illumos)
Copyright 2011 Oracle and/or its affiliates. All rights reserved.
Use is subject to license terms.
Assembled 26 June 2012

$ uname -a
SunOS Serve 5.11 oi_151a5 i86pc i386 i86pc Solaris

$ pkg list | grep incorporation
consolidation/SunVTS/SunVTS-incorporation 0.5.11-0.151.1.5 i--
consolidation/X/X-incorporation 0.5.11-0.151.1.5 i--
consolidation/admin/admin-incorporation 0.5.11-0.151.1.5 i--
consolidation/cacao/cacao-incorporation 0.5.11-0.151.1.5 i--
consolidation/cde/cde-incorporation 0.5.11-0.151.1.5 i--
consolidation/cns/cns-incorporation 0.5.11-0.151.1.5 i--
consolidation/dbtg/dbtg-incorporation 0.5.11-0.151.1.5 i--
consolidation/gfx/gfx-incorporation 0.5.11-0.151.1.5 i--
consolidation/gnome/gnome-incorporation 0.5.11-0.151.1.5 i--
consolidation/gnome_l10n/gnome_l10n-incorporation 0.5.11-0.151.1.5 i--
consolidation/hcts/hcts-incorporation 0.5.11-0.151.1.5 i--
consolidation/install/install-incorporation 0.5.11-0.151.1.5 i--
consolidation/ips/ips-incorporation 0.5.11-0.151.1.5 i--
consolidation/jdmk/jdmk-incorporation 0.5.11-0.151.1.5 i--
consolidation/l10n/l10n-incorporation 0.5.11-0.151.1.5 i--
consolidation/man/man-incorporation 0.5.11-0.151.1.5 i--
consolidation/nspg/nspg-incorporation 0.5.11-0.151.1.5 i--
consolidation/nvidia/nvidia-incorporation 0.5.11-0.151.1.5 i--
consolidation/osnet/osnet-incorporation 0.5.11-0.151.1.5 i--
consolidation/sfw/sfw-incorporation 0.5.11-0.151.1.5 i--
consolidation/sic_team/sic_team-incorporation 0.5.11-0.151.1.5 i--
consolidation/solaris_re/solaris_re-incorporation 0.5.11-0.151.1.5 i--
consolidation/sunpro/sunpro-incorporation 0.5.11-0.151.1.5 i--
consolidation/ub_javavm/ub_javavm-incorporation 0.5.11-0.151.1.5 i--
consolidation/vpanels/vpanels-incorporation 0.5.11-0.151.1.5 i--
consolidation/xvm/xvm-incorporation 0.5.11-0.151.1.5 i--

#3

Updated by Ken Mays about 8 years ago

  • Assignee set to Adam ┼átevko
#4

Updated by Ken Mays over 7 years ago

  • Status changed from Feedback to Closed
  • Assignee changed from Adam ┼átevko to OI Userland
  • % Done changed from 0 to 100

inet setup(SUNWcs):
swat stream tcp nowait.400 root /usr/sbin/swat swat

use browser for root login for SWAT

Tested as resolved in ,5.11-0.151.1.8:20130721T124357Z.

Also available in: Atom PDF