[Techtalk] ldap/cyrus

Maria McKinley maria at shadlen.org
Sun Sep 23 09:10:16 UTC 2007


Maria McKinley wrote:
> On 9/23/07, Maria McKinley <maria at shadlen.org> wrote:
>> Hello all,
>>
>> I just switched to a new ldap server, and have managed to get quite a
>> bit working with the new ldap server, but can't get mail login
>> working. Unfortunately, this means I can't read the mailing list, so
>> please send replies to my gmail account: monstermama at gmail.com. I
>> have other things on the mail server working with ldap, so it isn't
>> the connection to the ldap server. I think I have properly updated the
>> certificates (certainly the ldap ones are working). The log says it is
>> a problem with pam:
>>
>> Sep 23 01:13:37 ella saslauthd[22677]: (pam_unix) authentication
>> failure; logname= uid=0 euid=0 tty= ruser= rhost=  user=maria
>> Sep 23 01:13:37 ella saslauthd[22677]: do_auth         : auth failure:
>> [user=maria] [service=imap] [realm=] [mech=pam] [reason=PAM acct
>> error]
>>
>> Sep 23 01:13:37 ella cyrus/imapd[22905]: badlogin: [128.208.108.78]
>> plaintext maria SASL(-13): authentication failure: checkpass failed
>> Sep 23 01:14:35 ella cyrus/master[22783]: process 22948 exited, status 0
>>
>> I've made sure all these configs: libnss-ldap.ldap, pam_ldap.conf have
>> the correct ip.
>>
>> Any ideas what else to check?
>>
>> thanks,
>> maria
>>
> 
> A little too quick to say it was solved. I think it may have been a
> weirdness of being behind the firewall, but not sure. Pretty strange.
> I am able to use the smtp server (which also checks ldap), and it was
> after using smtp that I was able to see my email messages, although it
> still told me login failed.
> 
> from a very confused,
> maria
> 

Sometimes I think it is the act of spamming techtalk that sparks 
solutions. I spin my wheels and get nowhere, but sometimes as soon as I 
start sending out a few help requests, things seem to fall into place 
(but not if I just compose the emails and don't send them, of 
course...). I restarted saslauthd and that did the trick. :-)

~m


More information about the Techtalk mailing list