Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Other Versions > EOL (End Of Life) Versions
FedoraForum Search

Forgot Password? Join Us!

EOL (End Of Life) Versions This is a Forum to discuss problems and workarounds for versions of Fedora that have passed End of Life.

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 10th May 2006, 02:45 AM
spence Offline
Registered User
 
Join Date: Sep 2005
Posts: 20
FC5 - pam_succeed_if.so uid >= 500 quiet --> Why??

I am currently using LDAP for authentication and have found that I am unable to login to Gnome Desktop or switch user to certain system administrator accounts.
e.g.
su - sysxxx
Password: <enter correct password>
su: incorrect password

After a lot of investiagion I discovered that the problem is the accounts had a UID in the range of 200 to 220. These logins are also used on Solaris and are outside the Solaris reserved UID range. They work fine on Solaris and on Fedora Core 4 - just no good on Fedora Core 5.

I eventually tracked it down to the default settings of Fedora Core 5.

A new install of Fedora Core 4 does not let users with a UID of less than 100 login.
A new install of Fedora Core 5 does not let users with a UID of less than 500 login.

This is set in the files:
/etc/pam.d/system-auth
/etc/pam.d/system-auth-ac

e.g. from system-auth:
auth required pam_env.so
auth sufficient pam_unix.so nullok try_first_pass
auth requisite pam_succeed_if.so uid >= 500 quiet
auth sufficient pam_ldap.so use_first_pass
auth required pam_deny.so



I was just wondering what the motivation was for increasing the allowed UID range to above 500?
I don't see any issues changing it back to 100... in fact an upgrade insall from FC4 to FC5 preserves the 100 value.
  #2  
Old 11th May 2006, 05:34 AM
Jman Offline
Registered User
 
Join Date: Mar 2004
Location: Minnesota, USA
Age: 27
Posts: 7,909
Regular Fedora users' ids start at 500, I presume the pam policy is so that system accounts are denied login.
  #3  
Old 11th May 2006, 05:51 AM
spence Offline
Registered User
 
Join Date: Sep 2005
Posts: 20
Quote:
Originally Posted by Jman
Regular Fedora users' ids start at 500, I presume the pam policy is so that system accounts are denied login.
Hmm well not a very good policy if you are using the same LDAP login across multiple systems. Traditionally <100 has been considered reserved on unix systems like Solaris.

In a mixed environemnt its most annoying to suddenly switch your behaviour.
  #4  
Old 1st April 2011, 01:32 AM
ghostofmorgan Offline
Registered User
 
Join Date: Mar 2011
Posts: 1
linuxfedorafirefox
Re: FC5 - pam_succeed_if.so uid >= 500 quiet --> Why??

I m not to efficient with Fedora yet , but I m trying to update clamav and I keep
getting a message that says "I need a writeable UID 500 to get this update . Where do I get this
UID 500 so I can update clamscan ? Aloha
  #5  
Old 1st April 2011, 01:49 AM
bob's Avatar
bob Online
Administrator (yeah, back again)
 
Join Date: Jul 2004
Location: Colton, NY; Junction of Heaven & Earth (also Routes 56 & 68).
Age: 67
Posts: 21,330
linuxfirefox
Re: FC5 - pam_succeed_if.so uid >= 500 quiet --> Why??

Ghost, you've tagged a 6-yr. old thread. I'm going to close this one. Why not start your own? As info, you're under the sub-Forum for "End Of Life" versions. If you're running a F13 or F14, you should be posting in another sub-forum.

Just select the right one, then look for the "new topic" button on the top left and start a fresh post!
__________________
Linux & Beer - That TOTALLY Computes!
Registered Linux User #362651


Don't use any of my solutions on working computers or near small children.
Closed Thread

Tags
>, 500, fc5, pamsucceedifso, quiet, uid

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sound too quiet DanMachado Using Fedora 6 31st August 2009 08:41 PM
Very quiet sound in F10. ESC201 Using Fedora 3 1st July 2009 12:51 AM
pam_succeed_if uid <100 macadam Using Fedora 0 13th June 2005 10:49 AM


Current GMT-time: 21:44 (Tuesday, 18-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat