Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-2696: PAM authentication fails on Solaris 11.1

Centrify DirectControl ,  

12 April,16 at 11:46 AM

Applies to: Centrify DirectControl 5.0.x on Oracle Solaris 11.1 only

Problem:
After Centrify is joined and a user is added to the Zone, an attempt to login results in the following PAM authentication failure:


sshd[6986]: [ID 800047 auth.error] error: PAM: Authentication failed for oracle from host1.domain.com

Cause:
In Oracle Solaris 11.1, the PAM configuration completely changed when compared to the previous release Solaris 11, the changes caused the PAM authentication to fail.

Workaround:
Modify /etc/pam.d/login and add the following 2 lines at the top:

auth sufficient         pam_centrifydc.so unix_cred
auth requisite          pam_centrifydc.so deny

Modify /etc/pam.d/other and add the following 7 lines at the top:

auth sufficient pam_centrifydc.so unix_cred
auth requisite pam_centrifydc.so deny
account sufficient pam_centrifydc.so
account requisite pam_centrifydc.so deny
session required pam_centrifydc.so
password sufficient pam_centrifydc.so try_first_pass
password requisite pam_centrifydc.so deny

Also, modify /etc/pam.d/passwd and add the following 4 lines at the top:

auth sufficient pam_centrifydc.so try_first_pass
auth requisite pam_centrifydc.so deny
account sufficient pam_centrifydc.so unix_cred
account requisite pam_centrifydc.so deny

Then test again.

Resolution:
This is fixed in Centrify DirectControl 5.1.1

Additional reading on how PAM works in Solaris 11.1 (the below link was provided as a courtesy):
http://docs.oracle.com/cd/E26502_01/html/E29015/pam-32.html#scrolltoc

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.