Re: pam authentication for postgres - Mailing list pgsql-general

From Jason Tesser
Subject Re: pam authentication for postgres
Date
Msg-id 04875CB4331F0240A0AD66F970978651160A2D@paul
Whole thread Raw
In response to pam authentication for postgres  ("Jason Tesser" <JTesser@nbbc.edu>)
Responses Re: pam authentication for postgres  (Jan Wieck <JanWieck@Yahoo.com>)
List pgsql-general
> Please post a comprehensive description of what you're trying to do
> together with the configuration files you use.

I thought I did that sorry.  I am trying to get Postgres to authenticate through Pam so I can authenticate to Active
Directory on our network.  All the steps I took are posted below.  If you notice the messages I pasted from my logs
you will see that winbind is authenticating ok but for some reason Postgres still denies access.  

<snip>
>
> here is the messages I have is the log from trying to log in
>
> Nov 26 08:55:16 localhost postgresql(pam_unix)[22693]: authentication failure; logname= uid=26 euid=26 tty= ruser=
rhost= user=cherring
 
> Nov 26 08:55:16 localhost pam_winbind[22693]: user 'cherring' granted acces
>
> as you can see winbind is actually granting access but fro some reason poasgres still denies it.
> weird.  any ideas. 
>
<snip> postgresql/linux/pam setup.
>>
>> 0) configure postgresql for pam, for example
>>
>>       [root ( at ) omega tmp]# grep pam /usr/local/pgsql/data/pg_hba.conf
>>       host    all         all          137.75.0.0        255.255.0.0       pam
>>
>> 1) create a /etc/pam.d/postgresql entry, here's how i did mine
>>
>>       [root ( at ) omega tmp]# cp /etc/pam.d/passwd /etc/pam.d/postgresql
>>
>>   i don't know if it's the best setup, but it works!  mine looks like this
>>
>>       [root ( at ) omega tmp]# cat /etc/pam.d/postgresql
>>       #%PAM-1.0
>>       auth       required     /lib/security/pam_stack.so service=system-auth
>>       account    required     /lib/security/pam_stack.so service=system-auth
>>       password   required     /lib/security/pam_stack.so service=system-auth
>




pgsql-general by date:

Previous
From: Alex Satrapa
Date:
Subject: Re: disaster recovery
Next
From: Doug McNaught
Date:
Subject: Re: disaster recovery