# LDAP client configuration

**URL:** <https://forums.suse.com/t/ldap-client-configuration/25373>\
**Category:** SLES Configure-Administer\
**Created:** [April 11, 2014, 9:10pm UTC](https://forums.suse.com/t/ldap-client-configuration/25373 "2014-04-11T21:10:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![madhum210](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@madhum210](https://forums.suse.com/u/madhum210)\
**Post date:** [April 11, 2014, 9:10pm UTC](https://forums.suse.com/t/ldap-client-configuration/25373/1 "2014-04-11T21:10:49Z")

</div>

I am trying to configure Active Directory authentication to SUSE Linux Enterprise Server 11 (x86\_64) sever, but somehow we are not able to succeed. in warn file logs are showing error message “nss\_ldap: could not search LDAP server - Server is unavailable”… and I am able to do the ldapsearch from SUSE server with same user.

I used yast to configure LDAP client… does anyone has any idea why we getting this?

below lines are from messages file…

suselx01 sshd[13631]: Invalid user from 14.x.x.x  
suselx01 sshd[13633]: pam\_ldap: ldap\_search\_s Operations error  
suselx01 sshd[13631]: error: PAM: User not known to the underlying authentication module for illegal user from 14.x.x.x  
suselx01 sshd[13631]: Failed keyboard-interactive/pam for invalid user from 14.x.x.x port 61072 ssh2  
suselx01 sshd[13637]: Accepted keyboard-interactive/pam for root from 14.x.x.x port 61073 ssh2  
suselx01 sshd[13635]: pam\_unix2(sshd:auth): conversation failed  
suselx01 sshd[13635]: pam\_ldap: ldap\_search\_s Operations error  
suselx01 sshd[13635]: error: ssh\_msg\_send: write

---

<div class="post-metadata">

**Author:** ![madhum210](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@madhum210](https://forums.suse.com/u/madhum210)\
**Post date:** [April 14, 2014, 8:46pm UTC](https://forums.suse.com/t/ldap-client-configuration/25373/2 "2014-04-14T20:46:17Z")

</div>

Does anyone has experience or achieved in configured SUSE as AD client for authentication?

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [April 14, 2014, 9:09pm UTC](https://forums.suse.com/t/ldap-client-configuration/25373/3 "2014-04-14T21:09:40Z")

</div>

There have been threads in the past covering this. Did you find those?  
Here’s one:

[https://forums.suse.com/showthread.php?1260-control-access-from-active-directory](https://forums.suse.com/showthread.php?1260-control-access-from-active-directory)

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![madhum210](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@madhum210](https://forums.suse.com/u/madhum210)\
**Post date:** [April 14, 2014, 10:02pm UTC](https://forums.suse.com/t/ldap-client-configuration/25373/4 "2014-04-14T22:02:09Z")

</div>

Hi AB,

thanks for the reply…

I did lot of research on net to figure out why it is not working… I didn’t find any helpful data. I even opened case with IBM to see why it is not working … not much help from them as well.  
I am using nss\_ldap and pam\_ldap … and I just need to login to box using AD credentials… not sure where the issue is… it is simply throwing below error it doesn’t matter what changes I done on configuration.

Invalid user xxx\xxxxx  
error: PAM: User not known to the underlying authentication module for illegal user xxx/xxxx  
Failed keyboard-interactive/pam for invalid user xxx/xxx port 54163 ssh2

I think Linux is sending one format and AD is configured another format… like Linux is sending posixaccount and AD is looking UID…

any help…

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [April 22, 2014, 4:32pm UTC](https://forums.suse.com/t/ldap-client-configuration/25373/5 "2014-04-22T16:32:29Z")

</div>

Hi madhum210,

in your initial message you said that your ldapsearch worked fine using that same user - did you search for the user entry or did you specify the user DN as the bind DN?

While I have not had to bind against AD yet, if ldapsearch works, you can get nss\_dap working, too 🙂

Have you enabled the settings in /etc/ldap.conf’s “# RFC 2307 (AD) mappings” section?

Regards,  
Jens
