# Pam config using LDAP and local users problems

**URL:** <https://forums.suse.com/t/pam-config-using-ldap-and-local-users-problems/26003>\
**Category:** SLES Configure-Administer\
**Created:** [August 25, 2014, 6:11pm UTC](https://forums.suse.com/t/pam-config-using-ldap-and-local-users-problems/26003 "2014-08-25T18:11:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mlopezlaguna](https://avatars.discourse-cdn.com/v4/letter/m/97f17d/32.png) [@mlopezlaguna](https://forums.suse.com/u/mlopezlaguna)\
**Post date:** [August 25, 2014, 6:11pm UTC](https://forums.suse.com/t/pam-config-using-ldap-and-local-users-problems/26003/1 "2014-08-25T18:11:46Z")

</div>

Hi, we are using SLES11 as LDAP client and ITDS (IBM Tivoli Directory Server) as LDAP Server.

The problem we have with PAM is that upon connection pam\_tally increases by 1, always, just accesing the server, then if you use the wrong password it increases another one (1 per ssh connection + 1 per faulted password). When the password is ok the counter does not reset and we are not using the no\_reset parameter

Playing around with common-auth and the modulesLDAP users no longer have this problem (including pam\_succeed\_if.so since gid \> 100000 are the LDAP ones) but the local users keep getting locked as the count increases by 1 on every connection (except using public keys)

The common-auth file content:  
auth required pam\_env.so  
auth [success=1 default=ignore] pam\_succeed\_if.so gid ge 100000  
auth required pam\_tally.so deny=5 onerr=fail per\_user no\_lock\_time  
auth sufficient pam\_unix2.so  
auth required pam\_ldap.so use\_first\_pass

I’m not sure if pam\_ldap should go before pam\_succed\_if and how to prevent pam\_tally to increase the count with the connections

I’ve also check that vsftpd works fine reseting the pam\_tally after a good connection, pam.d/sshd and pam.d/vsftpd are similar configurations

SSH:  
auth requisite pam\_nologin.so  
auth include common-auth  
account include common-account  
password include common-password  
session required pam\_mkhomedir.so skel=/etc/skel/ umask=0077  
session required pam\_loginuid.so  
session include common-session

VSFTPD:  
auth required pam\_listfile.so item=user sense=deny file=/etc/ftpusers onerr=succeed  
auth required pam\_shells.so  
auth include common-auth  
account include common-account  
password include common-password  
session required pam\_loginuid.so  
session include common-session

If anyone has any insight it would be greatly appreciate. Thanks

---

<div class="post-metadata">

**Author:** ![mlopezlaguna](https://avatars.discourse-cdn.com/v4/letter/m/97f17d/32.png) [@mlopezlaguna](https://forums.suse.com/u/mlopezlaguna)\
**Post date:** [August 26, 2014, 5:36pm UTC](https://forums.suse.com/t/pam-config-using-ldap-and-local-users-problems/26003/2 "2014-08-26T17:36:23Z")

</div>

I’ve already found the solution! The problem was with the common-account modules order.

What i had:

account requisite pam\_unix2.so  
account sufficient pam\_localuser.so  
account required pam\_ldap.so use\_first\_pass  
account required pam\_tally.so

The problem was localiced on pam\_localuser.so, since i had sufficient it didn’t analize anything else so it didn’t go through pam\_tally. Also i’m not really using the localuser module so i took it off the config

The final config for common-account:

account sufficient pam\_ldap.so  
account required pam\_unix2.so use\_first\_pass  
account required pam\_tally.so

Now i have just one minor issue left, i do not understand why upon connection faillog increses by 1, it’s a minor isse but it means that each connection (whitout correct access that will reset the counter) increases the counter. I have deny=5 so

- Connection +1 (1)
  - Bad password +1 (2)
  - Bad Password + 1 (3)

- Ctr-C
- Connection +1 (4)
  - Bad password +1 (5)
  - Good Password + 1 (6) → already blocked even when i introduced a bad password just 3 times

Any ideas about why it has this beha

Thanks
