# vsftp - local user auth

**URL:** <https://forums.suse.com/t/vsftp-local-user-auth/29904>\
**Category:** SLES Configure-Administer\
**Created:** [June 12, 2017, 2:53pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904 "2017-06-12T14:53:39Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![christianmolecki](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@christianmolecki](https://forums.suse.com/u/christianmolecki)\
**Post date:** [June 12, 2017, 2:53pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/1 "2017-06-12T14:53:39Z")

</div>

Hello everyone,

we have some SLES12 SP2 servers, which are integratet in AD domain.  
For about two weeks its no possible to login with a local user by a ftp client.

```auto
vsftpd[13188]: pam_winbind(vsftpd:auth): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_USER_UNKNOWN (10), NTSTATUS: NT_STATUS_NO_SUCH_USER, Error message was: No such user
```

The user exists and the passwort ist correct (really).  
I’m able to login with the user by a ssh shell.

In my opinion the ftp server tries to authenticate the local user against the active directory.  
But thats no correct and won’t work.

BR  
Christian

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [June 12, 2017, 3:29pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/2 "2017-06-12T15:29:33Z")

</div>

Hi Christian,

> For about two weeks its no possible to login with a local user by a ftp client.  
> the ftp server tries to authenticate the local user against the active directory.

have a look at the configuration files in /etc/pam.d, especially /etc/pam.d/vsftpd and /etc/pam.d/common-auth. Were these files recently changed, which might explain the change in behavior?

(it is possible to change the PAM service name in /etc/vsftpd.conf, see pam\_service\_name option there.)

By changing /etc/pam.d/vsftpd, you may configure to use a different authentication path for vsftpd than the general default. Or was the server configured the other way around, using local auth as a default and having a differing config for sshd? Anyhow, that’s where you can change to match your requirements…

Regards,  
J

---

<div class="post-metadata">

**Author:** ![christianmolecki](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@christianmolecki](https://forums.suse.com/u/christianmolecki)\
**Post date:** [June 12, 2017, 3:57pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/3 "2017-06-12T15:57:31Z")

</div>

Hi J,

the date of last change is 7th April (vsftp) and 15th Mai (common-auth-pc).  
The pam\_service\_name is vsftp.

I didn’t change something in /etc/pam.d/vsftp or /etc/vsftp.conf.  
In /etc/security/pam\_winbind I configured the require\_membership\_of to limit access to the server.

Regards,  
Christian

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [June 12, 2017, 4:21pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/4 "2017-06-12T16:21:44Z")

</div>

Hi Christian,

does the current PAM configuration suggest that vsftpd should use locla users, while sshd should verify the credentials against the domain? Because the log message from you initial post clearly shows that PAM is validating the vsftp login against the domain, which I understood is not what you intended.

Regards,  
J

---

<div class="post-metadata">

**Author:** ![christianmolecki](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@christianmolecki](https://forums.suse.com/u/christianmolecki)\
**Post date:** [June 12, 2017, 4:25pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/5 "2017-06-12T16:25:10Z")

</div>

How/Where can I check this?

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [June 12, 2017, 4:46pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/6 "2017-06-12T16:46:50Z")

</div>

> [@christianmolecki;38236](#):
>
> How/Where can I check this?

Start with /etc/pam.d/vsftpd and follow the chain of “auth” entries. One of the modules will be “pam\_winbind” (as per your initial message) to authenticate against your AD domain, while checks against the local users in /etc/passwd is done via pam\_unix. See “man pam\_unix” and “man pam\_winbind” for details on these modules, and “man 8 pam” and the various sources on the net for a general description of PAM.

Regards,  
J

---

<div class="post-metadata">

**Author:** ![christianmolecki](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@christianmolecki](https://forums.suse.com/u/christianmolecki)\
**Post date:** [June 12, 2017, 4:51pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/7 "2017-06-12T16:51:40Z")

</div>

In /etc/pam.d/vsftp is no pam\_winbind. 😕

[CODE]#%PAM-1.0

# Uncomment this to achieve what used to be ftpd -A.

# auth required pam\_listfile.so item=user sense=allow file=/etc/ftpchroot onerr=fail

auth required pam\_listfile.so item=user sense=deny file=/etc/ftpusers onerr=succeed

# Uncomment the following line for anonymous ftp.

#auth sufficient pam\_ftp.so  
auth required pam\_shells.so  
auth include common-auth  
account include common-account  
password include common-password  
session required pam\_loginuid.so  
session include common-session[/CODE]

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [June 12, 2017, 5:14pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/8 "2017-06-12T17:14:47Z")

</div>

Hi Christian,  
[QUOTE=christianmolecki;38238]In /etc/pam.d/vsftp is no pam\_winbind. 😕[/QUOTE]  
this is expected - follow the include chain (“auth include common-auth”) and you should see that module referenced.

[QUOTE=christianmolecki;38238][CODE]#%PAM-1.0

# Uncomment this to achieve what used to be ftpd -A.

# auth required pam\_listfile.so item=user sense=allow file=/etc/ftpchroot onerr=fail

auth required pam\_listfile.so item=user sense=deny file=/etc/ftpusers onerr=succeed

# Uncomment the following line for anonymous ftp.

#auth sufficient pam\_ftp.so  
auth required pam\_shells.so  
auth include common-auth  
account include common-account  
password include common-password  
session required pam\_loginuid.so  
session include common-session[/CODE][/QUOTE]

Since you wrote that common-auth was last modified many weeks ago and the problem surfaced only recently, I’m rather curious how this did work at all. Maybe it wasn’t local users that were checked, but some AD account nevertheless? Introducing the group filter may then have broken that path to these accounts?

Regards,  
J

---

<div class="post-metadata">

**Author:** ![christianmolecki](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@christianmolecki](https://forums.suse.com/u/christianmolecki)\
**Post date:** [June 14, 2017, 12:24pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/9 "2017-06-14T12:24:13Z")

</div>

So I compared the content of the files of /etc/pam.d/ between a SLES12 SP2 plain installation with a SLES12 SP2 current updates installation.

There are differences in common-account-pc, common-auth-pc, common-password-pc and common-session-pc.

If I replace the common-account-pc or the common-session-pc with the file from the plain installation, the login with local users works!

Differences common-account-pc

[CODE]  
plain:  
account required pam\_unix.so try\_first\_pass

current updates:  
account requisite pam\_unix.so try\_first\_pass  
account sufficient pam\_localuser.so  
account required pam\_winbind.so use\_first\_pass [/CODE]

common-session-pc

[CODE]  
plain:  
session required pam\_limits.so   
session required pam\_unix.so try\_first\_pass  
session optional pam\_umask.so   
session optional pam\_systemd.so  
session optional pam\_gnome\_keyring.so auto\_start only\_if=gdm,gdm-password,lxdm,lightdm  
session optional pam\_env.so

current updates:  
session optional pam\_mkhomedir.so   
session required pam\_limits.so   
session required pam\_unix.so try\_first\_pass  
session required pam\_winbind.so   
session optional pam\_umask.so   
session optional pam\_systemd.so  
session optional pam\_gnome\_keyring.so auto\_start only\_if=gdm,gdm-password,lxdm,lightdm  
session optional pam\_env.so [/CODE]

BR  
Christian

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [June 14, 2017, 2:31pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/10 "2017-06-14T14:31:15Z")

</div>

Hi Christian,

> between a SLES12 SP2 plain installation with a SLES12 SP2 current updates installation

are both servers “AD-enabled”? Because the differences you show look like the result of activating AD integration (pam\_winbind) and allowing creation of home dir on login (pam\_mkhomedir).

pam\_localuser, OTOH, looks like a manual addition. It will only check for the _presence_ of a user in /etc/passwd and not by itself allow local users to log in.

How’s the actual authentication set up? Do you see pam\_unix as a sufficient module in there, before winbind is invoked?

Regards,  
J

---

<div class="post-metadata">

**Author:** ![christianmolecki](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@christianmolecki](https://forums.suse.com/u/christianmolecki)\
**Post date:** [August 10, 2017, 3:24pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/11 "2017-08-10T15:24:39Z")

</div>

[QUOTE=jmozdzen;38281]Hi Christian,

> between a SLES12 SP2 plain installation with a SLES12 SP2 current updates installation

are both servers “AD-enabled”? Because the differences you show look like the result of activating AD integration (pam\_winbind) and allowing creation of home dir on login (pam\_mkhomedir).

pam\_localuser, OTOH, looks like a manual addition. It will only check for the _presence_ of a user in /etc/passwd and not by itself allow local users to log in.

How’s the actual authentication set up? Do you see pam\_unix as a sufficient module in there, before winbind is invoked?

Regards,  
J[/QUOTE]

The reason why local users can’t login, is the “require\_membership\_of” setting in /etc/security/pam\_winbind.conf  
Only these users/groups can login via ftp.

Is it possible to add a local user to this setting?

Christian

---

<div class="post-metadata">

**Author:** ![christianmolecki](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@christianmolecki](https://forums.suse.com/u/christianmolecki)\
**Post date:** [August 10, 2017, 4:00pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/12 "2017-08-10T16:00:16Z")

</div>

Or can I disable the check agains pam\_winbind for ftp

---

<div class="post-metadata">

**Author:** ![ntami](https://avatars.discourse-cdn.com/v4/letter/n/f08c70/32.png) [@ntami](https://forums.suse.com/u/ntami)\
**Post date:** [March 8, 2018, 5:08pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/13 "2018-03-08T17:08:59Z")

</div>

Just found this post, as i am on the way to track down the same issue.  
I do not have a fix for now, but a workaround.

Looks like vsftpd has some issues with pam\_systemd.

As a workaround you can to disable pam\_systemd.so for vsftpd

like …

`grep ^[^#] /etc/pam.d/common-session >> /etc/pam.d/vsftpd
sed -i -e 's/\\(.*pam_systemd.so.*\\)/#\\1/' -e 's/\\(.*common-session.*\\)/#\\1/' /etc/pam.d/vsftpd`

---

<div class="post-metadata">

**Author:** ![christianmolecki](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@christianmolecki](https://forums.suse.com/u/christianmolecki)\
**Post date:** [March 8, 2018, 5:17pm UTC](https://forums.suse.com/t/vsftp-local-user-auth/29904/14 "2018-03-08T17:17:20Z")

</div>

In the meantime, we replaced ftp by more secure technologies.  
So I can’t evaluate your workaround.

Thank you for updating this with your suggestion.
