tacacs01 PAM-tacplus[9067]: auth failed: 2

824 views
Skip to first unread message

Juan Carlos León Centurión

unread,
Dec 31, 2013, 6:26:41 AM12/31/13
to event-driv...@googlegroups.com
Hello Folks,
 
   For some unknown reason, I'm not capable to integrate tacacs+ + AD
 
 
Testing against my own server, I get this error message. 
 
Dec 30 17:44:24 tacacs01 tac_plus[9064]: 127.0.0.1: pap login for 'myuser' from some_ip on ssh failed (no such user)
Dec 30 17:44:24 tacacs01 PAM-tacplus[9067]: auth failed: 2
 
Testing one of my switches :
 
Dec 30 18:14:34 tacacs01 tac_plus[9064]: 10.0.1.5: shell login for 'myuser' from some_ip on tty2 failed (no such user)
Dec 30 18:14:40 tacacs01 tac_plus[9064]: 10.0.1.5: shell login for 'myuser' from some_ip on tty2 failed (no such user)
 
Please take a look at my configuration and point me out the errors.
 
[root@tacacs01 ~]# cat /etc/pam.d/tacacs
auth    required   /usr/local/lib/security/pam_tacplus.so debug server=127.0.0.1 secret=secret
account sufficient /usr/local/lib/security/pam_tacplus.so debug server=127.0.0.1 secret=secret service=shell
session sufficient /usr/local/lib/security/pam_tacplus.so debug server=127.0.0.1 secret=secret service=shell
 
 
#!/usr/local/sbin/tac_plus
id = spawnd {
        listen = { port = 49 }
        spawn = {
                instances min = 1
                instances max = 10
        }
        background = yes
}
id = tac_plus {
         access log = /var/log/tac_plus/access/%Y%m%d.log
         accounting log = /var/log/tac_plus/acct/%Y%m%d.log
         coredump directory  = /var/log/tac_plus
        mavis module = external {
                setenv LDAP_SERVER_TYPE = "microsoft"
                setenv LDAP_HOSTS = "ad_server:389"
                setenv LDAP_BASE = "dc=mydomain,dc=com"
                setenv LDAP_FILTER = "(&(objectclass=Usuarios)(sAMAccountName=%s))"
                setenv LDAP_FILTER_CHPW = "(&(objectclass=user) (sAMAccountName=%s))"
                setenv LDAP_SCOPE = sub
                setenv LDAP_USER = "ada...@mydomain.com"
                setenv LDAP_PASSWD = "secretpass"
                setenv REQUIRE_TACACS_GROUP_PREFIX = 1
                exec = /usr/local/lib/mavis/mavis_tacplus_ldap.pl
        }
        login backend = mavis
        user backend = mavis
        pap backend = mavis
        host = world {
                address = ::/0
                prompt = "Welcome to AAA \n"
                enable 15 = clear secret
                key = "Secret"
              }
        group = admincisco {
                default service = permit
                service = shell {
                        default command = permit
                        default attribute = permit
                        set priv-lvl = 15
                }
        }
        group = admin {
                default service = permit
                service = shell {
                        default command = permit
                        default attribute = permit
                        set priv-lvl = 15
                }
        }
        group = guest {
                default service = permit
                enable = deny
                service = shell {
                        default command = permit
                        default attribute = permit
                        set priv-lvl = 1
                }
        }
        user = cisco {
                password = clear cisco
                member = admin
                service = shell {
                        default command = permit
                        default attribute = permit
                        set priv-lvl = 15
                }
        }
        user = readonly {
                password = clear readonly
                member = guest
        }
}

Juan Carlos León Centurión

unread,
Dec 31, 2013, 7:24:19 AM12/31/13
to event-driv...@googlegroups.com
More Details :
 
 
As you can see below, my user Works fine.
 
mavistest -d -1 /usr/local/etc/tac_plus.cfg tac_plus TACPLUS MyUser *****
11711: file=/usr/local/etc/tac_plus.cfg line=2 sym=[id] buf='id'
11711: file=/usr/local/etc/tac_plus.cfg line=2 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=2 sym=[<string>] buf='spawnd'
11711: file=/usr/local/etc/tac_plus.cfg line=2 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=3 sym=[listen] buf='listen'
11711: file=/usr/local/etc/tac_plus.cfg line=3 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=3 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=3 sym=[port] buf='port'
11711: file=/usr/local/etc/tac_plus.cfg line=3 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=3 sym=[<string>] buf='49'
11711: file=/usr/local/etc/tac_plus.cfg line=3 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=4 sym=[spawn] buf='spawn'
11711: file=/usr/local/etc/tac_plus.cfg line=4 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=4 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=5 sym=[instances] buf='instances'
11711: file=/usr/local/etc/tac_plus.cfg line=5 sym=[min] buf='min'
11711: file=/usr/local/etc/tac_plus.cfg line=5 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=5 sym=[<string>] buf='1'
11711: file=/usr/local/etc/tac_plus.cfg line=6 sym=[instances] buf='instances'
11711: file=/usr/local/etc/tac_plus.cfg line=6 sym=[max] buf='max'
11711: file=/usr/local/etc/tac_plus.cfg line=6 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=6 sym=[<string>] buf='10'
11711: file=/usr/local/etc/tac_plus.cfg line=7 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=8 sym=[background] buf='background'
11711: file=/usr/local/etc/tac_plus.cfg line=8 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=8 sym=[yes] buf='yes'
11711: file=/usr/local/etc/tac_plus.cfg line=9 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=11 sym=[id] buf='id'
11711: file=/usr/local/etc/tac_plus.cfg line=11 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=11 sym=[<string>] buf='tac_plus'
11711: file=/usr/local/etc/tac_plus.cfg line=11 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=12 sym=[access] buf='access'
11711: file=/usr/local/etc/tac_plus.cfg line=12 sym=[log] buf='log'
11711: file=/usr/local/etc/tac_plus.cfg line=12 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=12 sym=[<string>] buf='/var/log/tac_plus/access/%Y%m%d.log'
11711: file=/usr/local/etc/tac_plus.cfg line=13 sym=[accounting] buf='accounting'
11711: file=/usr/local/etc/tac_plus.cfg line=13 sym=[log] buf='log'
11711: file=/usr/local/etc/tac_plus.cfg line=13 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=13 sym=[<string>] buf='/var/log/tac_plus/acct/%Y%m%d.log'
11711: file=/usr/local/etc/tac_plus.cfg line=14 sym=[authorization] buf='authorization'
11711: file=/usr/local/etc/tac_plus.cfg line=14 sym=[log] buf='log'
11711: file=/usr/local/etc/tac_plus.cfg line=14 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=14 sym=[<string>] buf='/var/log/tac_plus/%Y%m%d.log'
11711: file=/usr/local/etc/tac_plus.cfg line=15 sym=[mavis] buf='mavis'
11711: file=/usr/local/etc/tac_plus.cfg line=15 sym=[module] buf='module'
11711: file=/usr/local/etc/tac_plus.cfg line=15 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=15 sym=[<string>] buf='external'
11711: file=/usr/local/etc/tac_plus.cfg line=15 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=16 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=16 sym=[<string>] buf='LDAP_SERVER_TYPE'
11711: file=/usr/local/etc/tac_plus.cfg line=16 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=16 sym=[<string>] buf='microsoft'
11711: file=/usr/local/etc/tac_plus.cfg line=18 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=18 sym=[<string>] buf='LDAP_HOSTS'
11711: file=/usr/local/etc/tac_plus.cfg line=18 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=18 sym=[<string>] buf='ad_server:389'
11711: file=/usr/local/etc/tac_plus.cfg line=20 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=20 sym=[<string>] buf='LDAP_BASE'
11711: file=/usr/local/etc/tac_plus.cfg line=20 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=20 sym=[<string>] buf='dc=mydomain,dc=local'
11711: file=/usr/local/etc/tac_plus.cfg line=21 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=21 sym=[<string>] buf='LDAP_FILTER'
11711: file=/usr/local/etc/tac_plus.cfg line=21 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=21 sym=[<string>] buf='(&(objectclass=Usuarios)(sAMAccountName=%s))'
11711: file=/usr/local/etc/tac_plus.cfg line=22 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=22 sym=[<string>] buf='LDAP_FILTER_CHPW'
11711: file=/usr/local/etc/tac_plus.cfg line=22 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=22 sym=[<string>] buf='(&(objectclass=user) (sAMAccountName=%s))'
11711: file=/usr/local/etc/tac_plus.cfg line=23 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=23 sym=[<string>] buf='LDAP_SCOPE'
11711: file=/usr/local/etc/tac_plus.cfg line=23 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=23 sym=[<string>] buf='sub'
11711: file=/usr/local/etc/tac_plus.cfg line=24 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=24 sym=[<string>] buf='LDAP_USER'
11711: file=/usr/local/etc/tac_plus.cfg line=24 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=24 sym=[<string>] buf='***@***'
11711: file=/usr/local/etc/tac_plus.cfg line=25 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=25 sym=[<string>] buf='LDAP_PASSWD'
11711: file=/usr/local/etc/tac_plus.cfg line=25 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=25 sym=[<string>] buf='*****'
11711: file=/usr/local/etc/tac_plus.cfg line=26 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=26 sym=[<string>] buf='UNLIMIT_AD_GROUP_MEMBERSHIP'
11711: file=/usr/local/etc/tac_plus.cfg line=26 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=26 sym=[<string>] buf='1'
11711: file=/usr/local/etc/tac_plus.cfg line=27 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=27 sym=[<string>] buf='EXPAND_AD_GROUP_MEMBERSHIP'
11711: file=/usr/local/etc/tac_plus.cfg line=27 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=27 sym=[<string>] buf='1'
11711: file=/usr/local/etc/tac_plus.cfg line=28 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=28 sym=[<string>] buf='AD_GROUP_PREFIX'
11711: file=/usr/local/etc/tac_plus.cfg line=28 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=28 sym=[<string>] buf='tacacs'
11711: file=/usr/local/etc/tac_plus.cfg line=29 sym=[setenv] buf='setenv'
11711: file=/usr/local/etc/tac_plus.cfg line=29 sym=[<string>] buf='REQUIRE_TACACS_GROUP_PREFIX'
11711: file=/usr/local/etc/tac_plus.cfg line=29 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=29 sym=[<string>] buf='1'
11711: file=/usr/local/etc/tac_plus.cfg line=30 sym=[exec] buf='exec'
11711: file=/usr/local/etc/tac_plus.cfg line=30 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=30 sym=[<string>] buf='/usr/local/lib/mavis/mavis_tacplus_ldap.pl'
11711: file=/usr/local/etc/tac_plus.cfg line=31 sym=[exec] buf='exec'
11711: file=/usr/local/etc/tac_plus.cfg line=31 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=31 sym=[<string>] buf='/usr/local/lib/mavis/mavis_ldap_authonly.pl'
11711: file=/usr/local/etc/tac_plus.cfg line=32 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=34 sym=[login] buf='login'
11711: file=/usr/local/etc/tac_plus.cfg line=34 sym=[backend] buf='backend'
11711: file=/usr/local/etc/tac_plus.cfg line=34 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=34 sym=[mavis] buf='mavis'
11711: file=/usr/local/etc/tac_plus.cfg line=35 sym=[user] buf='user'
11711: file=/usr/local/etc/tac_plus.cfg line=35 sym=[backend] buf='backend'
11711: file=/usr/local/etc/tac_plus.cfg line=35 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=35 sym=[mavis] buf='mavis'
11711: file=/usr/local/etc/tac_plus.cfg line=36 sym=[pap] buf='pap'
11711: file=/usr/local/etc/tac_plus.cfg line=36 sym=[backend] buf='backend'
11711: file=/usr/local/etc/tac_plus.cfg line=36 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=36 sym=[mavis] buf='mavis'
11711: file=/usr/local/etc/tac_plus.cfg line=38 sym=[host] buf='host'
11711: file=/usr/local/etc/tac_plus.cfg line=38 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=38 sym=[<string>] buf='world'
11711: file=/usr/local/etc/tac_plus.cfg line=38 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=39 sym=[address] buf='address'
11711: file=/usr/local/etc/tac_plus.cfg line=39 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=39 sym=[<string>] buf='::/0'
11711: file=/usr/local/etc/tac_plus.cfg line=40 sym=[prompt] buf='prompt'
11711: file=/usr/local/etc/tac_plus.cfg line=40 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=40 sym=[<string>] buf='Welcome
'
11711: file=/usr/local/etc/tac_plus.cfg line=41 sym=[enable] buf='enable'
11711: file=/usr/local/etc/tac_plus.cfg line=41 sym=[<string>] buf='15'
11711: file=/usr/local/etc/tac_plus.cfg line=41 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=41 sym=[clear] buf='clear'
11711: file=/usr/local/etc/tac_plus.cfg line=41 sym=[<string>] buf='secret'
11711: file=/usr/local/etc/tac_plus.cfg line=42 sym=[key] buf='key'
11711: file=/usr/local/etc/tac_plus.cfg line=42 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=42 sym=[<string>] buf='SuperSecreto'
11711: file=/usr/local/etc/tac_plus.cfg line=44 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=46 sym=[group] buf='group'
11711: file=/usr/local/etc/tac_plus.cfg line=46 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=46 sym=[<string>] buf='admincisco'
11711: file=/usr/local/etc/tac_plus.cfg line=46 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=47 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=47 sym=[service] buf='service'
11711: file=/usr/local/etc/tac_plus.cfg line=47 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=47 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=48 sym=[service] buf='service'
11711: file=/usr/local/etc/tac_plus.cfg line=48 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=48 sym=[shell] buf='shell'
11711: file=/usr/local/etc/tac_plus.cfg line=48 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=49 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=49 sym=[command] buf='command'
11711: file=/usr/local/etc/tac_plus.cfg line=49 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=49 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=50 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=50 sym=[attribute] buf='attribute'
11711: file=/usr/local/etc/tac_plus.cfg line=50 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=50 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=51 sym=[set] buf='set'
11711: file=/usr/local/etc/tac_plus.cfg line=51 sym=[<string>] buf='priv-lvl'
11711: file=/usr/local/etc/tac_plus.cfg line=51 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=51 sym=[<string>] buf='15'
11711: file=/usr/local/etc/tac_plus.cfg line=52 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=53 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=55 sym=[group] buf='group'
11711: file=/usr/local/etc/tac_plus.cfg line=55 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=55 sym=[<string>] buf='admin'
11711: file=/usr/local/etc/tac_plus.cfg line=55 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=56 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=56 sym=[service] buf='service'
11711: file=/usr/local/etc/tac_plus.cfg line=56 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=56 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=57 sym=[service] buf='service'
11711: file=/usr/local/etc/tac_plus.cfg line=57 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=57 sym=[shell] buf='shell'
11711: file=/usr/local/etc/tac_plus.cfg line=57 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=58 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=58 sym=[command] buf='command'
11711: file=/usr/local/etc/tac_plus.cfg line=58 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=58 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=59 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=59 sym=[attribute] buf='attribute'
11711: file=/usr/local/etc/tac_plus.cfg line=59 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=59 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=60 sym=[set] buf='set'
11711: file=/usr/local/etc/tac_plus.cfg line=60 sym=[<string>] buf='priv-lvl'
11711: file=/usr/local/etc/tac_plus.cfg line=60 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=60 sym=[<string>] buf='15'
11711: file=/usr/local/etc/tac_plus.cfg line=61 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=62 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=64 sym=[group] buf='group'
11711: file=/usr/local/etc/tac_plus.cfg line=64 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=64 sym=[<string>] buf='guest'
11711: file=/usr/local/etc/tac_plus.cfg line=64 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=65 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=65 sym=[service] buf='service'
11711: file=/usr/local/etc/tac_plus.cfg line=65 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=65 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=66 sym=[enable] buf='enable'
11711: file=/usr/local/etc/tac_plus.cfg line=66 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=66 sym=[deny] buf='deny'
11711: file=/usr/local/etc/tac_plus.cfg line=67 sym=[service] buf='service'
11711: file=/usr/local/etc/tac_plus.cfg line=67 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=67 sym=[shell] buf='shell'
11711: file=/usr/local/etc/tac_plus.cfg line=67 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=68 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=68 sym=[command] buf='command'
11711: file=/usr/local/etc/tac_plus.cfg line=68 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=68 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=69 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=69 sym=[attribute] buf='attribute'
11711: file=/usr/local/etc/tac_plus.cfg line=69 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=69 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=70 sym=[set] buf='set'
11711: file=/usr/local/etc/tac_plus.cfg line=70 sym=[<string>] buf='priv-lvl'
11711: file=/usr/local/etc/tac_plus.cfg line=70 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=70 sym=[<string>] buf='1'
11711: file=/usr/local/etc/tac_plus.cfg line=71 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=72 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=74 sym=[user] buf='user'
11711: file=/usr/local/etc/tac_plus.cfg line=74 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=74 sym=[<string>] buf='cisco'
11711: file=/usr/local/etc/tac_plus.cfg line=74 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=75 sym=[password] buf='password'
11711: file=/usr/local/etc/tac_plus.cfg line=75 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=75 sym=[clear] buf='clear'
11711: file=/usr/local/etc/tac_plus.cfg line=75 sym=[<string>] buf='cisco'
11711: file=/usr/local/etc/tac_plus.cfg line=76 sym=[member] buf='member'
11711: file=/usr/local/etc/tac_plus.cfg line=76 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=76 sym=[<string>] buf='admin'
11711: file=/usr/local/etc/tac_plus.cfg line=77 sym=[service] buf='service'
11711: file=/usr/local/etc/tac_plus.cfg line=77 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=77 sym=[shell] buf='shell'
11711: file=/usr/local/etc/tac_plus.cfg line=77 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=78 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=78 sym=[command] buf='command'
11711: file=/usr/local/etc/tac_plus.cfg line=78 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=78 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=79 sym=[default] buf='default'
11711: file=/usr/local/etc/tac_plus.cfg line=79 sym=[attribute] buf='attribute'
11711: file=/usr/local/etc/tac_plus.cfg line=79 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=79 sym=[permit] buf='permit'
11711: file=/usr/local/etc/tac_plus.cfg line=80 sym=[set] buf='set'
11711: file=/usr/local/etc/tac_plus.cfg line=80 sym=[<string>] buf='priv-lvl'
11711: file=/usr/local/etc/tac_plus.cfg line=80 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=80 sym=[<string>] buf='15'
11711: file=/usr/local/etc/tac_plus.cfg line=81 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=82 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=84 sym=[user] buf='user'
11711: file=/usr/local/etc/tac_plus.cfg line=84 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=84 sym=[<string>] buf='readonly'
11711: file=/usr/local/etc/tac_plus.cfg line=84 sym=[{] buf='{'
11711: file=/usr/local/etc/tac_plus.cfg line=85 sym=[password] buf='password'
11711: file=/usr/local/etc/tac_plus.cfg line=85 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=85 sym=[clear] buf='clear'
11711: file=/usr/local/etc/tac_plus.cfg line=85 sym=[<string>] buf='readonly'
11711: file=/usr/local/etc/tac_plus.cfg line=86 sym=[member] buf='member'
11711: file=/usr/local/etc/tac_plus.cfg line=86 sym=[=] buf='='
11711: file=/usr/local/etc/tac_plus.cfg line=86 sym=[<string>] buf='guest'
11711: file=/usr/local/etc/tac_plus.cfg line=87 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=88 sym=[}] buf='}'
11711: file=/usr/local/etc/tac_plus.cfg line=90 sym=[<end-of-file>] buf=''
Input attribute-value-pairs:
TYPE                TACPLUS
TIMESTAMP           mavistest-11711-1388496017-0
USER                MyUser
PASSWORD            *******
TACTYPE             AUTH

Output attribute-value-pairs:
TYPE                TACPLUS
TIMESTAMP           mavistest-11711-1388496017-0
USER                MyUser
RESULT              NFD
PASSWORD            ******
SERIAL              geDFB96ZPpVCdTZyqwLBpg=
TACTYPE             AUTH
 

Marc Huber

unread,
Dec 31, 2013, 11:07:39 AM12/31/13
to event-driv...@googlegroups.com
Hi,

On 31.12.13 13:24, Juan Carlos Le�n Centuri�n wrote:
> As you can see below, my user Works fine.
<snip>
> RESULT NFD

alas, no. "NFD" is short for "not found", so I'd guess that either your
LDAP base or your filter doesn't match.

Cheers,

Marc

Juan Carlos León Centurión

unread,
Jan 6, 2014, 11:39:49 AM1/6/14
to event-driv...@googlegroups.com
Thank you for your response Marc!
 
Do you have any example or documentation I can read about the filters or LDAP base?
 
I would be more thankful if you can point me out to the right direction.
 
Thanks once Marc!

El martes, 31 de diciembre de 2013 12:07:39 UTC-4, Marc Huber escribió:
Hi,

Juan Carlos León Centurión

unread,
Jan 10, 2014, 2:44:09 PM1/10/14
to event-driv...@googlegroups.com
Hello Marc,
       How can I translate the bellow configuration to tac_plus conf file? Any idea?
 
 
    The bellow settings is a working configuration for my Tomcat AppServer. 
 
       connectionURL="ldap://IP:389"
        connectionName="user@domain"
        connectionPassword="password"
        referrals="follow"
        userBase="OU=Users,OU=Office,dc=domain,dc=com"
        userSearch="(sAMAccountName={0})"
        userSubtree="true"
        roleBase="OU=Groups,DC=domain,DC=com"
        roleName="name"
        roleSubtree="true"
        roleSearch="(member={0})" /> 
 
Thank you for your kind help.
Reply all
Reply to author
Forward
0 new messages