The first snippet is from /var/log/messages, and the second is from /var/log/secure. If truly stumped and it wouldn't violate the security of a critical environment, you can also try commenting the account lines one at a time until you identify your culprit. PBIS Open 8.x and higher properly deliver a /usr/share/pam-configs/pbis configuration so that this shouldn't happen in the future.

The system returned: (22) Invalid argument The remote host or network may be down. By default the likewise agent has 25MB of memory allocated, while the memory cache cap is set to unlimited. Connect to the ESXi host using SSH.

Dec 8 08:31:30 ubuntu login[2136]: pam_env(login:session): No such user!? Run this command to start the lsassd services:/etc/init.d/lsassd start Add the host back to the domain.

For the record, here is a copy of the correct /etc/pam.d/common-account configuration that FIXES my issue (the two pam_lsass.so lines were missing from the systems that were not working): account [success=3

asked 6 years ago viewed 5770 times Related 2Ubuntu Login Screen Reloads0Suddenly getting remote login failures from Vista client to NT 4 domain, both undisturbed2Windows XP login at domain takes too

Recently AD authentication stopped working on several workstations after users performed an apt-get upgrade of 200+ packages at once. linux login windows-domain kerberos

By creating an account, you're agreeing to our Terms of Use, Privacy Policy and to receive emails from Spiceworks. I am unable to log in with that user at all, although other 'local' users do work. Authentication attempts give the errors, "invalid password," "user account has expired," or "is your account locked?" I have not been able to link the issue to a specific package upgrade but

Duplicate of bug #598034 Remove Convert to a question Link a related branch Link to CVE You are not directly subscribed to this bug's notifications. When I replaced the ø with o, he was able to log in.

Click the Configuration tab. After a failed login, /var/log/auth.log reports: gdm-session-worker[1477]: pam_succeed_if(gdm:auth): error retrieving information about user \ gdm-session-worker[1477]: pam_unix(gdm:auth): check pass; user unknown gdm-session-worker[1477]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost= Also,

Hard to interpret what happens next without seeing your full account stack, but you'd definitely be skipping past 1 line in another file or the end of the stack entirely. Here's the output from a second user, with lsass.conf configured to explicitly allow access from the trusted user account in the format of DOMAIN\USER. Any user that contained non US-ASCII characters in the Full Name in AD (not even the login name!) could not log in, while others could do.

This results in my name always appearing in the gdm user list, but still about half the time my authentication attempt is denied and I have to reboot That second point

Why this was a problem on only one server, I haven't figuered out yet. Normally, after the machine boots, I am presented with a login screen (gdm, I think) that lists a few accounts. But it does seem that the above problem is caused (or at least related) to the inability of lsassd to start. Pbis Logon Restriction Yes Cheers, Herman http://www.aeronetworks.ca Adv Reply December 8th, 2010 #3 fooraide View Profile View Forum Posts Private Message First Cup of Ubuntu Join Date Aug 2010 Beans 2 Re: Likewise-Open and

The entry resembles to:memory-cache-size-cap = 10485760 Save and close the file. Review the applicable account modules one by one, and try adding the debug flag to individual entries to expand the logging output if you need more hints. Once you know that, it should be much easier to identify why the module thinks the user should be blocked. My personal account is not listed in /etc/passwd but it usually appears, and I just click on it, type password, and log in.

As for what changed, more than likely your PAM config was modified when these packages were installed. Success! Chances are that the users in question were in this state all along, but the database associated with the misbehaving account module was being bypassed. (skipped, commented, not present at all, Subscribing...