something strange I can't understand.


  I have working LDAP which has some users and it
authenticates also fine, but I saw a problem yesterday
when I changed something in system_Auth

# This file is auto-generated.
# User changes will be destroyed the next time
authconfig is run.
auth        required      /lib/security/pam_env.so
auth        sufficient    /lib/security/pam_unix.so
likeauth nullok
auth        sufficient    /lib/security/pam_ldap.so
auth        required      /lib/security/pam_deny.so

account     required      /lib/security/pam_unix.so
#account     required      /lib/security/pam_ldap.so

password    required     
/lib/security/pam_cracklib.so retry=3 type=
password    sufficient    /lib/security/pam_unix.so
nullok use_authtok md5 shadow
password    sufficient    /lib/security/pam_ldap.so
password    required      /lib/security/pam_deny.so

session     required      /lib/security/pam_limits.so
session     required      /lib/security/pam_unix.so
session     optional      /lib/security/pam_ldap.so
"system-auth" 19L, 879C

Above is my system-auth
As soon as I umcommented the commented entry
#account     required      /lib/security/pam_ldap.so
I couldn't login as any user whether the user was in
LDAP database, or system files, so I had boot system
in sigle user mode, and reverted my changes and it
Can anybody make sense of this?
Plus I setup things so that users can change their own
passwords in LDAP, but I tried to change password as a
user using passwd utility, and it told me that only
root can change password.

Does anyone know how I can make this work.
fgollowing are ACL in my ldap

access to dn=".*,dc=navtechinc,dc=com"
        by dn="cn=Manager,dc=navtechinc,dc=com" write
        by self write
        by * auth

access to dn=".*,dc=navtechinc,dc=com" attr=mail
        by dn="cn=Manager,dc=navtechinc,dc=com" write
        by self write
        by * read

access to dn=".*,ou=ykf,dc=navtechinc,dc=com"
        by * read

access to dn=".*,dc=navtechinc,dc=com"
        by self write
        by * read

Thanks in advance.

