Re: Invalid credentials

ok i think i see what you are saying. I didnt think pam_ldap needed to
support SASL. I thought pam_ldap <-> openldap communicate via anonymous
bind  and then openldap would hand off to SASL on its own to

So as far as the sshd file in /etc/pam.d, auth and password would be
pam_radius, and account would be pam_ldap right ?  that would keep all
account information in the LDAP directory (uid, homedir and shell),
however direct authentication towards the radius server. I have nss_ldap
working ( i can finger, and id a user with results) and i can auth
successfully using pam_radius_auth, so i guess its just a matter of the
right pam.d file at this point.  Any pointers there?

thanks again 

> Well, actually your stack would be PAM->LDAP->SASL->PAM->RADIUS, however
> this isn't possible, because pam_ldap doesn't implement this (it only
> implements simple binds, no SASL binds). I don't think this would make
> sense. Why don't you just use PAM->RADIUS directly? It is possible (and
> quite feasible) to combine nss_ldap (the modile to resolve uids and the
> like) with any other PAM module (like pam_radius or pam_krb5).
> This ACL where sufficient for simple authentication if the password was
> stored in the userPassword attribute.
