Unable to authenticate with AD user after making AD group entry in access.conf (pam_access.so) file
Issue
- While using pam_access.so module and access.conf file to limit access just to Active Directory users, able to archive it if explicit mention
AD user on access.conf file, but if I try to use a group in stead of using user's name it's not working.
[root@VM-RHEL-JUMP-SERVER-EUS-01 pam.d]# tail /etc/security/access.conf
+:@role-g-example-server-admins : ALL
.
.
.
.
+: root : ALL
-: ALL : ALL
[root@VM-RHEL-JUMP-SERVER-EUS-01 pam.d]#
* sshd[818732]: fatal: Access denied for user rakkumar by PAM account configuration [preauth]
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- SSSD
- Active Directory
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.