Unable to log in RHEL 6.10 host with AD user- Error: pam_ldap: ldap_simple_bind Can't contact LDAP server

Solution Verified - Updated -

Issue

  1. While trying to access the server rhel-server which was integrated with AD using nslcd , getting below given error:
Apr 26 16:27:59 rhel-server sshd[22773]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=remote-client  user=aduser
Apr 26 16:27:59 rhel-server sshd[22773]: pam_ldap: ldap_simple_bind Can't contact LDAP server
Apr 26 16:27:59 rhel-server sshd[22773]: pam_ldap: reconnecting to LDAP server...
Apr 26 16:27:59 rhel-server sshd[22773]: pam_ldap: ldap_simple_bind Can't contact LDAP server
Apr 26 16:28:01 rhel-server sshd[22773]: Failed password for aduser from 10.51.0.95 port 26379 ssh2
  1. This is /etc/pam.d/password-auth:
auth        required      pam_env.so
auth        sufficient    pam_unix.so nullok try_first_pass
auth        requisite     pam_succeed_if.so uid >= 500 quiet
auth        sufficient    pam_ldap.so use_first_pass
auth        required      pam_deny.so

account     required      pam_unix.so broken_shadow
account     sufficient    pam_localuser.so
account     sufficient    pam_succeed_if.so uid < 500 quiet
account     [default=bad success=ok user_unknown=ignore] pam_ldap.so
account     required      pam_permit.so

password    requisite     pam_cracklib.so try_first_pass retry=3 type=
password    sufficient    pam_unix.so sha512 shadow nullok try_first_pass use_authtok
password    sufficient    pam_ldap.so use_authtok
password    required      pam_deny.so


session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so
session     optional      pam_ldap.so
  1. This is /etc/openldap/ldap.conf:
URI ldap://adserver.example.com/
BASE o=example

# This is included for pam_ldap.conf
binddn cn=pamproxyuser,ou=admin,o=example
bindpw password
scope sub

ldap_version   3
timelimit      120
bind_timelimit 120
idle_timelimit 3600
bind_policy    soft
deref          never


# DNs in groups
nss_map_attribute uniqueMember member
nss_map_attribute uid shortName
nss_map_attribute userPassword authPassword

nss_initgroups_ignoreusers root daemon bin sys sync games man lp mail news uucp proxy www-data backup list irc gnats nobody libuuid statd sshd puppet


pam_login_attribute              shortName
pam_member_attribute             uniqueMember
pam_password                     nds
pam_password_prohibit_message        Please change your password from your local workstation or the portal.

#ssl start_tls
#ssl on
#TLS_CACERTFILE /etc/ssl/certs/ldap.pem
ssl no

Environment

  • Red Hat Enterprise Linux 6.10

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content