PAM error (unable to open /etc/pam.d/system-auth) occurred.

Solution Unverified - Updated -

Issue

  • The customer wants to know the cause for the following messages.
  • Excerpt from secure log.
Feb 21 01:10:01 EASAP002 crond[7937]: PAM _pam_load_conf_file: unable to open /etc/pam.d/system-auth 
Feb 21 01:10:01 EASAP002 crond[7937]: PAM unable to dlopen(<*unknown module path*>) 
Feb 21 01:10:01 EASAP002 crond[7937]: PAM [error: <*unknown module path*>: 共有オブジェクトファイルを開けません: そのようなファイルやディレクトリはありません]
Feb 21 01:10:01 EASAP002 crond[7937]: PAM adding faulty module: <*unknown module path*>
  • Excerpt from cron log.
Feb 21 01:09:01 EASAP002 crond[6700]: (root) CMD (/opt/UMF/Operations/apchk/apchk.sh)
Feb 21 01:10:01 EASAP002 crond[7937]: モジュールが不明です
Feb 21 01:10:01 EASAP002 crond[7937]: CRON (root) ERROR: failed to open PAM security session: 成功です
Feb 21 01:10:01 EASAP002 crond[7937]: CRON (root) ERROR: cannot set security context Feb 21 01:10:01 EASAP002 crond[7938]: (root) CMD (/usr/lib64/sa/sa1 1 1) Feb 21 01:10:01 EASAP002 crond[7939]: (root) CMD (/root/scripts/del_log/del_wlstlog.sh)
  • From cron log and cron configuration, I think it occurred during when user script is executed by crond every a minute.

  • /var/spool/cron/root

0 0 * * * /root/logrotate.daily/logrotate
*/1 * * * * /path/to/user/script/user_script.sh
<snip>
  • We confirmed that the same messages were logged in /var/log/secure and cron log when removing /etc/pam.d/system-auth-ac. However, this issue occurred only once, so it seems that actually /etc/pam.d/system-auth-ac was not removed.

Environment

  • Red Hat Enterprise Linux 5.7
  • pam-0.99.6.2-6.el5_5.2
  • vixie-cron-4.1-77.el5_4.1

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.