Zuerst einmal danke für die Hilfe ☺
Windows Version:
Microsoft Windows Server 2003 Enterprise SP2
Schemaerweiterung durchgeführt:
Nein
/etc/pam.d/common-auth:
auth [success=2 default=ignore] pam_unix.so nullok_secure
auth [success=1 default=ignore] pam_ldap.so use_first_pass
auth requisite pam_deny.so
auth required pam_permit.so
auth sufficient pam_ldap.so
auth required pam_unix.so use_first_pass nullok_secure
/etc/pam.d/common-session
session [default=1] pam_permit.so
session requisite pam_deny.so
session required pam_permit.so
session required pam_unix.so
session optional pam_ldap.so
session optional pam_ck_connector.so nox11
/etc/nsswitch.conf
passwd: compat
group: compat
shadow: compat
hosts: files mdns4_minimal [NOTFOUND=return] dns mdns4
networks: files
protocols: db files
services: db files
ethers: db files
rpc: db files
netgroup: nis
passwd_compat: ldap
group_compat: ldap
shadow_compat: ldap
/etc/ldap.conf
base DC=DOMÄNE,DC=FRIMA,DC=de
uri ldapi://DOMÄNEN-IP/
ldap_version 3
rootbinddn CN=USER,OU=Admins,DC=DOMÄNE,DC=FIRMA,DC=de
pam_password md5
# ADS
scope sub
timelimit 5
bind_timelimit 5
idle_timelimit 3600
pam_login_attribute uid
pam_login_attribute sAMAccountName
pam_password ad
nss_base_passwd <DN_User_Container>
nss_base_shadow <DN_User_Container>
nss_base_group <DN_Group_Container>
nss_map_objectclass posixAccount user
nss_map_objectclass shadowAccount user
nss_map_attribute uid sAMAccountName
nss_map_attribute uidNumber msSFU30UidNumber
nss_map_attribute gidNumber msSFU30GidNumber
nss_map_attribute cn sAMAccountName
nss_map_attribute posixGroup memberOf
nss_map_attribute userPassword msSFU30Password
nss_map_attribute homeDirectory msSFU30HomeDirectory
nss_map_attribute loginShell msSFU30LoginShell
nss_map_attribute gecos name
nss_map_objectclass posixGroup group
nss_map_attribute uniqueMember member
pam_filter objectclass=user
ssl no
bind_policy soft
nss_initgroups_ignoreusers +,avahi,avahi-autoipd,backup,bin,couchdb,daemon,games,gdm,gnats,haldaemon,hplip,irc,kernoops,libuuid,list,lp,mail,man,messagebus,news,proxy,pulse,root,rtkit,saned,speech-dispatcher,sync,sys,syslog,usbmux,uucp,www-data
/etc/krb5.conf
Exestiert nicht