IP Address for an Unknown User is Not Logged By sshd and Winbind Pam Auth Module (Doc ID 1446707.1)

Last updated on JULY 29, 2016

Applies to:

Solaris Operating System - Version 10 10/08 U6 and later
Information in this document applies to any platform.

Symptoms

Using winbind as pam module for ssh auth, an IP is logged in the syslog when login is attempted with valid user. With an invalid user, the IP is not logged.

In /etc/ssh/sshd_config:

SyslogFacility auth
LogLevel VERBOSE


In pam.conf we have:

login auth sufficient pam_winbind.so.1 debug
other auth sufficient pam_winbind.so.1 try_first_pass debug


 
When login is attempted with invalid user, it does not log the IP. It logs only this:

Mar 30 14:55:57 solarishost sshd[1816]: [ID 186046 auth.error] pam_winbind(sshd-kbdint): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_USER_UNKNOWN (13), NTSTATUS: NT_STATUS_NO_SUCH_USER, Error message was: No such user

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms