IP Address for an Unknown User is Not Logged By sshd and Winbind Pam Auth Module

(Doc ID 1446707.1)

Last updated on MAY 09, 2018

Applies to:

Solaris Operating System - Version 10 10/08 U6 and later
Information in this document applies to any platform.


Using winbind as pam module for ssh auth, an IP is logged in the syslog when login is attempted with valid user. With an invalid user, the IP is not logged.

In /etc/ssh/sshd_config:

SyslogFacility auth

In pam.conf we have:

login auth sufficient pam_winbind.so.1 debug
other auth sufficient pam_winbind.so.1 try_first_pass debug

When login is attempted with invalid user, it does not log the IP. It logs only this:

Mar 30 14:55:57 solarishost sshd[1816]: [ID 186046 auth.error] pam_winbind(sshd-kbdint): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_USER_UNKNOWN (13), NTSTATUS: NT_STATUS_NO_SUCH_USER, Error message was: No such user


Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms