Ok new problem today. I'm being asked to connect all of my FreeBSD 11.0 Servers to a radius server for ssh. I have created the /etc/radius.conf file and added my servers both auth and acct lines with the secret.
I have modified my /etc/pam.d/sshd file and just added the pam_radius.so to the sections.
I then restart my sshd service and try to login.
When using root account... I can still access the box no problem.
I do see it gets a radius rejection in the login process for root.
When I try and login using my radius credentials if just keeps telling me Radius rejection and drops me back to a password prompt. The only message I see in the /var/log/security file is
Is there something else I need to add/remove to/from the sshd file to make this work? I have never needed to use radius before. And no I do not have access to the Radius servers... that is controlled by the IT department.
Thanks
Code:
auth server1.f.q.d.n secret
acct server1.f.q.d.n secret
I have modified my /etc/pam.d/sshd file and just added the pam_radius.so to the sections.
Code:
auth sufficient pam_opie.so no_warn no_fake_prompts
auth requisite pam_opieaccess.so no_warn allow_local
auth sufficient pam_radius.so
auth required pam_unix.so no_warn try_first_pass
account sufficient pam_radius.so
account required pam_nologin.so
account required pam_login_access.so
account required pam_unix.so
session required pam_permit.so
password sufficient pam_radius.so
password required pam_unix.so no_warn try_first_pass
I then restart my sshd service and try to login.
When using root account... I can still access the box no problem.
I do see it gets a radius rejection in the login process for root.
Code:
login as: root
Using keyboard-interactive authentication.
RADIUS Password:
Radius rejection
Last login: Wed Jun 28 09:31:42 2017 from a.b.c.d
FreeBSD 11.0-RELEASE-p9 (GENERIC) #0: Tue Apr 11 08:48:40 UTC 2017
When I try and login using my radius credentials if just keeps telling me Radius rejection and drops me back to a password prompt. The only message I see in the /var/log/security file is
Code:
Jun 28 09:51:26 servername sshd[15248]: in openpam_dispatch(): /usr/lib/pam_radius.so.6: no pam_sm_acct_mgmt()
Is there something else I need to add/remove to/from the sshd file to make this work? I have never needed to use radius before. And no I do not have access to the Radius servers... that is controlled by the IT department.
Thanks