[Samba] pam_mkhomedir.so problem

WebMaster b3 at bdat.net
Wed Jan 4 11:50:13 GMT 2006


Hello;

> session    required    pam_mkhomedir.so skel=/etc/skel/ umask=0077


Well I use optional in 
session optional /lib/security/$ISA/pam_mkhomedir.so skel=/etc/skel/ 
umask=0022


I had the same problem. Initial login runs as user, no as root, and have no 
rights for writing.

See, for example, man sshd_config:

     UsePrivilegeSeparation
             Specifies whether sshd separates privileges by creating an 
unprivileged child process to deal with incoming network traffic.
             After successful authentication, another process will be created 
that has the privilege of the authenticated user.  The goal
             of privilege separation is to prevent privilege escalation by 
containing any corruption within the unprivileged processes.
             The default is "yes".

Set apropiate chmod to /home. I used /home/samba/ for on the fly home 
directories and did not change /home permissions.


Pedrop


http://dns.bdat.net


More information about the samba mailing list