Jump to content

Recommended Posts

Posted

pam_mount.conf.xml:

   path="UserProfiles" mountpoint="/home/local/BROOKVALE"
 options="sec=krb5i,user=%(DOMAIN_USER)@%(DOMAIN_NAME),uid=%(USERUID),gid=%(USERGID),cruid=%(USERUID),nodev,nosuid,file_mode=0700,dir_mode=0700">
 
 
 

Posted
One thing I did have to change in there was to change the 'sec=kerb5i' to 'sec=kerb5'. Also check if you XML parses correctly (you should have an error in auth.log if not).
Posted

Right, changed that and now there seems to be a few more details in the auth.log file:

Jun 30 15:32:42 simon-rm-nbook-200 systemd-logind[551]: New seat seat0.
Jun 30 15:32:42 simon-rm-nbook-200 systemd-logind[551]: Watching system buttons on /dev/input/event2 (Power Button)
Jun 30 15:32:42 simon-rm-nbook-200 systemd-logind[551]: Watching system buttons on /dev/input/event1 (Power Button)
Jun 30 15:32:42 simon-rm-nbook-200 systemd-logind[551]: Watching system buttons on /dev/input/event0 (Lid Switch)
Jun 30 15:32:42 simon-rm-nbook-200 systemd-logind[551]: Watching system buttons on /dev/input/event5 (Video Bus)
Jun 30 15:32:48 simon-rm-nbook-200 lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Jun 30 15:32:48 simon-rm-nbook-200 lightdm: PAM adding faulty module: pam_kwallet.so
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (pam_mount.c:568): pam_mount 2.14: entering session stage
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (pam_mount.c:477): warning: could not obtain password interactively either
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:267): Mount info: globalconf, user=lightdm  fstab=0 ssh=0
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:664): Password will be sent to helper as-is.
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: command: 'mount' '-t' 'cifs' '//bhs-sr-001.brookvale.internal/UserProfiles' '/home/local/BROOKVALE' '-o' 'username=lightdm,uid=120,gid=129,sec=krb5,user=lightdm@,uid=120,gid=129,cruid=120,nodev,nosuid,file_mode=0700,dir_mode=0700'
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:72): Messages from underlying mount program:
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:76): mount error: could not resolve address for bhs-sr-001.brookvale.internal: Unknown error
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 17 22 0:16 / /sys rw,nosuid,nodev,noexec,relatime shared:7 - sysfs sysfs rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 18 22 0:4 / /proc rw,nosuid,nodev,noexec,relatime shared:12 - proc proc rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 19 22 0:6 / /dev rw,relatime shared:2 - devtmpfs udev rw,size=1875104k,nr_inodes=468776,mode=755
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 20 19 0:13 / /dev/pts rw,nosuid,noexec,relatime shared:3 - devpts devpts rw,gid=5,mode=620,ptmxmode=000
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 21 22 0:17 / /run rw,nosuid,noexec,relatime shared:5 - tmpfs tmpfs rw,size=377252k,mode=755
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 22 0 8:1 / / rw,relatime shared:1 - ext4 /dev/disk/by-uuid/5f170ada-78f1-4c37-b9ee-933b21534cb8 rw,errors=remount-ro,data=ordered
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 23 17 0:11 / /sys/kernel/security rw,nosuid,nodev,noexec,relatime shared:8 - securityfs securityfs rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 24 19 0:18 / /dev/shm rw,nosuid,nodev shared:4 - tmpfs tmpfs rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 25 21 0:19 / /run/lock rw,nosuid,nodev,noexec,relatime shared:6 - tmpfs tmpfs rw,size=5120k
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 26 17 0:20 / /sys/fs/cgroup ro,nosuid,nodev,noexec shared:9 - tmpfs tmpfs ro,mode=755
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 27 26 0:21 / /sys/fs/cgroup/systemd rw,nosuid,nodev,noexec,relatime shared:10 - cgroup cgroup rw,xattr,release_agent=/lib/systemd/systemd-cgroups-agent,name=systemd
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 28 17 0:22 / /sys/fs/pstore rw,nosuid,nodev,noexec,relatime shared:11 - pstore pstore rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 29 26 0:23 / /sys/fs/cgroup/hugetlb rw,nosuid,nodev,noexec,relatime shared:13 - cgroup cgroup rw,hugetlb
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 30 26 0:24 / /sys/fs/cgroup/blkio rw,nosuid,nodev,noexec,relatime shared:14 - cgroup cgroup rw,blkio
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 31 26 0:25 / /sys/fs/cgroup/cpu,cpuacct rw,nosuid,nodev,noexec,relatime shared:15 - cgroup cgroup rw,cpu,cpuacct
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 32 26 0:26 / /sys/fs/cgroup/memory rw,nosuid,nodev,noexec,relatime shared:16 - cgroup cgroup rw,memory
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 33 26 0:27 / /sys/fs/cgroup/devices rw,nosuid,nodev,noexec,relatime shared:17 - cgroup cgroup rw,devices
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 34 26 0:28 / /sys/fs/cgroup/net_cls,net_prio rw,nosuid,nodev,noexec,relatime shared:18 - cgroup cgroup rw,net_cls,net_prio
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 35 26 0:29 / /sys/fs/cgroup/freezer rw,nosuid,nodev,noexec,relatime shared:19 - cgroup cgroup rw,freezer
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 36 26 0:30 / /sys/fs/cgroup/cpuset rw,nosuid,nodev,noexec,relatime shared:20 - cgroup cgroup rw,cpuset,clone_children
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 37 26 0:31 / /sys/fs/cgroup/perf_event rw,nosuid,nodev,noexec,relatime shared:21 - cgroup cgroup rw,perf_event
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 38 18 0:32 / /proc/sys/fs/binfmt_misc rw,relatime shared:22 - autofs systemd-1 rw,fd=21,pgrp=1,timeout=300,minproto=5,maxproto=5,direct
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 39 17 0:7 / /sys/kernel/debug rw,relatime shared:23 - debugfs debugfs rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 40 19 0:33 / /dev/hugepages rw,relatime shared:24 - hugetlbfs hugetlbfs rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 41 19 0:15 / /dev/mqueue rw,relatime shared:25 - mqueue mqueue rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:558): 42 17 0:34 / /sys/fs/fuse/connections rw,relatime shared:26 - fusectl fusectl rw
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (pam_mount.c:522): mount of UserProfiles failed
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (pam_mount.c:477): warning: could not obtain password interactively either
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: command: 'pmvarrun' '-u' 'lightdm' '-o' '1'
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (pam_mount.c:441): pmvarrun says login count is 1
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (pam_mount.c:660): done opening session (ret=0)
Jun 30 15:32:49 simon-rm-nbook-200 systemd-logind[551]: New session c1 of user lightdm.
Jun 30 15:32:49 simon-rm-nbook-200 systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Jun 30 15:32:49 simon-rm-nbook-200 lightdm: pam_mkhomedir(lightdm-greeter:session): unknown option: /skel=/etc/skel
Jun 30 15:32:51 simon-rm-nbook-200 dbus[619]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.17" (uid=0 pid=970 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.7" (uid=0 pid=591 comm="/usr/sbin/NetworkManager --no-daemon ")
Jun 30 15:32:52 simon-rm-nbook-200 lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Jun 30 15:32:52 simon-rm-nbook-200 lightdm: PAM adding faulty module: pam_kwallet.so
Jun 30 15:32:52 simon-rm-nbook-200 lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "simon"
Jun 30 15:32:58 simon-rm-nbook-200 lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Jun 30 15:32:58 simon-rm-nbook-200 lightdm: PAM adding faulty module: pam_kwallet.so
Jun 30 15:33:13 simon-rm-nbook-200 lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Jun 30 15:33:13 simon-rm-nbook-200 lightdm: PAM adding faulty module: pam_kwallet.so
Jun 30 15:33:13 simon-rm-nbook-200 lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "harrypotter"
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: (pam_mount.c:365): pam_mount 2.14: entering auth stage
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: (pam_mount.c:706): received order to close things
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: command: 'pmvarrun' '-u' 'lightdm' '-o' '-1'
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: (pam_mount.c:441): pmvarrun says login count is 0
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: (mount.c:889): going to unmount
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: (mount.c:267): Mount info: globalconf, user=lightdm  fstab=0 ssh=0
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: command: 'pmt-ofl' '-k0' '/home/local/BROOKVALE'
Jun 30 15:33:19 simon-rm-nbook-200 lightdm: command: 'umount' '/home/local/BROOKVALE'
Jun 30 15:33:20 simon-rm-nbook-200 lightdm: (mount.c:72): umount messages:
Jun 30 15:33:20 simon-rm-nbook-200 lightdm: (mount.c:76): umount: /home/local/BROOKVALE: not mounted
Jun 30 15:33:20 simon-rm-nbook-200 lightdm: (mount.c:892): unmount of UserProfiles failed
Jun 30 15:33:20 simon-rm-nbook-200 lightdm: (pam_mount.c:743): pam_mount execution complete
Jun 30 15:33:20 simon-rm-nbook-200 lightdm: (pam_mount.c:116): Clean global config (0)
Jun 30 15:33:20 simon-rm-nbook-200 lightdm: pam_unix(lightdm:session): session opened for user harrypotter by (uid=0)
Jun 30 15:33:25 simon-rm-nbook-200 gnome-keyring-daemon[1480]: The PKCS#11 component was already initialized
Jun 30 15:33:25 simon-rm-nbook-200 gnome-keyring-daemon[1480]: The SSH agent was already initialized
Jun 30 15:33:26 simon-rm-nbook-200 gnome-keyring-daemon[1480]: The GPG agent was already initialized
Jun 30 15:33:27 simon-rm-nbook-200 gnome-keyring-daemon[1480]: The Secret Service was already initialized
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (pam_mount.c:365): pam_mount 2.14: entering auth stage
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: Successful su for simon by harrypotter
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: + /dev/pts/1 harrypotter:simon
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: pam_unix(su:session): session opened for user simon by harrypotter(uid=267925267)
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (pam_mount.c:568): pam_mount 2.14: entering session stage
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:267): Mount info: globalconf, user=simon  fstab=0 ssh=0
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:664): Password will be sent to helper as-is.
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: command: 'mount' '-t' 'cifs' '//bhs-sr-001.brookvale.internal/UserProfiles' '/home/local/BROOKVALE' '-o' 'username=simon,uid=1000,gid=1000,sec=krb5,user=simon@,uid=1000,gid=1000,cruid=1000,nodev,nosuid,file_mode=0700,dir_mode=0700'
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:72): Messages from underlying mount program:
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:76): mount error(126): Required key not available
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:76): Refer to the mount.cifs(8) manual page (e.g. man mount.cifs)
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 17 22 0:16 / /sys rw,nosuid,nodev,noexec,relatime shared:7 - sysfs sysfs rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 18 22 0:4 / /proc rw,nosuid,nodev,noexec,relatime shared:12 - proc proc rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 19 22 0:6 / /dev rw,relatime shared:2 - devtmpfs udev rw,size=1875104k,nr_inodes=468776,mode=755
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 20 19 0:13 / /dev/pts rw,nosuid,noexec,relatime shared:3 - devpts devpts rw,gid=5,mode=620,ptmxmode=000
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 21 22 0:17 / /run rw,nosuid,noexec,relatime shared:5 - tmpfs tmpfs rw,size=377252k,mode=755
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 22 0 8:1 / / rw,relatime shared:1 - ext4 /dev/disk/by-uuid/5f170ada-78f1-4c37-b9ee-933b21534cb8 rw,errors=remount-ro,data=ordered

continued...

Posted
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 23 17 0:11 / /sys/kernel/security rw,nosuid,nodev,noexec,relatime shared:8 - securityfs securityfs rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 24 19 0:18 / /dev/shm rw,nosuid,nodev shared:4 - tmpfs tmpfs rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 25 21 0:19 / /run/lock rw,nosuid,nodev,noexec,relatime shared:6 - tmpfs tmpfs rw,size=5120k
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 26 17 0:20 / /sys/fs/cgroup ro,nosuid,nodev,noexec shared:9 - tmpfs tmpfs ro,mode=755
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 27 26 0:21 / /sys/fs/cgroup/systemd rw,nosuid,nodev,noexec,relatime shared:10 - cgroup cgroup rw,xattr,release_agent=/lib/systemd/systemd-cgroups-agent,name=systemd
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 28 17 0:22 / /sys/fs/pstore rw,nosuid,nodev,noexec,relatime shared:11 - pstore pstore rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 29 26 0:23 / /sys/fs/cgroup/hugetlb rw,nosuid,nodev,noexec,relatime shared:13 - cgroup cgroup rw,hugetlb
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 30 26 0:24 / /sys/fs/cgroup/blkio rw,nosuid,nodev,noexec,relatime shared:14 - cgroup cgroup rw,blkio
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 31 26 0:25 / /sys/fs/cgroup/cpu,cpuacct rw,nosuid,nodev,noexec,relatime shared:15 - cgroup cgroup rw,cpu,cpuacct
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 32 26 0:26 / /sys/fs/cgroup/memory rw,nosuid,nodev,noexec,relatime shared:16 - cgroup cgroup rw,memory
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 33 26 0:27 / /sys/fs/cgroup/devices rw,nosuid,nodev,noexec,relatime shared:17 - cgroup cgroup rw,devices
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 34 26 0:28 / /sys/fs/cgroup/net_cls,net_prio rw,nosuid,nodev,noexec,relatime shared:18 - cgroup cgroup rw,net_cls,net_prio
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 35 26 0:29 / /sys/fs/cgroup/freezer rw,nosuid,nodev,noexec,relatime shared:19 - cgroup cgroup rw,freezer
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 36 26 0:30 / /sys/fs/cgroup/cpuset rw,nosuid,nodev,noexec,relatime shared:20 - cgroup cgroup rw,cpuset,clone_children
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 37 26 0:31 / /sys/fs/cgroup/perf_event rw,nosuid,nodev,noexec,relatime shared:21 - cgroup cgroup rw,perf_event
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 38 18 0:32 / /proc/sys/fs/binfmt_misc rw,relatime shared:22 - autofs systemd-1 rw,fd=21,pgrp=1,timeout=300,minproto=5,maxproto=5,direct
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 39 17 0:7 / /sys/kernel/debug rw,relatime shared:23 - debugfs debugfs rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 40 19 0:33 / /dev/hugepages rw,relatime shared:24 - hugetlbfs hugetlbfs rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 41 19 0:15 / /dev/mqueue rw,relatime shared:25 - mqueue mqueue rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 42 17 0:34 / /sys/fs/fuse/connections rw,relatime shared:26 - fusectl fusectl rw
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (mount.c:558): 72 21 0:35 / /run/user/120 rw,nosuid,nodev,relatime shared:55 - tmpfs tmpfs rw,size=377252k,mode=700,uid=120,gid=129
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (pam_mount.c:522): mount of UserProfiles failed
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: command: 'pmvarrun' '-u' 'simon' '-o' '1'
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (pam_mount.c:441): pmvarrun says login count is 1
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: (pam_mount.c:660): done opening session (ret=0)
Jun 30 15:34:32 simon-rm-nbook-200 systemd-logind[551]: New session c2 of user simon.
Jun 30 15:34:32 simon-rm-nbook-200 systemd: pam_unix(systemd-user:session): session opened for user simon by (uid=0)
Jun 30 15:34:32 simon-rm-nbook-200 su[1736]: pam_mkhomedir(su:session): unknown option: /skel=/etc/skel
Jun 30 15:34:49 simon-rm-nbook-200 systemd-logind[551]: Removed session c1.
Jun 30 15:34:49 simon-rm-nbook-200 systemd: pam_unix(systemd-user:session): session closed for user lightdm
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: pam_unix(su:session): session closed for user simon
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: (pam_mount.c:706): received order to close things
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: command: 'pmvarrun' '-u' 'simon' '-o' '-1'
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: (pam_mount.c:441): pmvarrun says login count is 0
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: (mount.c:889): going to unmount
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: (mount.c:267): Mount info: globalconf, user=simon  fstab=0 ssh=0
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: command: 'pmt-ofl' '-k0' '/home/local/BROOKVALE'
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: command: 'umount' '/home/local/BROOKVALE'
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: (mount.c:72): umount messages:
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: (mount.c:76): umount: /home/local/BROOKVALE: not mounted
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: (mount.c:892): unmount of UserProfiles failed
Jun 30 15:35:28 simon-rm-nbook-200 su[1736]: (pam_mount.c:743): pam_mount execution complete

Posted

Jun 30 15:32:49 simon-rm-nbook-200 lightdm: (mount.c:76): mount error: could not resolve address for bhs-sr-001.brookvale.internal: Unknown error

 

Can you ping 'bhs-sr-001.brookvale.internal' from this machine? If not, you would appear to have a DNS issue (hint: It's always DNS).

Posted
As per a windows domain PC. Your search domain needs to be the DNS domain name and your DNS needs to be set to your Domain Controller(s).
Posted
Put the DNS settings in but still shows the same thing. I think it's trying to launch the mount before the network interface is starting which is why it's failing. Also, why does it appear to be trying to use the username 'lightdm'? That doesn't exist anywhere.
Posted

Still can't fathom what's going on then. Cleared my auth.log and rebooted and this is what's in the auth.log now:

 

Jul  2 08:17:56 simon-rm-nbook-200 systemd-logind[612]: New seat seat0.
Jul  2 08:17:56 simon-rm-nbook-200 systemd-logind[612]: Watching system buttons on /dev/input/event2 (Power Button)
Jul  2 08:17:56 simon-rm-nbook-200 systemd-logind[612]: Watching system buttons on /dev/input/event1 (Power Button)
Jul  2 08:17:56 simon-rm-nbook-200 systemd-logind[612]: Watching system buttons on /dev/input/event0 (Lid Switch)
Jul  2 08:17:56 simon-rm-nbook-200 systemd-logind[612]: Watching system buttons on /dev/input/event5 (Video Bus)
Jul  2 08:18:03 simon-rm-nbook-200 lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Jul  2 08:18:03 simon-rm-nbook-200 lightdm: PAM adding faulty module: pam_kwallet.so
Jul  2 08:18:03 simon-rm-nbook-200 lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (pam_mount.c:568): pam_mount 2.14: entering session stage
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (pam_mount.c:477): warning: could not obtain password interactively either
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:267): Mount info: globalconf, user=lightdm  fstab=0 ssh=0
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:664): Password will be sent to helper as-is.
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: command: 'mount' '-t' 'cifs' '//bhs-sr-001.brookvale.internal/UserProfiles' '/home/local/BROOKVALE' '-o' 'username=lightdm,uid=120,gid=129,sec=krb5,user=lightdm@,uid=120,gid=129,cruid=120,nodev,nosuid,file_mode=0700,dir_mode=0700'
Jul  2 08:18:04 simon-rm-nbook-200 dbus[628]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.15" (uid=0 pid=944 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.7" (uid=0 pid=571 comm="/usr/sbin/NetworkManager --no-daemon ")
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:72): Messages from underlying mount program:
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:76): mount error(126): Required key not available
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:76): Refer to the mount.cifs(8) manual page (e.g. man mount.cifs)
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 17 22 0:16 / /sys rw,nosuid,nodev,noexec,relatime shared:7 - sysfs sysfs rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 18 22 0:4 / /proc rw,nosuid,nodev,noexec,relatime shared:12 - proc proc rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 19 22 0:6 / /dev rw,relatime shared:2 - devtmpfs udev rw,size=1875104k,nr_inodes=468776,mode=755
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 20 19 0:13 / /dev/pts rw,nosuid,noexec,relatime shared:3 - devpts devpts rw,gid=5,mode=620,ptmxmode=000
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 21 22 0:17 / /run rw,nosuid,noexec,relatime shared:5 - tmpfs tmpfs rw,size=377252k,mode=755
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 22 0 8:1 / / rw,relatime shared:1 - ext4 /dev/disk/by-uuid/5f170ada-78f1-4c37-b9ee-933b21534cb8 rw,errors=remount-ro,data=ordered
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 23 17 0:11 / /sys/kernel/security rw,nosuid,nodev,noexec,relatime shared:8 - securityfs securityfs rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 24 19 0:18 / /dev/shm rw,nosuid,nodev shared:4 - tmpfs tmpfs rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 25 21 0:19 / /run/lock rw,nosuid,nodev,noexec,relatime shared:6 - tmpfs tmpfs rw,size=5120k
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 26 17 0:20 / /sys/fs/cgroup ro,nosuid,nodev,noexec shared:9 - tmpfs tmpfs ro,mode=755
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 27 26 0:21 / /sys/fs/cgroup/systemd rw,nosuid,nodev,noexec,relatime shared:10 - cgroup cgroup rw,xattr,release_agent=/lib/systemd/systemd-cgroups-agent,name=systemd
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 28 17 0:22 / /sys/fs/pstore rw,nosuid,nodev,noexec,relatime shared:11 - pstore pstore rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 29 26 0:23 / /sys/fs/cgroup/devices rw,nosuid,nodev,noexec,relatime shared:13 - cgroup cgroup rw,devices
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 30 26 0:24 / /sys/fs/cgroup/net_cls,net_prio rw,nosuid,nodev,noexec,relatime shared:14 - cgroup cgroup rw,net_cls,net_prio
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 31 26 0:25 / /sys/fs/cgroup/memory rw,nosuid,nodev,noexec,relatime shared:15 - cgroup cgroup rw,memory
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 32 26 0:26 / /sys/fs/cgroup/perf_event rw,nosuid,nodev,noexec,relatime shared:16 - cgroup cgroup rw,perf_event
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 33 26 0:27 / /sys/fs/cgroup/cpu,cpuacct rw,nosuid,nodev,noexec,relatime shared:17 - cgroup cgroup rw,cpu,cpuacct
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 34 26 0:28 / /sys/fs/cgroup/cpuset rw,nosuid,nodev,noexec,relatime shared:18 - cgroup cgroup rw,cpuset,clone_children
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 35 26 0:29 / /sys/fs/cgroup/freezer rw,nosuid,nodev,noexec,relatime shared:19 - cgroup cgroup rw,freezer
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 36 26 0:30 / /sys/fs/cgroup/blkio rw,nosuid,nodev,noexec,relatime shared:20 - cgroup cgroup rw,blkio
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 37 26 0:31 / /sys/fs/cgroup/hugetlb rw,nosuid,nodev,noexec,relatime shared:21 - cgroup cgroup rw,hugetlb
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 38 18 0:32 / /proc/sys/fs/binfmt_misc rw,relatime shared:22 - autofs systemd-1 rw,fd=27,pgrp=1,timeout=300,minproto=5,maxproto=5,direct
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 39 17 0:7 / /sys/kernel/debug rw,relatime shared:23 - debugfs debugfs rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 40 19 0:33 / /dev/hugepages rw,relatime shared:24 - hugetlbfs hugetlbfs rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 41 19 0:15 / /dev/mqueue rw,relatime shared:25 - mqueue mqueue rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:558): 42 17 0:34 / /sys/fs/fuse/connections rw,relatime shared:26 - fusectl fusectl rw
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (pam_mount.c:522): mount of UserProfiles failed
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (pam_mount.c:477): warning: could not obtain password interactively either
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: command: 'pmvarrun' '-u' 'lightdm' '-o' '1'
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (pam_mount.c:441): pmvarrun says login count is 1
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (pam_mount.c:660): done opening session (ret=0)
Jul  2 08:18:04 simon-rm-nbook-200 systemd-logind[612]: New session c1 of user lightdm.
Jul  2 08:18:04 simon-rm-nbook-200 systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Jul  2 08:18:04 simon-rm-nbook-200 lightdm: pam_mkhomedir(lightdm-greeter:session): unknown option: /skel=/etc/skel
Jul  2 08:18:06 simon-rm-nbook-200 lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Jul  2 08:18:06 simon-rm-nbook-200 lightdm: PAM adding faulty module: pam_kwallet.so
Jul  2 08:18:06 simon-rm-nbook-200 lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "systemadmin"
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (pam_mount.c:365): pam_mount 2.14: entering auth stage
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (pam_mount.c:706): received order to close things
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: command: 'pmvarrun' '-u' 'lightdm' '-o' '-1'
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (pam_mount.c:441): pmvarrun says login count is 0
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (mount.c:889): going to unmount
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (mount.c:267): Mount info: globalconf, user=lightdm  fstab=0 ssh=0
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: command: 'pmt-ofl' '-k0' '/home/local/BROOKVALE'
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: command: 'umount' '/home/local/BROOKVALE'
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (mount.c:72): umount messages:
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (mount.c:76): umount: /home/local/BROOKVALE: not mounted
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (mount.c:892): unmount of UserProfiles failed
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (pam_mount.c:743): pam_mount execution complete
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: (pam_mount.c:116): Clean global config (0)
Jul  2 08:18:20 simon-rm-nbook-200 lightdm: pam_unix(lightdm:session): session opened for user systemadmin by (uid=0)
Jul  2 08:18:25 simon-rm-nbook-200 gnome-keyring-daemon[1485]: The PKCS#11 component was already initialized
Jul  2 08:18:26 simon-rm-nbook-200 gnome-keyring-daemon[1485]: The SSH agent was already initialized
Jul  2 08:18:26 simon-rm-nbook-200 gnome-keyring-daemon[1485]: The GPG agent was already initialized
Jul  2 08:18:27 simon-rm-nbook-200 gnome-keyring-daemon[1485]: The Secret Service was already initialized
Jul  2 08:19:12 simon-rm-nbook-200 sudo: (pam_mount.c:365): pam_mount 2.14: entering auth stage
Jul  2 08:19:12 simon-rm-nbook-200 sudo: systemadmin : TTY=pts/1 ; PWD=/home/local/BROOKVALE/systemadmin ; USER=root ; COMMAND=/usr/bin/gedit /var/log/auth.log
Jul  2 08:19:12 simon-rm-nbook-200 sudo: pam_unix(sudo:session): session opened for user root by systemadmin(uid=0)

Posted

Jul  2 08:18:04 simon-rm-nbook-200 lightdm: (mount.c:76): mount error(126): Required key not available

 

Looks like a kerberos issue to me. Is the keytab in /var/run/user//

Posted
I'm going to start again from scratch this time using Ubuntu 14.04. I'm using 15.04 at the moment and I ran into some teething problems installing pbis due to systemd, so maybe this is why I'm encountering problems.
Posted
You could always downgrade the security method in pam_mount's cifs call to ntlmv2 if you get really stuck. Not ideal I know, but if it means it works.
Posted (edited)

@simonhayes

Can I suggest you use realmd (made by Redhat, but available in Ubuntu from 14.04 onwards). Realmd is by far the simplest way of joining Linux to an AD domain.

 

Once you have your machine working using the realm tool, try what @mjk suggests in their post:

http://www.edugeek.net/forums/nix/153923-ubuntu-mount-windows-share-logon.html#post1319895

 

Centos and Redhat use sssd and realmd by default when you attempt an enterprise login, so it's definitely the way forwards compared with smb authentication.

 

This is about the best write-up on realmd for Ubuntu by some margin.

Utilising Kerberos/AD auth in Ubuntu 14.04 with realmd - Myles Gray

 

 

If you need the full manual for realmd, it's provided by RedHat. If you can say one thing about RedHat, it's that their documentation is second to none.

https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Windows_Integration_Guide/ch-Configuring_Authentication.html

 

 

One thing missing from this is that Ubuntu will not let you login with a user that it doesn't know about. To allow a free text input for the username (e.g. domain\me) you must change a setting in the lighdm 'Greeter' screen you see right at the login screen.

Edit the file: /usr/share/lightdm/lightdm.conf.d/50-ubuntu.conf

and add this line of code to the file.

greeter-show-manual-login=true

 

 

I've distilled the meat of this into my mini-cheatsheet, pasted below.

realm discover

 

realm -v join -U user

 

Edit /etc/pam.d/common-session

 

Add this line at the end

session required pam_mkhomedir.so skel=/etc/skel/ umask=0022

 

 

Ubuntu Greeter will not allow you to log-in with free text until you allow a manual login

 

Edit /usr/share/lightdm/lightdm.conf.d/50-ubuntu.conf

 

[seatDefaults]

user-session=ubuntu

greeter-show-manual-login=true

Edited by jinnantonnixx
Posted
Sorry, didn't get round to trying any of that yesterday. The blasted laptop I was using has gone into the dreaded low graphics mode and I can't seem to get it out. I'm going to try again on a different laptop.
Posted (edited)
Sorry, didn't get round to trying any of that yesterday. The blasted laptop I was using has gone into the dreaded low graphics mode and I can't seem to get it out. I'm going to try again on a different laptop.

 

 

By coincidence, I had a graphics disaster in the week. Once you know how to fix it, it's quite straightforward. It's probably falling back to the VESA mode.

The most promising fix is to purge the drivers and do a simple reboot.

 

  sudo apt-get remove --purge xorg-driver-fglrx fglrx*

 

Then reboot.

 

That should remove all the drivers and the kernel should hook in with a probed driver, just like a boot from USB or CD would.

 

 

http://www.edugeek.net/forums/general-chat/149837-what-did-you-learn-today-5.html#post1339613

 

 

For further documentation on the graphics system, I found this very helpful.

https://wiki.ubuntu.com/X/Troubleshooting/VideoDriverDetection?action=show&redirect=X%2FTroubleshooting%2FFglrxInteferesWithRadeonDriver

Edited by jinnantonnixx
Posted

Started from scratch with a clean install of 14.04LTS. Still couldn't get this to work. Tried mjk's suggestion as well.

 

It logs into the domain fine, but just cannot get it to mount the home folder on the server. Very frustrating!

@Geoff, how do I go about downgrading the security method to ntlmv2?

 

Thanks all for your help, it is very much appreciated.

Posted

Only gone and got it working!!!!!! :D :D :D :D

 

Noticed a mistake in the pam_mount.conf.xml file, which I copied from the DevOps site, the "" were formatted versions. Corrected that and we're in!

 

Thanks so much for all your help Geoff.

 

Unfortunately I'm not done there though!! My users are in different containers on the server, for example admin are in a "SystemAdminWork" share, teachers in a 'TeacherWork' share and students in a "StudentWork' share. Is there any way of accounting for this?

 

Thanks again for all your help.

Posted

Tried this in the pam_mount.conf.xml but it doesn't seem to work:

 

path="RMStudentWork\Year 7" mountpoint="/home/local/BROOKVALE"
options="sec=krb5,user=%(DOMAIN_USER)@%(DOMAIN_NAME),uid=%(USERUID),gid=%(USERGID),cruid=%(USERUID),nodev,nosuid,file_mode=0700,dir_mode=0700">



path="RMSysAdminWork" mountpoint="/home/local/BROOKVALE"
options="sec=krb5,user=%(DOMAIN_USER)@%(DOMAIN_NAME),uid=%(USERUID),gid=%(USERGID),cruid=%(USERUID),nodev,nosuid,file_mode=0700,dir_mode=0700">









Posted

That's what I have tried to do if you see the above.

 

The admin accounts are working fine, as is the Shared Documents folder which everyone should have. However, if I try and log on as a user in the group 'year 7' which should be a student user, it still tries to map it to the RMAdminWork share, which should only go to admin users. This obviously doesn't work as students don't get permission to access this share, but it shouldn't even try. What am I doing wrong? Am I doing the group names correctly?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...