Discussion:
[Ltsp-discuss] Patching /usr/share/ldm/rc.d/X01-localapps gives unanticipated results
David Groos
2016-09-01 02:54:53 UTC
Permalink
Hi Folks,

-- I'm using ltsp-pnp Ubuntu 16.01.
-- Just joined the server to the district AD server Using Open PowerBroker
(formerly Likewise Open--been doing this since 2010)
-- can no longer log into clients with local clients either.

To begin to address this problem I patched /usr/share/ldm/rc.d/X01-localapps
using the patch from here https://bugs.launchpad.net/ltsp/+bug/1610304.
<https://bugs.launchpad.net/ltsp/+bug/1610304>

There seem to be 2 unintended consequences:

1. When I log in on the server (via regular gui) I get Image shown here:
https://imagebin.ca/v/2tWrqAQ2Ee2y. After entering the password it says
"Access denied" twice and doesn't log in. But, when I then click into the
"log In" box, it logs me in!
2. When sitting at the server or remotely sshed into the server, I try
to "sudo ltsp-update-image --cleanup / "and it just hangs. When I Control +
C, I get the following error message: ^Crmdir: failed to remove
'/tmp/tmp.6nLBVnjB0z': No such file or directory.

Any ideas?

Thanks,
David G

https://imagebin.ca/v/2tWrqAQ2Ee2y

*Here's auth.log results from trying to log log into server via splash page
(and more)*
Aug31 19:17:20 south-sci-1 systemd-logind[2302]: New seat seat0.
Aug 31 19:17:20 south-sci-1 systemd-logind[2302]: Watching system buttons
on /dev/input/event1 (Power Button)
Aug 31 19:17:20 south-sci-1 systemd-logind[2302]: Watching system buttons
on /dev/input/event0 (Power Button)
Aug 31 19:17:20 south-sci-1 systemd-logind[2302]: Watching system buttons
on /dev/input/event10 (HP WMI hotkeys)
Aug 31 19:17:20 south-sci-1 systemd-logind[2302]: Watching system buttons
on /dev/input/event10 (HP WMI hotkeys)
Aug 31 19:17:20 south-sci-1 sshd[2445]: Server listening on 0.0.0.0 port 22.
Aug 31 19:17:20 south-sci-1 sshd[2445]: Server listening on :: port 22.
Aug 31 19:17:20 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet.so):
/lib/security/pam_kwallet.so: cannot open shared object file: No such file
or directory
Aug 31 19:17:20 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet.so
Aug 31 19:17:20 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet5.so):
/lib/security/pam_kwallet5.so: cannot open shared object file: No such file
or directory
Aug 31 19:17:20 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet5.so
Aug 31 19:17:20 south-sci-1 lightdm: [lsass-pam]
[module:pam_lsass]pam_sm_open_session failed [login:lightdm][error code: 2]
Aug 31 19:17:20 south-sci-1 lightdm: pam_unix(lightdm-greeter:session):
session opened for user lightdm by (uid=0)
Aug 31 19:17:20 south-sci-1 systemd: [lsass-pam]
[module:pam_lsass]pam_sm_acct_mgmt failed [login:lightdm][error code:2]
Aug 31 19:17:20 south-sci-1 systemd: [lsass-pam]
[module:pam_lsass]pam_sm_acct_mgmt failed [login:lightdm][error code:2]
Aug 31 19:17:20 south-sci-1 systemd: [lsass-pam]
[module:pam_lsass]pam_sm_open_session failed [login:lightdm][error code: 2]
Aug 31 19:17:20 south-sci-1 systemd: pam_unix(systemd-user:session):
session opened for user lightdm by (uid=0)
Aug 31 19:17:20 south-sci-1 systemd-logind[2302]: New session c1 of user
lightdm.
Aug 31 19:17:20 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet.so):
/lib/security/pam_kwallet.so: cannot open shared object file: No such file
or directory
Aug 31 19:17:20 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet.so
Aug 31 19:17:20 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet5.so):
/lib/security/pam_kwallet5.so: cannot open shared object file: No such file
or directory
Aug 31 19:17:20 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet5.so
Aug 31 19:17:20 south-sci-1 lightdm: pam_succeed_if(lightdm:auth):
requirement "user ingroup nopasswdlogin" not met by user "dgroos"
Aug 31 19:17:23 south-sci-1 sshd[2445]: Received SIGHUP; restarting.
Aug 31 19:17:23 south-sci-1 sshd[2445]: Server listening on 0.0.0.0 port 22.
Aug 31 19:17:23 south-sci-1 sshd[2445]: Server listening on :: port 22.
Aug 31 19:17:23 south-sci-1 sshd[2445]: Received SIGHUP; restarting.
Aug 31 19:17:23 south-sci-1 sshd[2445]: Server listening on 0.0.0.0 port 22.
Aug 31 19:17:23 south-sci-1 sshd[2445]: Server listening on :: port 22.
Aug 31 19:17:29 south-sci-1 sshd[2445]: Received SIGHUP; restarting.
Aug 31 19:17:29 south-sci-1 sshd[2445]: Server listening on 0.0.0.0 port 22.
Aug 31 19:17:29 south-sci-1 sshd[2445]: Server listening on :: port 22.
Aug 31 19:17:29 south-sci-1 sshd[2445]: Received SIGHUP; restarting.
Aug 31 19:17:29 south-sci-1 sshd[2445]: Server listening on 0.0.0.0 port 22.
Aug 31 19:17:29 south-sci-1 sshd[2445]: Server listening on :: port 22.
Aug 31 19:17:34 south-sci-1 lightdm: [lsass-pam] [module:pam_lsass]User
dgroos is denied access because they are not in the 'require membership of'
list
Aug 31 19:17:34 south-sci-1 lightdm: [lsass-pam] [module:pam_lsass]User
dgroos is denied access because they are not in the 'require membership of'
list
Aug 31 19:17:45 south-sci-1 dbus[2271]: [system] Failed to activate service
'org.bluez': timed out
Aug 31 19:18:05 south-sci-1 lightdm: pam_unix(lightdm-greeter:session):
session closed for user lightdm
Aug 31 19:18:05 south-sci-1 lightdm: pam_unix(lightdm:session): session
opened for user dgroos by (uid=0)
Aug 31 19:18:05 south-sci-1 systemd-logind[2302]: New session c2 of user
dgroos.
Aug 31 19:18:05 south-sci-1 systemd: pam_unix(systemd-user:session):
session opened for user dgroos by (uid=0)
Aug 31 19:18:06 south-sci-1 gnome-keyring-daemon[3740]: The PKCS#11
component was already initialized
Aug 31 19:18:06 south-sci-1 gnome-keyring-daemon[3740]: The SSH agent was
already initialized
Aug 31 19:18:06 south-sci-1 gnome-keyring-daemon[3740]: The Secret Service
was already initialized
Aug 31 19:18:07 south-sci-1 polkitd(authority=local): Registered
Authentication Agent for unix-session:c2 (system bus name :1.75
[/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object
path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
Aug 31 19:18:17 south-sci-1 polkitd(authority=local): Unregistered
Authentication Agent for unix-session:c2 (system bus name :1.75, object
path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
(disconnected from bus)
Aug 31 19:18:18 south-sci-1 lightdm: pam_unix(lightdm:session): session
closed for user dgroos
Aug 31 19:18:18 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet.so):
/lib/security/pam_kwallet.so: cannot open shared object file: No such file
or directory
Aug 31 19:18:18 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet.so
Aug 31 19:18:18 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet5.so):
/lib/security/pam_kwallet5.so: cannot open shared object file: No such file
or directory
Aug 31 19:18:18 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet5.so
Aug 31 19:18:18 south-sci-1 lightdm: pam_unix(lightdm-greeter:session):
session opened for user lightdm by (uid=0)
Aug 31 19:18:18 south-sci-1 systemd-logind[2302]: New session c3 of user
lightdm.
Aug 31 19:18:18 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet.so):
/lib/security/pam_kwallet.so: cannot open shared object file: No such file
or directory
Aug 31 19:18:18 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet.so
Aug 31 19:18:18 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet5.so):
/lib/security/pam_kwallet5.so: cannot open shared object file: No such file
or directory
Aug 31 19:18:18 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet5.so
Aug 31 19:18:18 south-sci-1 lightdm: pam_succeed_if(lightdm:auth):
requirement "user ingroup nopasswdlogin" not met by user "dgroos"
Aug 31 19:18:29 south-sci-1 lightdm: pam_unix(lightdm-greeter:session):
session closed for user lightdm
Aug 31 19:18:29 south-sci-1 lightdm: pam_unix(lightdm:session): session
opened for user dgroos by (uid=0)
Aug 31 19:18:29 south-sci-1 systemd-logind[2302]: New session c4 of user
dgroos.
Aug 31 19:18:30 south-sci-1 gnome-keyring-daemon[4615]: The PKCS#11
component was already initialized
Aug 31 19:18:30 south-sci-1 gnome-keyring-daemon[4615]: The Secret Service
was already initialized
Aug 31 19:18:30 south-sci-1 gnome-keyring-daemon[4615]: The SSH agent was
already initialized
Aug 31 19:18:31 south-sci-1 polkitd(authority=local): Registered
Authentication Agent for unix-session:c4 (system bus name :1.130
[/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object
path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
Aug 31 19:18:31 south-sci-1 dbus[2271]: [system] Failed to activate service
'org.bluez': timed out
Aug 31 19:18:37 south-sci-1 polkitd(authority=local): Unregistered
Authentication Agent for unix-session:c4 (system bus name :1.130, object
path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
(disconnected from bus)
Aug 31 19:18:38 south-sci-1 lightdm: pam_unix(lightdm:session): session
closed for user dgroos
Aug 31 19:18:38 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet.so):
/lib/security/pam_kwallet.so: cannot open shared object file: No such file
or directory
Aug 31 19:18:38 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet.so
Aug 31 19:18:38 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet5.so):
/lib/security/pam_kwallet5.so: cannot open shared object file: No such file
or directory
Aug 31 19:18:38 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet5.so
Aug 31 19:18:38 south-sci-1 lightdm: pam_unix(lightdm-greeter:session):
session opened for user lightdm by (uid=0)
Aug 31 19:18:38 south-sci-1 systemd-logind[2302]: New session c5 of user
lightdm.
Aug 31 19:18:38 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet.so):
/lib/security/pam_kwallet.so: cannot open shared object file: No such file
or directory
Aug 31 19:18:38 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet.so
Aug 31 19:18:38 south-sci-1 lightdm: PAM unable to dlopen(pam_kwallet5.so):
/lib/security/pam_kwallet5.so: cannot open shared object file: No such file
or directory
Aug 31 19:18:38 south-sci-1 lightdm: PAM adding faulty module:
pam_kwallet5.so
Aug 31 19:18:38 south-sci-1 lightdm: pam_succeed_if(lightdm:auth):
requirement "user ingroup nopasswdlogin" not met by user "dgroos"
Alkis Georgopoulos
2016-09-01 04:29:27 UTC
Permalink
Hi David,

Both (1) and (2) are completely unrelated to the X01-localapps patch.
X01-localapps never gets executed on the server, neither on login nor
when ltsp-update-image runs, so its contents cannot cause the issues
you're mentioning. Look elsewhere.

Cheers,
Alkis
Post by David Groos
Hi Folks,
-- I'm using ltsp-pnp Ubuntu 16.01.
-- Just joined the server to the district AD server Using Open
PowerBroker (formerly Likewise Open--been doing this since 2010)
-- can no longer log into clients with local clients either.
To begin to address this problem I patched
/usr/share/ldm/rc.d/X01-localapps using the patch from here
https://bugs.launchpad.net/ltsp/+bug/1610304.
<https://bugs.launchpad.net/ltsp/+bug/1610304>
1. When I log in on the server (via regular gui) I get Image shown
here: https://imagebin.ca/v/2tWrqAQ2Ee2y. After entering the
password it says "Access denied" twice and doesn't log in. But, when
I then click into the "log In" box, it logs me in!
2. When sitting at the server or remotely sshed into the server, I try
to "sudo ltsp-update-image --cleanup / "and it just hangs. When I
Control + C, I get the following error message: ^Crmdir: failed to
remove '/tmp/tmp.6nLBVnjB0z': No such file or directory.
Any ideas?
Thanks,
David G
David
2016-09-01 04:37:25 UTC
Permalink
That's very helpful to know, thanks Alkis! 
David


Sent from my T-Mobile 4G LTE Device

<div>-------- Original message --------</div><div>From: Alkis Georgopoulos <***@gmail.com> </div><div>Date:08/31/2016 11:29 PM (GMT-06:00) </div><div>To: ltsp-***@lists.sourceforge.net </div><div>Subject: Re: [Ltsp-discuss] Patching /usr/share/ldm/rc.d/X01-localapps gives unanticipated results </div><div>
</div>Hi David,

Both (1) and (2) are completely unrelated to the X01-localapps patch.
X01-localapps never gets executed on the server, neither on login nor
when ltsp-update-image runs, so its contents cannot cause the issues
you're mentioning. Look elsewhere.

Cheers,
Alkis
Post by David Groos
Hi Folks,
-- I'm using ltsp-pnp Ubuntu 16.01.
-- Just joined the server to the district  AD server Using Open
PowerBroker (formerly Likewise Open--been doing this since 2010)
-- can no longer log into clients with local clients either.
To begin to address this problem I patched
/usr/share/ldm/rc.d/X01-localapps using the patch from here
https://bugs.launchpad.net/ltsp/+bug/1610304.
<https://bugs.launchpad.net/ltsp/+bug/1610304>
  1. When I log in on the server (via regular gui) I get Image shown
     here: https://imagebin.ca/v/2tWrqAQ2Ee2y. After entering the
     password it says "Access denied" twice and doesn't log in. But, when
     I then click into the "log In" box, it logs me in!
  2. When sitting  at the server or remotely sshed into the server, I try
     to "sudo ltsp-update-image --cleanup / "and it just hangs. When I
     Control + C, I get the following error message: ^Crmdir: failed to
     remove '/tmp/tmp.6nLBVnjB0z': No such file or directory.
Any ideas?
Thanks,
David G
Rodolphe SEGBEDJI
2016-09-07 09:18:07 UTC
Permalink
hello LTSP's family..

I'd like to know how to harden a LTSP server..

thanks..
Post by David
That's very helpful to know, thanks Alkis!
David
Sent from my T-Mobile 4G LTE Device
<div>-------- Original message --------</div><div>From: Alkis Georgopoulos
[Ltsp-discuss] Patching /usr/share/ldm/rc.d/X01-localapps gives
unanticipated results </div><div>
</div>Hi David,
Both (1) and (2) are completely unrelated to the X01-localapps patch.
X01-localapps never gets executed on the server, neither on login nor
when ltsp-update-image runs, so its contents cannot cause the issues
you're mentioning. Look elsewhere.
Cheers,
Alkis
Post by David Groos
Hi Folks,
-- I'm using ltsp-pnp Ubuntu 16.01.
-- Just joined the server to the district  AD server Using Open
PowerBroker (formerly Likewise Open--been doing this since 2010)
-- can no longer log into clients with local clients either.
To begin to address this problem I patched
/usr/share/ldm/rc.d/X01-localapps using the patch from here
https://bugs.launchpad.net/ltsp/+bug/1610304.
<https://bugs.launchpad.net/ltsp/+bug/1610304>
  1. When I log in on the server (via regular gui) I get Image shown
     here: https://imagebin.ca/v/2tWrqAQ2Ee2y. After entering the
     password it says "Access denied" twice and doesn't log in. But, when
     I then click into the "log In" box, it logs me in!
  2. When sitting  at the server or remotely sshed into the server, I try
     to "sudo ltsp-update-image --cleanup / "and it just hangs. When I
     Control + C, I get the following error message: ^Crmdir: failed to
     remove '/tmp/tmp.6nLBVnjB0z': No such file or directory.
Any ideas?
Thanks,
David G
------------------------------------------------------------------------------
_____________________________________________________________________
      https://lists.sourceforge.net/lists/listinfo/ltsp-discuss
For additional LTSP help,   try #ltsp channel on irc.freenode.net
Loading...