No longer able to authenticate via PAM

I’m no longer able to login as root via the ciphermail web portal. I’m not sure what happened or how to debug but suddenly I can’t login. It was working fine initially. I’m using Red Hat packages for 5.0.4.

Jul 16 20:52:59 cmx01 ciphermail-gateway-backend[2991]: 16 Jul 2021 20:52:59 | WARN [Admin Login] Authentication failure: Bad credentials, Source: org.springframework.security.authentication.UsernamePasswordAuthenticationToken(a)1f: Principal: sa; Credentials: [PROTECTED]; Authenticated: false; Details: org.springframework.security.web.authentication.WebAuthenticationDetails(a)0: RemoteIpAddress: 10.10.10.2; SessionId: EB6F7486DC93FC9513F7AB0836D3158D; Not granted any authorities (mitm.common.event.EventLoggerImpl) [defaultEventExecutorGroup-4-2]
Jul 16 20:52:59 cmx01 ciphermail-gateway-backend[2991]: 16 Jul 2021 20:52:59 | INFO Certificate request handler thread started. (mitm.common.security.ca.CAImpl) [Certificate request handler thread]

Is there a way I can add a user to the db just so I’m able to login?

Thanks
-jeremy

You mention login with root but the log shows that you try to login
with user "sa". Was that a typo?

You should be able to login with PAM if and only if the user is root or
the user is a member of the wheel or sudo group.

Kind regards,

Martijn Brinkers

···

On Sat, 2021-07-17 at 00:12 -0400, Jeremy Hansen via Users wrote:

I’m no longer able to login as root via the ciphermail web
portal. I’m not sure what happened or how to debug but suddenly I
can’t login. It was working fine initially. I’m using Red Hat
packages for 5.0.4.

Jul 16 20:52:59 cmx01 ciphermail-gateway-backend[2991]: 16 Jul 2021
20:52:59 | WARN [Admin Login] Authentication failure: Bad
credentials, Source:
org.springframework.security.authentication.UsernamePasswordAuthenticationToken(a)1f
: Principal: sa; Credentials: [PROTECTED]; Authenticated: false;
Details:
org.springframework.security.web.authentication.WebAuthenticationDetails(a)0
: RemoteIpAddress: 10.10.10.2; SessionId:
EB6F7486DC93FC9513F7AB0836D3158D; Not granted any
authorities (mitm.common.event.EventLoggerImpl)
[defaultEventExecutorGroup-4-2]
Jul 16 20:52:59 cmx01 ciphermail-gateway-backend[2991]: 16 Jul 2021
20:52:59 | INFO Certificate request handler thread
started. (mitm.common.security.ca.CAImpl) [Certificate request
handler thread]

Is there a way I can add a user to the db just so I’m able to login?

Thanks
-jeremy

--
CipherMail email encryption
Email encryption with support for S/MIME,
OpenPGP, PDF Messenger and Webmail Messenger

Thanks for the reply. I was looking at old docs that mentioned sa/sa as a default user.

For some reason this issue cleared up. I don’t know what I was doing wrong but I’m able to log in consistently now.

Thanks!

···

On Jul 19, 2021, at 8:21 AM, Martijn Brinkers via Users <users(a)lists.ciphermail.com> wrote:

You mention login with root but the log shows that you try to login
with user "sa". Was that a typo?

You should be able to login with PAM if and only if the user is root or
the user is a member of the wheel or sudo group.

Kind regards,

Martijn Brinkers

On Sat, 2021-07-17 at 00:12 -0400, Jeremy Hansen via Users wrote:
I’m no longer able to login as root via the ciphermail web
portal. I’m not sure what happened or how to debug but suddenly I
can’t login. It was working fine initially. I’m using Red Hat
packages for 5.0.4.

Jul 16 20:52:59 cmx01 ciphermail-gateway-backend[2991]: 16 Jul 2021
20:52:59 | WARN [Admin Login] Authentication failure: Bad
credentials, Source:
org.springframework.security.authentication.UsernamePasswordAuthenticationToken(a)1f
: Principal: sa; Credentials: [PROTECTED]; Authenticated: false;
Details:
org.springframework.security.web.authentication.WebAuthenticationDetails(a)0
: RemoteIpAddress: 10.10.10.2; SessionId:
EB6F7486DC93FC9513F7AB0836D3158D; Not granted any
authorities (mitm.common.event.EventLoggerImpl)
[defaultEventExecutorGroup-4-2]
Jul 16 20:52:59 cmx01 ciphermail-gateway-backend[2991]: 16 Jul 2021
20:52:59 | INFO Certificate request handler thread
started. (mitm.common.security.ca.CAImpl) [Certificate request
handler thread]

Is there a way I can add a user to the db just so I’m able to login?

Thanks
-jeremy

--
CipherMail email encryption
Email encryption with support for S/MIME,
OpenPGP, PDF Messenger and Webmail Messenger