# Failed to map user PAM authentication

**URL:** <https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021>\
**Category:** Get Help\
**Tags:** ondemand2\
**Created:** [April 22, 2022, 7:15pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021 "2022-04-22T19:15:48Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![kgross](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/kgross/32/137_2.png) [@kgross](https://discourse.openondemand.org/u/kgross)\
**Post date:** [April 22, 2022, 7:15pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021/1 "2022-04-22T19:15:48Z")

</div>

Hi All, I’m in the middle of a new installation and have just configured our system for PAM authentication. I’m able to get to the login screen and enter a user’s credentials just username and password (no email). Then I get the following that others have seen.

"Error – failed to map user (nortech)

I’ve been doing some reading on the forms and it appears that many others have run across this issue and most have ended up using a different type of authentication procedure to get around the issue. I don’t have LDAP or any other authentication going on so I’m wondering what is the best way to proceed? Should I look at dex or something else or should I continue to try to setup PAM? Really just looking for guidance.

Currently my /var/log/httpd/error.log and access.log are empty. Thanks in advance, Kyle

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [April 22, 2022, 8:02pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021/2 "2022-04-22T20:02:25Z")

</div>

> [@kgross](#):
>
> Should I look at dex or something else or should I continue to try to setup PAM? Really just looking for guidance.

If you have an LDAP dex is a very good option. I would not consider PAM as it’s very insecure. Dex (open id connect) is much more secure.

As to the actual failure you’re seeing - `nortech` doesn’t seem to be a system user. Is that a real user? Does `id nortech` return anything?

---

<div class="post-metadata">

**Author:** ![kgross](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/kgross/32/137_2.png) [@kgross](https://discourse.openondemand.org/u/kgross)\
**Post date:** [April 25, 2022, 4:03pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021/3 "2022-04-25T16:03:30Z")

</div>

If we don’t have LDAP in the picture and we are just serving a couple users what would you suggest?

I can SSH in as the nortech user without issue.  
$ id nortech  
uid=1000(nortech) gid=1000(nortech) groups=1000(nortech)

Thanks

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [April 25, 2022, 4:38pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021/4 "2022-04-25T16:38:07Z")

</div>

What version of ondemand are you running? We may have _just_ patched an issue you’re running into in 2.0.23.

Also though - let’s see what your `ood_portal.yml` looks like (you can remove any secrets). Specifically I’m looking for `user_map_match` or `user_map_cmd`.

> [@kgross](#):
>
> we are just serving a couple users what would you suggest?

Depends on your tolerance for risk. The _only_ issue here is how secure do you need to be? Basic apache auth is passing your credentials in the header of every request in plain text. But if you’re not worried about folks seeing that network traffic, then that’s your call.

---

<div class="post-metadata">

**Author:** ![kgross](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/kgross/32/137_2.png) [@kgross](https://discourse.openondemand.org/u/kgross)\
**Post date:** [April 27, 2022, 2:15pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021/5 "2022-04-27T14:15:09Z")

</div>

I would say in this particular environment we aren’t concerned with the security issue. In other instances in the future we’ll probably have to introduce LDAP.

## This is currently all I have in the ood\_portal.yml. Thanks much, Kyle

auth:

- ‘AuthType Basic’
- ‘AuthName “Open OnDemand”’
- ‘AuthBasicProvider PAM’
- ‘AuthPAMService ood’
- ‘Require valid-user’  
user\_map\_cmd: “/opt/ood/ood\_auth\_map/bin/ood\_auth\_map.regex”

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [April 27, 2022, 3:05pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021/6 "2022-04-27T15:05:59Z")

</div>

> [@kgross](#):
>
> user\_map\_cmd: “/opt/ood/ood\_auth\_map/bin/ood\_auth\_map.regex”

Got it. I’ll be this is the issue. We don’t ship this file in 2.0 anymore. You can comment that configuration and your issue should resolve. The default `user_map_match` should work out of the box for you.

---

<div class="post-metadata">

**Author:** ![kgross](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/kgross/32/137_2.png) [@kgross](https://discourse.openondemand.org/u/kgross)\
**Post date:** [April 27, 2022, 4:35pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021/7 "2022-04-27T16:35:28Z")

</div>

Jeff, Beautiful! That did the trick. I appreciate the help, Kyle

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [October 24, 2022, 4:35pm UTC](https://discourse.openondemand.org/t/failed-to-map-user-pam-authentication/2021/8 "2022-10-24T16:35:52Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
