# PAM user mapping

**URL:** <https://discourse.openondemand.org/t/pam-user-mapping/1915>\
**Category:** Get Help\
**Tags:** question\
**Created:** [February 14, 2022, 3:36pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915 "2022-02-14T15:36:14Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![equiros-sfwmd](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/equiros-sfwmd/32/979_2.png) [@equiros-sfwmd](https://discourse.openondemand.org/u/equiros-sfwmd)\
**Post date:** [February 14, 2022, 3:36pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/1 "2022-02-14T15:36:14Z")

</div>

Trying to use the Open OnDemand PAM instructions here…  
[PAM Authentication](https://osc.github.io/ood-documentation/latest/authentication/pam.html)

I get the famous error message:  
**Error – failed to map user (testuser1)**

In the docs it has a reference to a regex user map.  
_ **/opt/ood/ood\_auth\_map/bin/ood\_auth\_map.regex** _

I’m looking at the docs for user mapping:  
[Setup User Mapping](https://osc.github.io/ood-documentation/latest/authentication/overview/map-user.html)

---

<div class="post-metadata">

**Author:** ![equiros-sfwmd](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/equiros-sfwmd/32/979_2.png) [@equiros-sfwmd](https://discourse.openondemand.org/u/equiros-sfwmd)\
**Post date:** [February 14, 2022, 4:34pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/3 "2022-02-14T16:34:10Z")

</div>

Still getting the **failed to map user** error  
I don’t really understand the user mapping.

I added the PAM configuration to the portal config

```auto
auth:
  - 'AuthType Basic'
  - 'AuthName "Open OnDemand"'
  - 'AuthBasicProvider PAM'
  - 'AuthPAMService ood'
  - 'Require valid-user'
# Capture system user name from authenticated user name
user_map_cmd: "/opt/ood/ood_auth_map/bin/ood_auth_map.regex"

```

I created the executable regex at

`/opt/ood/ood_auth_map/bin/ood_auth_map.regex`

With this content:

```auto
#!/bin/bash

REX="([^@]+)@localhost"
INPUT_USER="$1"

if [[$INPUT_USER =~ $REX]]; then
  MATCH="${BASH_REMATCH[1]}"
  echo "$MATCH" | tr '[:upper:]' '[:lower:]'
else
  # can't write to standard out or error, so let's use syslog
  logger -t 'ood-mapping' "cannot map $INPUT_USER"

  # and exit 1
  exit 1
fi

```

I am trying to use PAM as the authentication for OnDemand.

Could I just have a simple list of key-value pairs for the static user mapping?  
What could I be missing?

---

<div class="post-metadata">

**Author:** ![gbyrket](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/gbyrket/32/894_2.png) [@gbyrket](https://discourse.openondemand.org/u/gbyrket)\
**Post date:** [February 14, 2022, 5:43pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/5 "2022-02-14T17:43:50Z")

</div>

Hi Equiros.

Thanks for posting.

I will look into this.

Thanks,  
-gerald

---

<div class="post-metadata">

**Author:** ![equiros-sfwmd](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/equiros-sfwmd/32/979_2.png) [@equiros-sfwmd](https://discourse.openondemand.org/u/equiros-sfwmd)\
**Post date:** [February 14, 2022, 6:12pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/6 "2022-02-14T18:12:34Z")

</div>

Thanks Gerald, Sorry about the basic question.  
I just need a simple user list for a proof of concept.  
Thats is why I chose PAM as the authentication.  
These are test users that only exist locally.

I am following the docs for PAM authentication.  
I just have 3 or 4 test users for this environment.

I added the **mod\_authnz\_pam** package,  
and have passwords assigned to all my local users.

I added the PAM config shown above, and  
updated the portal, restarted ondemand-dex and httpd.

I just want a simple user list for this POC.  
How can I do that ?

---

<div class="post-metadata">

**Author:** ![gbyrket](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/gbyrket/32/894_2.png) [@gbyrket](https://discourse.openondemand.org/u/gbyrket)\
**Post date:** [February 14, 2022, 6:23pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/7 "2022-02-14T18:23:39Z")

</div>

It’s no problem. Trust me, the mapping piece is somewhat difficult. I’m working on another issue that was submitted, so I’ll get to yours as soon as I am finished with that one.

Thanks for your patience,  
-gerald

---

<div class="post-metadata">

**Author:** ![gbyrket](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/gbyrket/32/894_2.png) [@gbyrket](https://discourse.openondemand.org/u/gbyrket)\
**Post date:** [February 14, 2022, 6:24pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/8 "2022-02-14T18:24:40Z")

</div>

I’ve never tried using PAM integration, but I have been successful in using Apache Authentication.

---

<div class="post-metadata">

**Author:** ![equiros-sfwmd](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/equiros-sfwmd/32/979_2.png) [@equiros-sfwmd](https://discourse.openondemand.org/u/equiros-sfwmd)\
**Post date:** [February 14, 2022, 6:43pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/9 "2022-02-14T18:43:53Z")

</div>

I’m just trying to work around our lack of identity management for our Linux systems.  
We use AD for most things here. but LOCAL ACCOUNTS for Linux.  
We have started a project to add centralized Linux authentication, but no working system yet.

So, I have this Proof of Concept HPC, with local accounts. That is why I just need PAM.  
It is the simplest to use without adding additional external resources.

I am using the **ood\_auth\_map.regex** shown above. I have test users listed in  
/etc/passwd and in /etc/shadow. I have allowed apache user to read /etc/shadow.

When I login as testuser1@localhost, I simply get redirected back to the login screen,  
as if the password was not accepted. Also the log says that too.

When I login as testuser1 (without the localhost), I get the message  
**Error – failed to map user (testuser1)**  
As if the password was accepted, but the user not mapped.

---

<div class="post-metadata">

**Author:** ![equiros-sfwmd](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/equiros-sfwmd/32/979_2.png) [@equiros-sfwmd](https://discourse.openondemand.org/u/equiros-sfwmd)\
**Post date:** [February 14, 2022, 7:24pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/10 "2022-02-14T19:24:44Z")

</div>

Okay, I got it working with this regex script:

```auto
#!/bin/bash

REX="([^@]+)"
INPUT_USER="$1"

if [[$INPUT_USER =~ $REX]]; then
  MATCH="${BASH_REMATCH[1]}"
  echo "$MATCH" | tr '[:upper:]' '[:lower:]'
else
  # can't write to standard out or error, so let's use syslog
  logger -t 'ood-mapping' "cannot map $INPUT_USER"

  # and exit 1
  exit 1
fi

```

It looked like the regex was ignoring the part after the @, so I removed that part.  
My test users are now able to get to the dashboard. Thanks for your help!

---

<div class="post-metadata">

**Author:** ![gbyrket](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/gbyrket/32/894_2.png) [@gbyrket](https://discourse.openondemand.org/u/gbyrket)\
**Post date:** [February 14, 2022, 9:37pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/11 "2022-02-14T21:37:12Z")

</div>

I just saw your response here. I looked here because I came to the exact same conclusion. Remove the @osc.edu completely.

Thanks man.

Glad it’s working!

-gerald

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [August 13, 2022, 9:38pm UTC](https://discourse.openondemand.org/t/pam-user-mapping/1915/12 "2022-08-13T21:38:13Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
