CentrifyDc Express on AIX 7.1. adquery returns good information for IDs, but no one is allowed to login. Here is some of the debug info. The ID trying to login is sstu112. Why are we getting UNKOWN_USER?
# adquery user sstu112
sstu112:x:1619133973:545:Ed Stuart:/home/CORE/sstu112:/bin/sh
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <background> daemon
.main now = Tue May 10 15:51:26 2016, nextPasswordChange: Tue Jun 7 15:12:50 2016, lastKr
b5Renew: Tue May 10 15:13:22 2016, lastCacheCleanup: Tue May 10 15:44:26 2016, lastPrevali
date: Tue May 10 15:13:22 2016, lastChkDatadir: Tue May 10 15:45:56 2016, lastAzmanRefresh
: Tue May 10 15:42:56 2016, lastDnsRefresh: Tue May 10 15:12:51 2016
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <bg:netstate> netwo
rk.state CacheAccess purge
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <bg:chkDatadirFrees
pace> daemon.main Free space left in adclient data dir /var/centrifydc/ is 1228800 Kbytes
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <bg:adntlmlist> dae
mon.ipcclient Starting ageADNtlm...
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <bg:adntlmlist> dae
mon.ipcclient current timestamp: 1462913486 timeout value: 30
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <bg:adntlmlist> dae
mon.ipcclient ADNtlmList size after refresh: 0
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <bg:adntlmlist> dae
mon.ipcclient Finished ageADNtlm.
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <bg:ageBindings> ba
se.adagent Starting ageBindings...
May 10 15:51:26 autaap07 auth|security:debug adclient[12321016]: DEBUG <bg:ageBindings> ba
se.adagent Finished ageBindings
May 10 15:51:27 autaap07 auth|security:err|error sshd[15859818]: warning: /etc/hosts.allow
, line 2: host name/address mismatch: 172.17.0.10 != l44039.core.cpa.state.tx.us
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 ping > daemo
n.ipclient1 executing request 'ping' in thread 1286
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver lrpc client disconnected normally <fd:10>
May 10 15:51:31 autaap07 auth|security:info sshd[15859818]: Address 172.17.0.10 maps to l4
4039.core.cpa.state.tx.us, but this does not map back to the address - POSSIBLE BREAK-IN A
TTEMPT!
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver Accepted new lrpc2 client on <fd:10> with flags 0x00000006
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd -> centrifydc2_getentry user="sstu112"
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd attribute[0] = "id"
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver Accepted new lrpc2 client on <fd:23> with flags 0x00000006
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> daemon.ipcclient2 executing request 'LAMGetEntry' in thread 1800
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> daemon.ipcclient2 Getting attribute value for user 'sstu112', attribute = 'id'
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> base.adagent Find GUID: e17175bf2e922846895ea65c4723eac6 (7)
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> base.objecthelper age 568, expire age 600, cutoff time 0, refresh 5, negative=false, cac
heOps 7
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> base.adagent Find GUID: e17175bf2e922846895ea65c4723eac6 (7)
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> base.objecthelper age 568, expire age 600, cutoff time 0, refresh 5, negative=false, cac
heOps 7
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> daemon.ipcclient2 id=1619133973
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> daemon.ipcclient2 request 'LAMGetEntry' complete
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd value [0] = 1619133973
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd <- centrifydc2_getentry, result=NSS_SUCCESS(1)
May 10 15:51:31 autaap07 auth|security:info sshd[15859818]: Invalid user sstu112 from 172.
17.0.10
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver lrpc client disconnected normally <fd:23>
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver lrpc client disconnected normally <fd:10>
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver Accepted new lrpc2 client on <fd:10> with flags 0x00000006
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd attribute[0] = "id"
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver Accepted new lrpc2 client on <fd:23> with flags 0x00000006
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> daemon.ipcclient2 executing request 'LAMGetEntry' in thread 1800
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> daemon.ipcclient2 Getting attribute value for user 'sstu112', attribute = 'id'
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> base.adagent Find GUID: e17175bf2e922846895ea65c4723eac6 (7)
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> base.objecthelper age 568, expire age 600, cutoff time 0, refresh 5, negative=false, cac
heOps 7
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> base.adagent Find GUID: e17175bf2e922846895ea65c4723eac6 (7)
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> base.objecthelper age 568, expire age 600, cutoff time 0, refresh 5, negative=false, cac
heOps 7
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> daemon.ipcclient2 id=1619133973
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 LAMGetEntry
> daemon.ipcclient2 request 'LAMGetEntry' complete
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd value [0] = 1619133973
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd <- centrifydc2_getentry, result=NSS_SUCCESS(1)
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver lrpc client disconnected normally <fd:23>
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver lrpc client disconnected normally <fd:10>
May 10 15:51:41 autaap07 auth|security:info syslog: ssh: failed login attempt for UNKNOWN_
USER from 172.17.0.10
May 10 15:51:41 autaap07 auth|security:info sshd[15859818]: input_userauth_request: invali
d user sstu112 [preauth]
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver Accepted new lrpc2 client on <fd:10> with flags 0x00000006
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd -> centrifydc2_normalize user="NOUSER"
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver Accepted new lrpc2 client on <fd:23> with flags 0x00000006
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > daemon.ipcclient2 executing request 'PAMGetUnixName' in thread 1800
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > daemon.ipcclient2 Getting unix name of 'NOUSER'
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
8)> client.sshd value [0] = 1619133973
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd <- centrifydc2_getentry, result=NSS_SUCCESS(1)
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver lrpc client disconnected normally <fd:23>
May 10 15:51:31 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver lrpc client disconnected normally <fd:10>
May 10 15:51:41 autaap07 auth|security:info syslog: ssh: failed login attempt for UNKNOWN_
USER from 172.17.0.10
May 10 15:51:41 autaap07 auth|security:info sshd[15859818]: input_userauth_request: invali
d user sstu112 [preauth]
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver Accepted new lrpc2 client on <fd:10> with flags 0x00000006
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:10 sshd(1585981
8)> client.sshd -> centrifydc2_normalize user="NOUSER"
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <main> daemon.ipcse
rver Accepted new lrpc2 client on <fd:23> with flags 0x00000006
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > daemon.ipcclient2 executing request 'PAMGetUnixName' in thread 1800
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > daemon.ipcclient2 Getting unix name of 'NOUSER'
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > adclient.pam.util Creating CimsContext
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > adclient.pam.util username NOUSER, presented: , effective: , unix: unknown
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > base.schema.auto findByUnixName - name:NOUSER category:Person cacheOps:7
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > base.adagent findObject ADNames: NOUSER name: NOUSER type=SAM domain=CORE.CPA.STATE.T
X.US
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > base.bind.cache ADCB::search base , filter (&(objectClass=User)(|(objectCategory=Pers
on)(objectCategory=Computer))(sAMAccountName=NOUSER)), attrs 2 (cacheOps=7, GC=0)
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DIAG <fd:23 PAMGetUnixNa
me > base.bind.ldap 192.168.210.17:389 search base="DC=core,DC=cpa,DC=state,DC=tx,DC=us" f
ilter="(&(objectClass=User)(|(objectCategory=Person)(objectCategory=Computer))(sAMAccountN
ame=NOUSER))"
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > base.bind.cache ADCB::search: refresh list returns 0 objects
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > base.cache Cache store <GUID=0f440ef3b5e94dc79e50e24ecb09ef18>;CN=SearchMark,CN=CENTR
IFY MARKER,DC=CORE,DC=CPA,DC=STATE,DC=TX,DC=US : update indexes Yes
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DEBUG <fd:23 PAMGetUnixNa
me > base.bind.cache ADCB::search base , filter (&(objectClass=User)(|(objectCategory=Pers
on)(objectCategory=Computer))(sAMAccountName=NOUSER)), attrs 1e (cacheOps=7, GC=1)
May 10 15:51:49 autaap07 auth|security:debug adclient[12321016]: DIAG <fd:23 PAMGetUnixNa