your file snippets look ok. You also need to edit the /etc/pam.d/ files. Try: $ cat common-account account [success=1 default=ignore] pam_unix.so account required pam_ldap.so use_first_pass account required pam_permit.so
$ cat common-session session [success=1 default=ignore] pam_unix.so session sufficient pam_ldap.so try_first_pass session required pam_permit.so $ cat common-auth auth [success=1 default=ignore] pam_ldap.so auth required pam_unix.so try_first_pass auth required pam_permit.so $ cat common-password password sufficient pam_ldap.so password required pam_unix.so nullok obscure min=4 max=8 md5 try_first_pass -- Geoff Crompton Debian System Administrator Strategic Data +61 3 9340 9000 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]