# How to set up ybind in Rocky 9.2 , it always fail

**URL:** <https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350>\
**Category:** Rocky Linux Help & Support\
**Created:** [March 27, 2024, 9:24am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350 "2024-03-27T09:24:40Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamescxk](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@jamescxk](https://forums.rockylinux.org/u/jamescxk)\
**Post date:** [March 27, 2024, 9:24am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/1 "2024-03-27T09:24:40Z")

</div>

We are facing upgrade Redhat 6 to Redhat 9. There are many NIS user in Redhat 6, but Redhat 9 doesn’t support NIS .

I saw a post :[Nis on Rocky/RHEL 9](https://forums.rockylinux.org/t/nis-on-rocky-rhel-9/11227) , it says the ypbind tool could be installed in Redhat 9 .

But when i try to install ypbind , it showed the error log like below:

[root@rocky9 ~]# yum install /root/ypbind-2.7.2-8.fc36.x86\_64.rpm  
Last metadata expiration check: 0:00:30 ago on Wed 27 Mar 2024 05:02:23 PM CST.  
Error:  
Problem: conflicting requests

- nothing provides nss\_nis needed by ypbind-3:2.7.2-8.fc36.x86\_64
- nothing provides yp-tools \>= 4.2.2-2 needed by ypbind-3:2.7.2-8.fc36.x86\_64  
(try to add ‘–skip-broken’ to skip uninstallable packages or ‘–nobest’ to use not only best candidate packages)  
[root@rocky9 ~]# yum install /root/yp-tools-4.2.3-12.fc36.x86\_64.rpm  
Last metadata expiration check: 0:00:18 ago on Wed 27 Mar 2024 05:03:11 PM CST.  
Error:  
Problem: conflicting requests
- nothing provides ypbind \>= 3:2.4-2 needed by yp-tools-4.2.3-12.fc36.x86\_64  
(try to add ‘–skip-broken’ to skip uninstallable packages or ‘–nobest’ to use not only best candidate packages)

How to solve this ? Anyone could give me some help?  
Thx in advance.

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [March 27, 2024, 9:46am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/2 "2024-03-27T09:46:40Z")

</div>

EL9 has Identity Management (IdM). There is a section of docs for it in [Product Documentation for Red Hat Enterprise Linux 9 | Red Hat Customer Portal](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9)  
There is a bit about migrating from non-RHEL FreeIPA to RHEL IdM.  
FreeIPA has “migrate from NIS”: [NIS\_accounts\_migration\_preserving\_Passwords — FreeIPA documentation](https://www.freeipa.org/page/NIS_accounts_migration_preserving_Passwords)

Could it be possible to install IdM and migrate NIS accounts to it?

---

<div class="post-metadata">

**Author:** ![james-p](https://avatars.discourse-cdn.com/v4/letter/j/b782af/32.png) [@james-p](https://forums.rockylinux.org/u/james-p)\
**Post date:** [March 27, 2024, 10:09am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/3 "2024-03-27T10:09:56Z")

</div>

You need to install these three packages at the same time:

`dnf install /root/ypbind-2.7.2-8.fc36.x86_64.rpm /root/yp-tools-4.2.3-12.fc36.x86_64.rpm /root/nss_nis-3.1-11.fc36.x86_64.rpm`

---

<div class="post-metadata">

**Author:** ![jamescxk](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@jamescxk](https://forums.rockylinux.org/u/jamescxk)\
**Post date:** [March 28, 2024, 2:52am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/4 "2024-03-28T02:52:39Z")

</div>

Yes, we are considering about this in future.

---

<div class="post-metadata">

**Author:** ![jamescxk](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@jamescxk](https://forums.rockylinux.org/u/jamescxk)\
**Post date:** [March 28, 2024, 2:57am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/5 "2024-03-28T02:57:53Z")

</div>

Thx a lot. It really worked .

The NIS user could login via SHELL tools without any problem, but i try to use the NIS login the desktop, it fails with error:

Mar 28 10:49:06 rocky9 systemd[1]: Started Fingerprint Authentication Daemon.  
Mar 28 10:49:23 rocky9 /usr/libexec/gdm-wayland-session[40111]: dbus-daemon[40111]: [session uid=501 pid=40111] Activating service name=‘org.freedesktop.systemd1’ requested by ‘:1.0’ (uid=501 pid=40109 comm=“/usr/libexec/gdm-wayland-session --register-sessio” label=“kernel”)  
Mar 28 10:49:23 rocky9 /usr/libexec/gdm-wayland-session[40111]: dbus-daemon[40111]: [session uid=501 pid=40111] Activated service ‘org.freedesktop.systemd1’ failed: Process org.freedesktop.systemd1 exited with status 1  
Mar 28 10:49:23 rocky9 /usr/libexec/gdm-wayland-session[40109]: Unable to register display with display manager  
Mar 28 10:49:23 rocky9 gdm[872]: Gdm: GdmDisplay: Session never registered, failing  
Mar 28 10:49:23 rocky9 journal[38637]: unable to get EDID for xrandr-Virtual-1: unable to get EDID for output  
Mar 28 10:49:23 rocky9 journal[38637]: unable to get EDID for xrandr-Virtual-1: unable to get EDID for output  
Mar 28 10:49:23 rocky9 journal[38637]: unable to get EDID for xrandr-Virtual-1: unable to get EDID for output  
Mar 28 10:49:23 rocky9 org.gnome.Shell.desktop[40135]: The XKEYBOARD keymap compiler (xkbcomp) reports:  
Mar 28 10:49:23 rocky9 org.gnome.Shell.desktop[40135]: \> Warning: Unsupported maximum keycode 708, clipping.  
Mar 28 10:49:23 rocky9 org.gnome.Shell.desktop[40135]: \> X11 cannot support keycodes above 255.  
Mar 28 10:49:23 rocky9 org.gnome.Shell.desktop[40135]: Errors from xkbcomp are not fatal to the X server

Have you got this issue in Rocky desktop login ?

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [March 28, 2024, 7:30am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/6 "2024-03-28T07:30:31Z")

</div>

> [@jamescxk](#):
>
> The NIS user could login via SHELL tools without any problem, but i try to use the NIS login the desktop, it fails

First, that is a separate issue than the OP “how to install packages from files” that is already _resolved_. So should be on new thread for clarity.

* * *

I would test two things:

1. Can non-NIS accounts log in, i.e. is this only for NIS-accounts
2. Use Gnome, rather than Wayland. (There is a cog-wheel on right bottom corner where you can select type of session, when you have given/selected username and about to type password.)

---

<div class="post-metadata">

**Author:** ![jamescxk](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@jamescxk](https://forums.rockylinux.org/u/jamescxk)\
**Post date:** [March 28, 2024, 11:45pm UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/7 "2024-03-28T23:45:17Z")

</div>

Only non-NIS accounts could log in. NIS account after type password , it returned to the login screen .

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [March 29, 2024, 5:59am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/8 "2024-03-29T05:59:02Z")

</div>

The real solution is to move on from NIS to a more modern authentication and authorization stack. NIS has serious limitations and security issues. Consider moving to FreeIPA. Or, if you don’t want all of what it comes with, openldap-server (from epel and the plus repo we provide) or 389-ds-base all by itself.

---

<div class="post-metadata">

**Author:** ![jamescxk](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@jamescxk](https://forums.rockylinux.org/u/jamescxk)\
**Post date:** [March 29, 2024, 7:18am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/9 "2024-03-29T07:18:58Z")

</div>

ok. Thank you for your kindly suggestion.

---

<div class="post-metadata">

**Author:** ![limbooface](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@limbooface](https://forums.rockylinux.org/u/limbooface)\
**Post date:** [March 29, 2024, 7:38am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/10 "2024-03-29T07:38:04Z")

</div>

You could also look at zentyal that way you get support as well. I use it for authentication on my rocky 8.8 and 9.3 systems and now it also supports automounts. Works for Linux and windows clients .

---

<div class="post-metadata">

**Author:** ![james-p](https://avatars.discourse-cdn.com/v4/letter/j/b782af/32.png) [@james-p](https://forums.rockylinux.org/u/james-p)\
**Post date:** [April 2, 2024, 10:50am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/11 "2024-04-02T10:50:26Z")

</div>

When you say a ‘NIS user could login via SHELL tools’ - what exactly do you mean? (i.e. what are the ‘SHELL’ tools ?)

When NIS users log in this way, are they prompted for a password ?

What is the ‘passwd’ entry in /etc/nsswitch.conf ?

---

<div class="post-metadata">

**Author:** ![jamescxk](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@jamescxk](https://forums.rockylinux.org/u/jamescxk)\
**Post date:** [April 3, 2024, 12:52am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/12 "2024-04-03T00:52:48Z")

</div>

Thx for your reply. I mean NIS user could use the linux terminal like MobaXterm using ssh connection , they could execute the linux command without any problem , but when they try to use the graphical Desktop , it fails.

They login with Redhat 9 logon screen, they type user and password, then nothing happened. It returns to the logon screen again. The detail log i have post above.

The ‘passwd’ entry in /etc/nsswitch.conf :  
passwd: files nis  
group: files nis  
netgroup: files nis sss  
automount: files nis sss  
services: sss files

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [April 3, 2024, 7:03am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/13 "2024-04-03T07:03:00Z")

</div>

The nsswitch.conf tells _where_ to look for passwords (and other user info) from. The files in /etc/pam.d/ tell _when_ passwords are looked for, and sshd and gdm do probably have a bit different requirements.

The `journalctl` shows system logs, but there are probably still a partial copy in files `/var/log/messages` and `/var/log/secure` too. The logs might show whether issue is with password, or with creation of user session.

---

<div class="post-metadata">

**Author:** ![james-p](https://avatars.discourse-cdn.com/v4/letter/j/b782af/32.png) [@james-p](https://forums.rockylinux.org/u/james-p)\
**Post date:** [April 3, 2024, 10:40am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/14 "2024-04-03T10:40:37Z")

</div>

When using MobaXterm, are NIS users prompted for their password ? - or do you use ssh keys etc ?

i.e. if using ssh keys, then no password authentication will be done - whereas the graphical login will require password authentication - which may mean you will have to make changes in your PAM config files ?

I haven’t used NIS for authentication for years (and never with Rocky 9) - so not sure what you will need to change to get it working …

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [June 2, 2024, 10:41am UTC](https://forums.rockylinux.org/t/how-to-set-up-ybind-in-rocky-9-2-it-always-fail/13350/15 "2024-06-02T10:41:04Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
