Sorry to awaken such an old thread, but in case anyone is still having problems with this, I was able to get it working perfectly in my environment. I was experiencing the original issue and I tried the MattPie/Emu solution from posts #20/21, but I was still receiving two password prompts for local users. I ended up taking their suggestions and coming up with this:
I did not have to change anything in /etc/pam.d/gnome-screensaver. Instead, I made the first two lines in /etc/pam.d/common-auth file read as follows: auth [success=2 default=ignore] pam_ldap.so auth [success=1 default=ignore] pam_unix.so nullok_secure use_first_pass Using this configuration, both local users and ldap users can log into the desktop AND unlock the screensaver by entering their password only once. I cannot speak to how well this works with an encrypted ldap setup. -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to gnome-screensaver in Ubuntu. https://bugs.launchpad.net/bugs/64301 Title: Unable to unlock screen when using ldap Status in GNOME Screensaver: Invalid Status in “gnome-screensaver” package in Ubuntu: Confirmed Bug description: After locking the screen, you are unable to unlock it again when using ldap authentication. No errors, it just keeps saying wrong password. Local users can unlock the screen, but only if /etc/libnss-ldap.conf /etc/pam_ldap.conf are readable for everyone, which i don't want since this files contain passwords to connect to the ldapserver. To manage notifications about this bug go to: https://bugs.launchpad.net/gnome-screensaver/+bug/64301/+subscriptions -- Mailing list: https://launchpad.net/~desktop-packages Post to : [email protected] Unsubscribe : https://launchpad.net/~desktop-packages More help : https://help.launchpad.net/ListHelp

