-
Notifications
You must be signed in to change notification settings - Fork 83
package.use: enable back sssd for pambase #3696
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
This was not creating the system-auth with the 'pam_sss' module. Which makes sssd LDAP authentication to fail. Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
This brings a fix to move the pam_sss at the right position. I think this can be upstreamed. Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
chewi
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Well, it looks okay, but I honestly don't understand PAM well enough to say whether it's correct. I know it's not @krnowak's favourite subject either, but I'd feel better waiting for him.
I'm a little surprised Gentoo hasn't noticed. The sssd support has been in place for a couple of years now. Perhaps it's due to other differences in our config, but it doesn't seem that way.
I'm holding this until I get user feedback. I would honestly prefer having this released in alpha / beta before promoting a new stable |
@chewi I got this user feedback: flatcar/Flatcar#1985 (comment) - given this + the CI result I think we're good. But as proposed on Matrix, let's not promote this directly to Stable. |
This was not creating the system-auth with the 'pam_sss' module. Which makes sssd LDAP authentication to fail.
I amended the patch to move the
pam_sss.socall before thepam_faillock.sootherwise it was failing - I think this could be proposed to the upstream.Related to: flatcar/Flatcar#1985
TODO:
Testing: