version = "2"

# Bind cached credentials to the local TPM when one is available.
hsm_type = "tpm_if_possible"

default_shell = "/bin/bash"
home_prefix = "/home/"
home_attr = "uuid"
home_alias = "name"
use_etc_skel = true
selinux = true

[kanidm]
# Members of this Kanidm POSIX group are allowed to log in via PAM.
pam_allowed_login_groups = ["unix_users"]

# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
# so the service account token (when seeded) is passed as a systemd credential
# via the build.sh-generated drop-in
# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf.
# Do not set service_account_token_path here.
