fedora-cosmic: make Kanidm logins work despite a local uid-1000 account
- uid_attr_map/gid_attr_map = name so NSS/PAM see 'misthios', not the SPN - allow_local_account_override = [misthios] so Kanidm takes over an existing local account of the same name (Kanidm otherwise ignores its own entry, leaving logins to fall back to the local account and fail)
This commit is contained in:
@@ -10,10 +10,22 @@ home_alias = "name"
|
||||
use_etc_skel = true
|
||||
selinux = true
|
||||
|
||||
# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the
|
||||
# default (spn) the passwd entry name is "misthios@auth.plabble.org", which
|
||||
# confuses logins.
|
||||
uid_attr_map = "name"
|
||||
gid_attr_map = "name"
|
||||
|
||||
[kanidm]
|
||||
# Members of this Kanidm POSIX group are allowed to log in via PAM.
|
||||
pam_allowed_login_groups = ["unix_users"]
|
||||
|
||||
# A host almost always already has a local account at uid 1000. Kanidm ignores
|
||||
# its own entry when a local account with the same name exists, so logins would
|
||||
# use the local account (and the Kanidm password would fail). Let Kanidm take
|
||||
# over these local accounts. Add more names as needed.
|
||||
allow_local_account_override = ["misthios"]
|
||||
|
||||
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
|
||||
# so the service account token (when seeded) is passed as a systemd credential
|
||||
# via the build.sh-generated drop-in
|
||||
|
||||
Reference in New Issue
Block a user