fedora-cosmic: make Kanidm logins work despite a local uid-1000 account
Build containers / fedora-cosmic (rawhide) (push) Failing after 50s
Build containers / fedora-cosmic (44) (push) Successful in 11m0s
Build containers / Prune old releases (push) Successful in 20s

- uid_attr_map/gid_attr_map = name so NSS/PAM see 'misthios', not the SPN
- allow_local_account_override = [misthios] so Kanidm takes over an existing
  local account of the same name (Kanidm otherwise ignores its own entry,
  leaving logins to fall back to the local account and fail)
This commit is contained in:
2026-09-27 19:46:36 +02:00
parent f6205eb982
commit 380d550351
+12
View File
@@ -10,10 +10,22 @@ home_alias = "name"
use_etc_skel = true
selinux = true
# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the
# default (spn) the passwd entry name is "misthios@auth.plabble.org", which
# confuses logins.
uid_attr_map = "name"
gid_attr_map = "name"
[kanidm]
# Members of this Kanidm POSIX group are allowed to log in via PAM.
pam_allowed_login_groups = ["unix_users"]
# A host almost always already has a local account at uid 1000. Kanidm ignores
# its own entry when a local account with the same name exists, so logins would
# use the local account (and the Kanidm password would fail). Let Kanidm take
# over these local accounts. Add more names as needed.
allow_local_account_override = ["misthios"]
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
# so the service account token (when seeded) is passed as a systemd credential
# via the build.sh-generated drop-in