diff --git a/images/fedora-cosmic/files/kanidm-unixd b/images/fedora-cosmic/files/kanidm-unixd index 910fabd..fd72ba2 100644 --- a/images/fedora-cosmic/files/kanidm-unixd +++ b/images/fedora-cosmic/files/kanidm-unixd @@ -10,10 +10,22 @@ home_alias = "name" use_etc_skel = true selinux = true +# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the +# default (spn) the passwd entry name is "misthios@auth.plabble.org", which +# confuses logins. +uid_attr_map = "name" +gid_attr_map = "name" + [kanidm] # Members of this Kanidm POSIX group are allowed to log in via PAM. pam_allowed_login_groups = ["unix_users"] +# A host almost always already has a local account at uid 1000. Kanidm ignores +# its own entry when a local account with the same name exists, so logins would +# use the local account (and the Kanidm password would fail). Let Kanidm take +# over these local accounts. Add more names as needed. +allow_local_account_override = ["misthios"] + # NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file, # so the service account token (when seeded) is passed as a systemd credential # via the build.sh-generated drop-in