From 380d55035176cc442fb8ab71c4bb651521a4a650 Mon Sep 17 00:00:00 2001 From: Wesley van Tilburg Date: Sun, 27 Sep 2026 19:46:36 +0200 Subject: [PATCH] fedora-cosmic: make Kanidm logins work despite a local uid-1000 account - uid_attr_map/gid_attr_map = name so NSS/PAM see 'misthios', not the SPN - allow_local_account_override = [misthios] so Kanidm takes over an existing local account of the same name (Kanidm otherwise ignores its own entry, leaving logins to fall back to the local account and fail) --- images/fedora-cosmic/files/kanidm-unixd | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/images/fedora-cosmic/files/kanidm-unixd b/images/fedora-cosmic/files/kanidm-unixd index 910fabd..fd72ba2 100644 --- a/images/fedora-cosmic/files/kanidm-unixd +++ b/images/fedora-cosmic/files/kanidm-unixd @@ -10,10 +10,22 @@ home_alias = "name" use_etc_skel = true selinux = true +# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the +# default (spn) the passwd entry name is "misthios@auth.plabble.org", which +# confuses logins. +uid_attr_map = "name" +gid_attr_map = "name" + [kanidm] # Members of this Kanidm POSIX group are allowed to log in via PAM. pam_allowed_login_groups = ["unix_users"] +# A host almost always already has a local account at uid 1000. Kanidm ignores +# its own entry when a local account with the same name exists, so logins would +# use the local account (and the Kanidm password would fail). Let Kanidm take +# over these local accounts. Add more names as needed. +allow_local_account_override = ["misthios"] + # NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file, # so the service account token (when seeded) is passed as a systemd credential # via the build.sh-generated drop-in