version = "2" # Bind cached credentials to the local TPM when one is available. hsm_type = "tpm_if_possible" default_shell = "/bin/bash" home_prefix = "/home/" home_attr = "uuid" home_alias = "name" use_etc_skel = true selinux = true # Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the # default (spn) the passwd entry name is "misthios@auth.plabble.org", which # confuses logins. uid_attr_map = "name" gid_attr_map = "name" [kanidm] # Members of this Kanidm POSIX group are allowed to log in via PAM. pam_allowed_login_groups = ["unix_users"] # A host almost always already has a local account at uid 1000. Kanidm ignores # its own entry when a local account with the same name exists, so logins would # use the local account (and the Kanidm password would fail). Let Kanidm take # over these local accounts. Add more names as needed. allow_local_account_override = ["misthios"] # NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file, # so the service account token (when seeded) is passed as a systemd credential # via the build.sh-generated drop-in # /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf. # Do not set service_account_token_path here.