version = "2" # Bind cached credentials to the local TPM when one is available. hsm_type = "tpm_if_possible" default_shell = "/bin/bash" home_prefix = "/home/" home_attr = "uuid" home_alias = "name" use_etc_skel = true selinux = true [kanidm] # Members of this Kanidm POSIX group are allowed to log in via PAM. pam_allowed_login_groups = ["unix_users"] # NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file, # so the service account token (when seeded) is passed as a systemd credential # via the build.sh-generated drop-in # /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf. # Do not set service_account_token_path here.