Install kanidm-unixd-clients/kanidm-clients, point /etc/kanidm/config at
auth.plabble.org, configure unixd (TPM-backed cache, pam_allowed_login_groups),
and set up PAM/nsswitch via an authselect custom profile (with a direct-file
fallback). Enable kanidm-unixd{,-tasks} and make unconfined_service_t
permissive until Kanidm ships an SELinux policy.
21 lines
613 B
Plaintext
21 lines
613 B
Plaintext
version = "2"
|
|
|
|
# Bind cached credentials to the local TPM when one is available.
|
|
hsm_type = "tpm_if_possible"
|
|
|
|
default_shell = "/bin/bash"
|
|
home_prefix = "/home/"
|
|
home_attr = "uuid"
|
|
home_alias = "name"
|
|
use_etc_skel = true
|
|
selinux = true
|
|
|
|
[kanidm]
|
|
# Members of this Kanidm POSIX group are allowed to log in via PAM.
|
|
pam_allowed_login_groups = ["unix_users"]
|
|
|
|
# Token for the Kanidm service account used to resolve identities. Provision it
|
|
# at /etc/kanidm/unixd_token (a single line) after install, or remove this line
|
|
# if the server permits anonymous reads.
|
|
service_account_token_path = "/etc/kanidm/unixd_token"
|