Enforcing SELinux blocks Kanidm user resolution/authentication for sshd and friends, but no AVC is emitted (even with dontaudit disabled), so the exact allow could not be pinned. Keep the CIL allows and mark the login/nss domains permissive so Kanidm logins work. Revisit when the denial can be isolated.