kanidm-unixd runs with DynamicUser=yes, so it cannot read the root-only /etc/kanidm/unixd_token. With service_account_token_path set in /etc/kanidm/unixd the daemon failed with PermissionDenied and no Kanidm user resolved. Drop that setting and inject the token with LoadCredential + KANIDM_SERVICE_ACCOUNT_TOKEN_PATH through a generated drop-in. Verified in a QEMU VM: kanidm-unixd active, 'kanidm-unix status' online, 'getent passwd job' resolves.
22 lines
664 B
Plaintext
22 lines
664 B
Plaintext
version = "2"
|
|
|
|
# Bind cached credentials to the local TPM when one is available.
|
|
hsm_type = "tpm_if_possible"
|
|
|
|
default_shell = "/bin/bash"
|
|
home_prefix = "/home/"
|
|
home_attr = "uuid"
|
|
home_alias = "name"
|
|
use_etc_skel = true
|
|
selinux = true
|
|
|
|
[kanidm]
|
|
# Members of this Kanidm POSIX group are allowed to log in via PAM.
|
|
pam_allowed_login_groups = ["unix_users"]
|
|
|
|
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
|
|
# so the service account token (when seeded) is passed as a systemd credential
|
|
# via the build.sh-generated drop-in
|
|
# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf.
|
|
# Do not set service_account_token_path here.
|