Re: x11/xdm with PAM and security/sssd2: not working

A FreeBSD User <[email protected]>
Newsgroups gmane.os.freebsd.devel.ports,gmane.os.freebsd.devel.x11
Message-ID <[email protected]>
Am Tage des Herren Sat, 28 Mar 2026 20:27:07 +0300
Gleb Popov <[email protected]> schrieb:

> On Thu, Mar 26, 2026 at 9:02 PM A FreeBSD User <[email protected]> wrote:
> >
> > Nearby: when checking as root
> >
> > pamtester xdm ohartmann authenticate acct_mgmt open_session close_session
> >
> > I see up to acct_mgmt in the log - but nothing for open_session close_session.  
> 
> I just remembered about this: https://github.com/SSSD/sssd/pull/7761/changes
> Try adding the allow_chauthtok_by_root option into PAM configuration.
> 

Thank you for the hint.
I had the chance to put the referenced token into /etc/pam.d/xdm. Since lib_sss.so seems to be
very tolerant with respect to were I put the token, I tried every section and exclusively auth
and accounting or at all positions. NO effect.

I'm not very firm in terms of how the PAM stack works, I assume "xdm" is using the file
/etc/pam.d/xdm exclusively - not using another trailing module or not being a consecutive
module while another module (like login?) takes password and login credentials.

Without a proper logging I'm flying blind here and it seems that sssd2 isn't coping with xdm
or its way to provide credential.

I have to underline that any other pam method (or whatever login, sshd etc. is called) is
working flawless.

Kind regards,
oh 

-- 

A FreeBSD user
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQRQheDybVktG5eW/1Kxzvs8OqokrwUCac/2RAAKCRCxzvs8Oqok
ryJwAP4iutYulISkwzux3543w2Zw9JAnLdlKURhHOqQ24q+awwD9FZuiDYY5tKyJ
71ME8tTuTQ3IiiH5m4hqPhemji16Sgk=
=wDgK
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.