Re: x11/xdm with PAM and security/sssd2: not working
A FreeBSD User <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.ports,gmane.os.freebsd.devel.x11 |
|---|---|
| Message-ID | <[email protected]> |
Am Tage des Herren Sat, 28 Mar 2026 20:27:07 +0300 Gleb Popov <[email protected]> schrieb: > On Thu, Mar 26, 2026 at 9:02 PM A FreeBSD User <[email protected]> wrote: > > > > Nearby: when checking as root > > > > pamtester xdm ohartmann authenticate acct_mgmt open_session close_session > > > > I see up to acct_mgmt in the log - but nothing for open_session close_session. > > I just remembered about this: https://github.com/SSSD/sssd/pull/7761/changes > Try adding the allow_chauthtok_by_root option into PAM configuration. > Thank you for the hint. I had the chance to put the referenced token into /etc/pam.d/xdm. Since lib_sss.so seems to be very tolerant with respect to were I put the token, I tried every section and exclusively auth and accounting or at all positions. NO effect. I'm not very firm in terms of how the PAM stack works, I assume "xdm" is using the file /etc/pam.d/xdm exclusively - not using another trailing module or not being a consecutive module while another module (like login?) takes password and login credentials. Without a proper logging I'm flying blind here and it seems that sssd2 isn't coping with xdm or its way to provide credential. I have to underline that any other pam method (or whatever login, sshd etc. is called) is working flawless. Kind regards, oh -- A FreeBSD user
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQRQheDybVktG5eW/1Kxzvs8OqokrwUCac/2RAAKCRCxzvs8Oqok ryJwAP4iutYulISkwzux3543w2Zw9JAnLdlKURhHOqQ24q+awwD9FZuiDYY5tKyJ 71ME8tTuTQ3IiiH5m4hqPhemji16Sgk= =wDgK -----END PGP SIGNATURE-----