This sounds like a bug, could you follow 
https://docs.pagure.org/SSSD.sssd/users/troubleshooting.html, gather logs from 
the pam and domain sections and post them here? If the password is expired, 
then pam_sss should send a message to the login manager which the login manager 
should display.

The logs would at least show if the deamon is sending the message to pam_sss…

> On 21 Dec 2017, at 09:39, Johan Vermeulen via FreeIPA-users 
> <freeipa-users@lists.fedorahosted.org> wrote:
> 
> Hello All,
> 
> We run some 200 Centos7/Mate laptops, since last year they authenticate 
> against freeipa. 
> Lightdm/Mate are installed using epel repo. 
> 
> On Centos7.3/Lightdm 1.10.6-4.el7 things were al right, when a password 
> expired, users would get the passwd expired field, the "new password" field 
> en warnings if the made a mistake. 
> Since upgrading to Centos7.4/Lightdm 1.25.0-1.el7 things go terribly wrong. 
> Users very often get no warning if a password expired, just an authentication 
> failure. 
> Or they get no message at all. 
> 
> If at that point you got to tty....and log in you do get the warnings on the 
> command line. 
> The log files /var/log/secure also give clear password expired messages, only 
> the user sees nothing.
> 
> This is a big problem because users cannot login and cannot work without 
> interventions.
> 
> Many thanks for any help.
> 
> Greetings, J.
> _______________________________________________
> FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
> To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
  • [Freeipa-users] Cen... Johan Vermeulen via FreeIPA-users
    • [Freeipa-users... Stephen Berg (Contractor, Code 7320) via FreeIPA-users
    • [Freeipa-users... Jakub Hrozek via FreeIPA-users
      • [Freeipa-u... Johan Vermeulen via FreeIPA-users
        • [Freei... Jakub Hrozek via FreeIPA-users
          • [F... Jakub Hrozek via FreeIPA-users
            • ... Johan Vermeulen via FreeIPA-users
              • ... Jakub Hrozek via FreeIPA-users
                • ... Johan Vermeulen via FreeIPA-users
                • ... Jakub Hrozek via FreeIPA-users

Reply via email to