I'm not having any luck using smart card auth on an IPA joined Ubuntu 18.04
system.  It appears that pam is not properly configured, and in particular I
don't see "allow_missing_name" in use:

/etc/pam.d/common-auth:
auth    [success=2 default=ignore]      pam_unix.so nullok_secure
auth     [success=1 default=ignore]      pam_sss.so use_first_pass
auth    requisite                       pam_deny.so
auth    required                        pam_permit.so
auth    optional                        pam_cap.so

although if I add allow_missing_name to that line, it doesn't seem to help.  I
don't see any SSS_PAM_PREAUTH activity in the sssd_pam.log.

Any pointers?

Thanks!

- Orion

-- 
Orion Poplawski
Manager of NWRA Technical Systems          720-772-5637
NWRA, Boulder/CoRA Office             FAX: 303-415-9702
3380 Mitchell Lane                       [email protected]
Boulder, CO 80301                 https://www.nwra.com/
_______________________________________________
sssd-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to