From nobody Fri Apr 3 17:17:29 2026 X-Original-To: freebsd-ports@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fnQR54MrHz6YrlK; Fri, 03 Apr 2026 17:18:09 +0000 (UTC) (envelope-from freebsd@walstatt-de.de) Received: from smtp052.goneo.de (smtp052.goneo.de [85.220.129.60]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4fnQR31Frdz3ydr; Fri, 03 Apr 2026 17:18:06 +0000 (UTC) (envelope-from freebsd@walstatt-de.de) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=walstatt-de.de header.s=DKIM001 header.b=RZkPjtdb; dmarc=none; spf=pass (mx1.freebsd.org: domain of freebsd@walstatt-de.de designates 85.220.129.60 as permitted sender) smtp.mailfrom=freebsd@walstatt-de.de Received: from hub1.goneo.de (hub1.goneo.de [IPv6:2001:1640:5::8:52]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by smtp5.goneo.de (Postfix) with ESMTPS id D96CA2402AD; Fri, 3 Apr 2026 19:18:04 +0200 (CEST) Received: from hub1.goneo.de (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by hub1.goneo.de (Postfix) with ESMTPS id 07E0E240170; Fri, 3 Apr 2026 19:18:03 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=walstatt-de.de; s=DKIM001; t=1775236683; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=h6+zGLYJPvVZ2utIb4SQKXy3w8BINmsaEaIF0iSO62w=; b=RZkPjtdbTAWatuCLyTQ3X/clkr4nx+ydjieVmjzqTZQ53dW8uwSeCE0sCDD6zhoBvGi2e6 TqxjP9rQCRPOMHnDw6BNYUI3wUzsprVCLArLrJnzVAALQQ+S1UsPR1P3rGdyFFwtUYMIR9 LPr7EBEwZTwARvKIeW/Npvq+CgksrEzR3EKlI09fzdxBrqj5JHzs9aTLY2sQjJizzNns2b +ZKcNDbK+jROKbhbyBTX3ARQrnmjvbO2ZQOR4w4sYm6LEA6MwHRxDEM5EBaeIxnLFHg274 LM2eV/2B5xUMYisAEEfqhbQRe32HmE3v5tdCA4/mKIpx4BszktNGQiCq2WFdfw== Received: from thor.sb211.local (dynamic-2a02-3100-1cb7-8202-487a-ebb1-fb43-a8c5.310.pool.telefonica.de [IPv6:2a02:3100:1cb7:8202:487a:ebb1:fb43:a8c5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (prime256v1) server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by hub1.goneo.de (Postfix) with ESMTPSA id 9DEFC2400C0; Fri, 3 Apr 2026 19:18:02 +0200 (CEST) Date: Fri, 3 Apr 2026 19:17:29 +0200 From: A FreeBSD User To: Gleb Popov Cc: freebsd-x11@freebsd.org, FreeBSD Ports Subject: Re: x11/xdm with PAM and security/sssd2: not working Message-ID: <20260403191756.1a720c7d@thor.sb211.local> In-Reply-To: References: <20260322161501.690d8923@thor.sb211.local> <20260322231229.1421f764@thor.sb211.local> <20260325131602.4048563c@thor.sb211.local> <20260326190131.66aff61d@thor.sb211.local> X-Mailer: Claws Mail 4.4.0 (GTK 3.24.52; amd64-portbld-freebsd16.0) List-Id: Porting software to FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-ports List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-ports@freebsd.org Sender: owner-freebsd-ports@FreeBSD.org MIME-Version: 1.0 Content-Type: multipart/signed; boundary="Sig_/x33F7zhz0wuWzutvARtW_jq"; protocol="application/pgp-signature"; micalg=pgp-sha512 X-Rspamd-UID: a09827 X-Rspamd-UID: b83aec X-Spamd-Result: default: False [-5.70 / 15.00]; SIGNED_PGP(-2.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_SHORT(-1.00)[-0.997]; R_DKIM_ALLOW(-0.20)[walstatt-de.de:s=DKIM001]; R_SPF_ALLOW(-0.20)[+ip4:85.220.129.0/25]; MIME_GOOD(-0.20)[multipart/signed,text/plain]; RCVD_IN_DNSWL_LOW(-0.10)[85.220.129.60:from]; ARC_NA(0.00)[]; ASN(0.00)[asn:25394, ipnet:85.220.128.0/17, country:DE]; RCVD_TLS_ALL(0.00)[]; TO_DN_SOME(0.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:~]; RCVD_VIA_SMTP_AUTH(0.00)[]; RCVD_COUNT_THREE(0.00)[3]; MLMMJ_DEST(0.00)[freebsd-ports@freebsd.org,freebsd-x11@freebsd.org]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; FROM_EQ_ENVFROM(0.00)[]; DMARC_NA(0.00)[walstatt-de.de]; TO_MATCH_ENVRCPT_ALL(0.00)[]; DKIM_TRACE(0.00)[walstatt-de.de:+] X-Rspamd-Queue-Id: 4fnQR31Frdz3ydr X-Spamd-Bar: ----- --Sig_/x33F7zhz0wuWzutvARtW_jq Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Am Tage des Herren Sat, 28 Mar 2026 20:27:07 +0300 Gleb Popov schrieb: > On Thu, Mar 26, 2026 at 9:02=E2=80=AFPM A FreeBSD User wrote: > > > > Nearby: when checking as root > > > > pamtester xdm ohartmann authenticate acct_mgmt open_session close_sessi= on > > > > I see up to acct_mgmt in the log - but nothing for open_session close_s= ession. =20 >=20 > I just remembered about this: https://github.com/SSSD/sssd/pull/7761/chan= ges > Try adding the allow_chauthtok_by_root option into PAM configuration. >=20 Thank you for the hint. I had the chance to put the referenced token into /etc/pam.d/xdm. Since lib= _sss.so seems to be very tolerant with respect to were I put the token, I tried every section a= nd exclusively auth and accounting or at all positions. NO effect. I'm not very firm in terms of how the PAM stack works, I assume "xdm" is us= ing the file /etc/pam.d/xdm exclusively - not using another trailing module or not being= a consecutive module while another module (like login?) takes password and login credenti= als. Without a proper logging I'm flying blind here and it seems that sssd2 isn'= t coping with xdm or its way to provide credential. I have to underline that any other pam method (or whatever login, sshd etc.= is called) is working flawless. Kind regards, oh=20 --=20 A FreeBSD user --Sig_/x33F7zhz0wuWzutvARtW_jq Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQRQheDybVktG5eW/1Kxzvs8OqokrwUCac/2RAAKCRCxzvs8Oqok ryJwAP4iutYulISkwzux3543w2Zw9JAnLdlKURhHOqQ24q+awwD9FZuiDYY5tKyJ 71ME8tTuTQ3IiiH5m4hqPhemji16Sgk= =wDgK -----END PGP SIGNATURE----- --Sig_/x33F7zhz0wuWzutvARtW_jq--