Hello,Start with installing security/pamtester and running
fighting a major problem here.
On Sun, Mar 22, 2026 at 6:18=E2=80=AFPM A FreeBSD User <freebsd@walstatt-=de.de> wrote:
Hello,
fighting a major problem here. =20=20
Start with installing security/pamtester and running
=20
pamtester xdm <username> authenticate
=20
Does it also fail? Do you see something suspicious in SSSD logs?
=20
Using pam_sss.so as described initially in /etc/pam.d/xdm:Re-run these checks as root, because this is how xdm runs PAM, if I
ohartmann@host [ohartmann]: pamtester xdm ohartmann authenticate
Password:
pamtester: successfully authenticated
ohartmann@host [ohartmann]: pamtester xdm ohartmann acct_mgmt
pamtester: account management done.
ohartmann@host [ohartmann]: pamtester xdm ohartmann open_session
Can't mkdir /var/run/xdg/pamtester: Session failure
On Mon, Mar 23, 2026 at 1:13=E2=80=AFAM A FreeBSD User <freebsd@walstatt-=de.de> wrote:
Using pam_sss.so as described initially in /etc/pam.d/xdm:
ohartmann@host [ohartmann]: pamtester xdm ohartmann authenticate
Password:
pamtester: successfully authenticated
ohartmann@host [ohartmann]: pamtester xdm ohartmann acct_mgmt
pamtester: account management done.
ohartmann@host [ohartmann]: pamtester xdm ohartmann open_session=20
Can't mkdir /var/run/xdg/pamtester: Session failure =20
Re-run these checks as root, because this is how xdm runs PAM, if I understand it correctly.
=20
In /usr/local/etc/sssd/sssd.conf I also tried to enable "debug_level = 6" - I never see in ANYYes, I also don't remember how to properly enable logging to file in
log file residing in /var/log more than (grep -r sssd /var/log):
On Wed, Mar 25, 2026 at 3:16=E2=80=AFPM A FreeBSD User <freebsd@walstatt-=de.de> wrote:
=3D 6" - I never see inIn /usr/local/etc/sssd/sssd.conf I also tried to enable "debug_level =
ANY log file residing in /var/log more than (grep -r sssd /var/log): =20=20
Yes, I also don't remember how to properly enable logging to file in
SSSD. Instead, when I need to debug it, I do
=20
service sssd stop
sssd -dddd -i
=20
This runs sssd in the foreground with all logs visible on the console.
Maybe you should try this as a last attempt?
=20
Nearby: when checking as rootI just remembered about this: https://github.com/SSSD/sssd/pull/7761/changes Try adding the allow_chauthtok_by_root option into PAM configuration.
pamtester xdm ohartmann authenticate acct_mgmt open_session close_session
I see up to acct_mgmt in the log - but nothing for open_session close_session.
On Thu, Mar 26, 2026 at 9:02=E2=80=AFPM A FreeBSD User <freebsd@walstatt-=de.de> wrote:
onNearby: when checking as root
pamtester xdm ohartmann authenticate acct_mgmt open_session close_sessi=
ession. =20I see up to acct_mgmt in the log - but nothing for open_session close_s=
=20ges
I just remembered about this: https://github.com/SSSD/sssd/pull/7761/chan=
Try adding the allow_chauthtok_by_root option into PAM configuration.
=20
I managed to reproduce the issue on 15.0-RELEASE and SSSD with theAs a data point, I managed to login as a domain user via x11/sddm.
Active Directory backend.
Unfortunately, debugging XDM is painful as it forks a lot, so I
haven't been able to identify the root cause yet.
I will hopefully take another stab on it next week.
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 65 |
| Nodes: | 6 (0 / 6) |
| Uptime: | 62:51:35 |
| Calls: | 862 |
| Files: | 1,311 |
| D/L today: |
10 files (20,373K bytes) |
| Messages: | 264,051 |