Skip to content

pam: keep preauth indicator for socket activation - #9399

Open
Apollo3zehn wants to merge 1 commit into
SSSD:masterfrom
Apollo3zehn:fix/pam-preauth-socket-activation
Open

Apollo3zehn wants to merge 1 commit into
SSSD:masterfrom
Apollo3zehn:fix/pam-preauth-socket-activation

Conversation

@Apollo3zehn

Copy link
Copy Markdown

I ran into this while testing IdP login through ssh on a Debian system with socket activated responders.

After the PAM responder was idle for a while, it exited and removed the pam_preauth_available file. The next ssh login then showed a Password prompt first. Pressing enter still started the IdP device flow, and the next login worked directly again because the responder was running by then.

This changes the pam_sss preauth check so it also tries preauth when the PAM responder socket exists. In that case the socket can start the responder and preauth can return the device flow prompt directly.

I tested this locally with a rebuilt package by stopping/letting the PAM responder go away so the indicator file was absent while /var/lib/sss/pipes/pam still existed. With this patch the ssh login showed the device flow prompt directly instead of Password first.

@sumit-bose

Copy link
Copy Markdown
Contributor

Hi,

thank you for making us aware of the issue and the patch. But I think your solution basically makes the PAM_PREAUTH_INDICATOR file useless because the PAM socket well always be available if SSSD is running either permanently or socket activated. I wonder if you can check if the PAM responder would not remove the PAM_PREAUTH_INDICATOR, e.g. by not calling atexit(cleanup_preauth_indicator) in create_preauth_indicator() if the PAM responder is socket activated (socket_activated member in struct resp_ctx), it will work as well?

bye,
Sumit

@Apollo3zehn Apollo3zehn changed the title pam_sss: also try preauth when PAM socket exists pam: keep preauth indicator for socket activation Oct 8, 2026
@Apollo3zehn

Copy link
Copy Markdown
Author

Hi Sumit,

yes, I tested your suggested approach locally.

I removed the client-side PAM socket fallback and changed the responder-side indicator handling instead, so create_preauth_indicator() does not register atexit(cleanup_preauth_indicator) when the responder is socket-activated.

With a rebuilt Debian package I forced the relevant state:

  • sssd-pam.service inactive
  • /var/lib/sss/pipes/pam present
  • /var/lib/sss/pubconf/pam_preauth_available present

Then I retried the SSH IdP login. The device authorization prompt was shown directly, without a preceding password prompt :-)

@sumit-bose

Copy link
Copy Markdown
Contributor

Hi,

thank you for the update. Please squash the two patches into one and it would be nice if you can add a short comment in src/util/util_preauth.c why we do not want to delete the file if the responder is socket activated.

bye,
Sumit

@alexey-tikhonov
alexey-tikhonov self-requested a review October 8, 2026 12:50
@alexey-tikhonov alexey-tikhonov self-assigned this Oct 8, 2026
@Apollo3zehn
Apollo3zehn force-pushed the fix/pam-preauth-socket-activation branch from 35a77b0 to 6edc5f3 Compare October 8, 2026 18:47
@Apollo3zehn

Copy link
Copy Markdown
Author

Done as requested

Comment thread src/util/util_preauth.c Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Not introduced by this PR, but worth fixing while here)
tmp_ctx is unsed and can be removed.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I deleted all references to tmp_ctx

Comment thread src/util/util_preauth.c
ret = atexit(cleanup_preauth_indicator);
if (ret != EOK) {
DEBUG(SSSDBG_OP_FAILURE, "atexit failed. Continuing.\n");
}

@alexey-tikhonov alexey-tikhonov Oct 9, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sumit-bose, maybe it makes sense to cleanup_preauth_indicator() at else branch of

if (pctx->cert_auth

?

Otherwise on systems with socket activated PAM responder (and without IPA provider), once created file will never be cleared, even if config changes.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,

that's a good idea. I was wondering as well where a cleanup, when the configuration changes, can be implemented.

bye,
Sumit

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Apollo3zehn, mind adding this please?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

@Apollo3zehn
Apollo3zehn force-pushed the fix/pam-preauth-socket-activation branch from ece95e2 to 6990bf4 Compare October 9, 2026 14:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants