Repository navigation
pam: keep preauth indicator for socket activation - #9399
Apollo3zehn wants to merge 1 commit into
Conversation
|
Hi, thank you for making us aware of the issue and the patch. But I think your solution basically makes the PAM_PREAUTH_INDICATOR file useless because the PAM socket well always be available if SSSD is running either permanently or socket activated. I wonder if you can check if the PAM responder would not remove the PAM_PREAUTH_INDICATOR, e.g. by not calling bye, |
|
Hi Sumit, yes, I tested your suggested approach locally. I removed the client-side PAM socket fallback and changed the responder-side indicator handling instead, so create_preauth_indicator() does not register atexit(cleanup_preauth_indicator) when the responder is socket-activated. With a rebuilt Debian package I forced the relevant state:
Then I retried the SSH IdP login. The device authorization prompt was shown directly, without a preceding password prompt :-) |
|
Hi, thank you for the update. Please squash the two patches into one and it would be nice if you can add a short comment in bye, |
35a77b0 to
6edc5f3
Compare
|
Done as requested |
There was a problem hiding this comment.
(Not introduced by this PR, but worth fixing while here)
tmp_ctx is unsed and can be removed.
There was a problem hiding this comment.
I deleted all references to tmp_ctx
| ret = atexit(cleanup_preauth_indicator); | ||
| if (ret != EOK) { | ||
| DEBUG(SSSDBG_OP_FAILURE, "atexit failed. Continuing.\n"); | ||
| } |
There was a problem hiding this comment.
@sumit-bose, maybe it makes sense to cleanup_preauth_indicator() at else branch of
sssd/src/responder/pam/pamsrv.c
Line 321 in db521e9
?
Otherwise on systems with socket activated PAM responder (and without IPA provider), once created file will never be cleared, even if config changes.
There was a problem hiding this comment.
Hi,
that's a good idea. I was wondering as well where a cleanup, when the configuration changes, can be implemented.
bye,
Sumit
ece95e2 to
6990bf4
Compare
I ran into this while testing IdP login through ssh on a Debian system with socket activated responders.
After the PAM responder was idle for a while, it exited and removed the pam_preauth_available file. The next ssh login then showed a Password prompt first. Pressing enter still started the IdP device flow, and the next login worked directly again because the responder was running by then.
This changes the pam_sss preauth check so it also tries preauth when the PAM responder socket exists. In that case the socket can start the responder and preauth can return the device flow prompt directly.
I tested this locally with a rebuilt package by stopping/letting the PAM responder go away so the indicator file was absent while /var/lib/sss/pipes/pam still existed. With this patch the ssh login showed the device flow prompt directly instead of Password first.