-
-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
0.9.3 - ERROR PAM_IGNORE, unexpected resolver response err=Error #419
Comments
Please provide debug logs. |
Hello dmulder, I have the same configuration (Ubuntu 24.04, gdm3) and I get the same error. Please note, that I am not the admin. I am trying to help our admin to save a few hundred Notebooks from filling the landscape. In the log-file you will find a username '[email protected]'. Sometimes this name gets exchanged by '[email protected]'. Hope it helps. |
Thank You. I don't have enough time to investigate the problem with himmelblau. |
I'm investigating from the logs provided by @theageman. Be aware that authd is lacking in both features and security considerations. |
@theageman could you share your himmelblau.conf? Your log shows a single successful SFA auth, followed by 2 attempts for '[email protected]' and '[email protected]' that bail out. It appears that PAM quits communicating with the daemon and never attempted to provide a credential. |
Sure: |
@theageman See
You set the allowed groups to a non-existant Entra Id group id/name, so Himmelblau is denying every user. |
Ok, thanks. I will talk to our admin tomorrow. Can you tell me where I can look up these Objekt IDs? Thanks again, |
Forget my last post. I found the Microsoft article. ;) I will check that tomorrow. Best wishes, |
These are present in the azure portal. |
Cool, thanks. |
Okay, I have tested a new himmelblau.conf and it works a treat. Thank you very much. |
Good. @vitich you're welcome to reopen this bug if this doesn't resolve your issue. |
Sorry... I'm glad you responded so quickly, but unfortunately the error is the same on 0.9.3 - both services work...
If you log in to gdm3, it just keeps asking for a password... Tried both on Debian 12 and Ubuntu 24.04.
Version 0.8.7 works fine.
Thank You.
The text was updated successfully, but these errors were encountered: