Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PAM config prevents launching of GDM on Fedora 27 #206

Closed
avanier opened this issue Apr 16, 2018 · 0 comments
Closed

PAM config prevents launching of GDM on Fedora 27 #206

avanier opened this issue Apr 16, 2018 · 0 comments

Comments

@avanier
Copy link
Contributor

avanier commented Apr 16, 2018

As title suggests, Gnome Display Manager is unhappy and falls into a crash loop with the pam config provided in rhel_system_auth.erb on Fedora 27.

Essentially, it seems to be missing the following line :

-session     optional       pam_systemd.so

in the last block of rhel_system_auth.erb.

Will submit PR, but I have no idea of the security implications. The man page suggests if essentially creates the context for certain systemd units to create a context for the user to login to graphical sessions, which seems innocuous enough at first glance.

I'd conditional this with platform detection and node['os-hardening']['desktop']['enable'].

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant