[Freeipa-users] Why would /etc/passwd get skipped?

Bret Wortman bret.wortman at damascusgrp.com
Thu May 22 16:47:29 UTC 2014


If this line is in /etc/nsswitch.conf:

passwd: files sss

Why would the user account from IPA get used when an identical one 
exists in /etc/passwd? We can tell because of some additional groups 
granted when authentication comes from IPA.

If I shut down sssd, then login proceeds through /etc/passwd as 
expected, but as soon as I restart sssd, this behavior starts again. 
It's almost as if nsswitch.conf is being ignored or read right-to-left.

Just another oddity I uncovered on one system as I was troubleshooting a 
particularly long "ssh localhost" and trying to rule things out.


-- 
*Bret Wortman*

http://damascusgrp.com/
http://about.me/wortmanbret

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20140522/35197012/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 51f7de33e4b08d2bdb8b4860
Type: image/png
Size: 28526 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20140522/35197012/attachment.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3766 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20140522/35197012/attachment.p7s>


More information about the Freeipa-users mailing list