Jump to content

Talk:SSSD

From ArchWiki
Latest comment: 2 September by Danblack in topic Alternate to running the sssd service as root

Alternate to running the sssd service as root

As a pam proxy, the objective is to have the sssd_proxy that executes `/usr/bin/unix_chkpwd` (it may be suid, however it changes back to `sssd` user) to be able to reading `/etc/shadow` file

So the below is sufficient to append read access for the sssd user.

setfacl -m u:sssd:r /etc/shadow Danblack (talk) 02:26, 2 September 2026 (UTC)Reply