Managing access to Fedora 27 workstation with FreeIPA and HBAC

If you are trying to create an HBAC rule in FreeIPA to allow users to log on to Fedora 27 workstations via GDM, you will need to do the following:

– Create a new HBAC service in FreeIPA, called “systemd-user”

– Create an HBAC rule that includes “gdm”, “gdm-password”, and “systemd-user”, granting access to your users for the targeted hosts

Figuring out the need to create the “systemd-user” service required adding “debug_level=9” in the [pam] section of /etc/sssd/sssd.conf, and a lot of patience.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s