On (02/12/15 20:42), Eric Biggers wrote:
The apparent change in ad_gpo_access_control in sssd-1.13.2 in Fedora 22 broke my setup as well --- although for me it was a "permission denied" failure in the "account" PAM module which only occurred when logging in with xscreensaver (not when logging in at a virtual console).
Is this possibly an SSSD bug, or is it a broken AD setup? What's the best way to debug this type of problem?
Eric, Edouard,
Could you provide sssd logfiles with enabled verbose logging and gpo in permissive or enforcing mode?
As Jakub wrote in different mail. we will need to see gpo_child.log and sssd_${domain}.log (with debug_level = 9)
If you do not want to send them to mailing list You can attach them to ticket https://fedorahosted.org/sssd/ticket/2889 or you can send them privately.
LS