Ubuntu 18.04.1 auth - SSSD + Kerberos - missing homedir











up vote
0
down vote

favorite












I set up AD auth in Ubuntu 18.04.1 and used the same config options like in a Ubuntu 18.04 installation where everything is working fine.



In 18.04.1 I can log in with my AD user but the home dir isn't created.
The logged in user logs out immediately after login and successful auth via ssh.
Syslog don't give a hint about that - only the messages



...
Started User Manager for UID 888015009
Stopping User Manager for UID 888015009
...


If I remove the line



session required pam_mkhomedir.so skel=/etc/skel/ umask=0022


from file /etc/pam.d/common-session I can log and session persists but of course without home dir.



My sssd.conf looks like



[sssd]
services = nss, pam
config_file_version = 2
domains = DOMAIN.LOCAL

[domain/DOMAIN.LOCAL]
id_provider = ad
access_provider = ad
default_shell = /bin/bash
cache_credentials = true

override_homedir = /home/%d/%u


If I create homedir manually everything else works as expected.



Any hints what's going wrong?
What's the function of user manager? In which context is it running? So maybe permissions problem?



It would be great if you could help me out getting this solved!










share|improve this question


























    up vote
    0
    down vote

    favorite












    I set up AD auth in Ubuntu 18.04.1 and used the same config options like in a Ubuntu 18.04 installation where everything is working fine.



    In 18.04.1 I can log in with my AD user but the home dir isn't created.
    The logged in user logs out immediately after login and successful auth via ssh.
    Syslog don't give a hint about that - only the messages



    ...
    Started User Manager for UID 888015009
    Stopping User Manager for UID 888015009
    ...


    If I remove the line



    session required pam_mkhomedir.so skel=/etc/skel/ umask=0022


    from file /etc/pam.d/common-session I can log and session persists but of course without home dir.



    My sssd.conf looks like



    [sssd]
    services = nss, pam
    config_file_version = 2
    domains = DOMAIN.LOCAL

    [domain/DOMAIN.LOCAL]
    id_provider = ad
    access_provider = ad
    default_shell = /bin/bash
    cache_credentials = true

    override_homedir = /home/%d/%u


    If I create homedir manually everything else works as expected.



    Any hints what's going wrong?
    What's the function of user manager? In which context is it running? So maybe permissions problem?



    It would be great if you could help me out getting this solved!










    share|improve this question
























      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      I set up AD auth in Ubuntu 18.04.1 and used the same config options like in a Ubuntu 18.04 installation where everything is working fine.



      In 18.04.1 I can log in with my AD user but the home dir isn't created.
      The logged in user logs out immediately after login and successful auth via ssh.
      Syslog don't give a hint about that - only the messages



      ...
      Started User Manager for UID 888015009
      Stopping User Manager for UID 888015009
      ...


      If I remove the line



      session required pam_mkhomedir.so skel=/etc/skel/ umask=0022


      from file /etc/pam.d/common-session I can log and session persists but of course without home dir.



      My sssd.conf looks like



      [sssd]
      services = nss, pam
      config_file_version = 2
      domains = DOMAIN.LOCAL

      [domain/DOMAIN.LOCAL]
      id_provider = ad
      access_provider = ad
      default_shell = /bin/bash
      cache_credentials = true

      override_homedir = /home/%d/%u


      If I create homedir manually everything else works as expected.



      Any hints what's going wrong?
      What's the function of user manager? In which context is it running? So maybe permissions problem?



      It would be great if you could help me out getting this solved!










      share|improve this question













      I set up AD auth in Ubuntu 18.04.1 and used the same config options like in a Ubuntu 18.04 installation where everything is working fine.



      In 18.04.1 I can log in with my AD user but the home dir isn't created.
      The logged in user logs out immediately after login and successful auth via ssh.
      Syslog don't give a hint about that - only the messages



      ...
      Started User Manager for UID 888015009
      Stopping User Manager for UID 888015009
      ...


      If I remove the line



      session required pam_mkhomedir.so skel=/etc/skel/ umask=0022


      from file /etc/pam.d/common-session I can log and session persists but of course without home dir.



      My sssd.conf looks like



      [sssd]
      services = nss, pam
      config_file_version = 2
      domains = DOMAIN.LOCAL

      [domain/DOMAIN.LOCAL]
      id_provider = ad
      access_provider = ad
      default_shell = /bin/bash
      cache_credentials = true

      override_homedir = /home/%d/%u


      If I create homedir manually everything else works as expected.



      Any hints what's going wrong?
      What's the function of user manager? In which context is it running? So maybe permissions problem?



      It would be great if you could help me out getting this solved!







      18.04 home-directory kerberos sssd






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 21 at 11:06









      pfleckenstein

      11




      11



























          active

          oldest

          votes











          Your Answer








          StackExchange.ready(function() {
          var channelOptions = {
          tags: "".split(" "),
          id: "89"
          };
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function() {
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled) {
          StackExchange.using("snippets", function() {
          createEditor();
          });
          }
          else {
          createEditor();
          }
          });

          function createEditor() {
          StackExchange.prepareEditor({
          heartbeatType: 'answer',
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader: {
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          },
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          });


          }
          });














          draft saved

          draft discarded


















          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1094769%2fubuntu-18-04-1-auth-sssd-kerberos-missing-homedir%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown






























          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes
















          draft saved

          draft discarded




















































          Thanks for contributing an answer to Ask Ubuntu!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.





          Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


          Please pay close attention to the following guidance:


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1094769%2fubuntu-18-04-1-auth-sssd-kerberos-missing-homedir%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Biblatex bibliography style without URLs when DOI exists (in Overleaf with Zotero bibliography)

          ComboBox Display Member on multiple fields

          Is it possible to collect Nectar points via Trainline?