#751 better default logging of access denials
Closed: Fixed Opened by ossman.

Ticket #670 and #746 adds some new access control mechanism. Unfortunately all you see in the logs by default when one of these hit is:

Dec 22 19:25:55 f14-test sshd[5701]: pam_sss(sshd:account): Access denied for user drzeus: 6 (Permission denied)
Dec 22 19:25:55 f14-test sshd[5702]: fatal: Access denied for user drzeus by PAM account configuration

As an admin, it would be very helpful to be able to see why a user was turned away.

(might also affect ticket #673 and #674)


Fields changed

component: LDAP Provider => PAM
milestone: NEEDS_TRIAGE => SSSD 1.5.1
owner: somebody => sbose
tests: 0 => 1

Fields changed

status: new => assigned

Fixed by 6742203fd84e97822cdddc4065402c15f3c5703f and e1522a568dac91499f5f2039ef978a0a4ceeb3b3

resolution: => fixed
status: assigned => closed

Confirmed working for both service and shadow.

upgrade: => 0

Fields changed

rhbz: => 0

Metadata Update from @ossman:
- Issue assigned to sbose
- Issue set to the milestone: SSSD 1.5.1

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/1793

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata