On Tue, Nov 15, 2016 at 02:26:12PM -0500, Chris Laprise wrote:
> On 11/15/2016 07:20 AM, Unman wrote:
> >On Tue, Nov 15, 2016 at 11:55:13AM +0000, Unman wrote:
> >>On Tue, Nov 15, 2016 at 05:53:56AM -0500, Chris Laprise wrote:
> >>>Following the instructions for the 'vm-sudo' doc, I get the following error
> >>>in Debian 9:
> >>>
> >>>/usr/lib/qubes/qrexec-client-vm failed: exit code 1
> >>>sudo: PAM authentication error: System error
> >>>
> >>>
> >>>Also, in the Debian 8 template the instructions don't match, as there
> >>>appears to be no file '/etc/pam.d/common-auth'.
> >>>
> >>>Chris
> >>>
> >>Where did you get that template? The file is present in the default 3.2,
> >>and even in a minimal-no-recommends template for Debian-8.
> >>
> >>I'll look at the Debian-9 issue now.
> >>
> >I'm afraid I don't see this issue in a Debian-9 template.
> >Can you check your editing?
> >
> >Also, try manually running the qrexec-client-vm dom0 qubes.VMAuth
> >command, and making sure you get the expected output.
> >You should see the prompt(from the policy) and then  output from dom0.
> >
> >unman
> >
> 
> Thanks for checking. However, I triple-checked my editing in Debian 9 and
> Debian 8 template is 'stock' basically nothing added to it.
> 
> The qubes.VMAuth request said 'Request refused'. The doc appears to have a
> typo for the second command in Step 1. "Adding Dom0 “VMAuth” service" that
> causes '$anyvm' to disappear from the output. This line should use single
> quotes instead.
> 
> Chris

You're right about that typo. Once you fixed it what happened?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20161115210433.GA24354%40thirdeyesecurity.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to