URL: https://github.com/SSSD/sssd/pull/268
Title: #268: pam_sss: add support for SSS_PAM_CERT_INFO_WITH_HINT

sumit-bose commented:
"""
>Is there a technical reason sssd cannot discover what to do without 
>allow_missing_name option to pam_sss? I'd prefer to avoid modifying PAM config 
>files...

Recent version of authconfig will do the modifications for you and you have to 
do the change becasue by default pam_pkcs11 will be in the PAM configuration 
(but this might change in future).

The reason for the option is that by default a missing user name is unexpteded 
and the pam module will prompt for since in most cases the user name cannot be 
derived by the other credentials given by the user.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/268#issuecomment-300713713
_______________________________________________
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org

Reply via email to