Hello Dominick.

On Tue, Jul 22, 2025 at 09:42:59AM +0200, Dominick Grift 
<dominick.gr...@defensec.nl> wrote:
> 
> From what I understand the sd-pam process is responsible for "PAM
> close" but it cannot do its job properly if it does not have privileges.

AFAICS, sd-pam should drop privs to User= of the service.

> should sd-pam always run as root?

Which service's sd-pam do you refer to?
What's your systemd version?

Thanks,
Michal

Attachment: signature.asc
Description: PGP signature

Reply via email to