GDM hangs when system is configured with sssd for AD authentication, unable to login graphically (GUI)

Solution Verified - Updated -

Issue

  • GDM hangs after configuring system with sssd for AD auhentication, AD login fails
  • GDM fails to start in runlevel 5 and unable to login as AD user via sssd. /var/log/secure shows:
Nov  5 17:30:37 server-01 gdm-launch-environment]: pam_sss(gdm-launch-environment:account): Access denied for user gdm: 10 (User not known to the underlying authentication module)
...
Nov  5 17:31:09 server-01 gdm-password]: pam_unix(gdm-password:auth): check pass; user unknown
Nov  5 17:31:09 server-01 gdm-password]: pam_unix(gdm-password:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Nov  5 17:31:09 server-01 gdm-password]: pam_sss(gdm-password:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=ad_user01
Nov  5 17:31:09 server-01 gdm-password]: pam_sss(gdm-password:auth): received for user ad_user01: 10 (User not known to the underlying authentication module)
Nov  5 17:31:09 server-01 gdm-password]: gkr-pam: error looking up user information
...
Nov  5 17:32:55 server-01 gdm-launch-environment]: pam_sss(gdm-launch-environment:account): Access denied for user gdm: 10 (User not known to the underlying authentication module)
...
Nov  5 17:36:23 server-01 gdm-launch-environment]: pam_sss(gdm-launch-environment:account): Request to sssd failed. Connection refused
  • Everything runs perfect in runlevel 3. On commenting 'pam_sss.so' from 'account' section of PAM, GDM seems to load but login fails. Everything works perfect if you start system in runlevel 3 and so 'startx'

Environment

  • Red Hat Enterprise Linux 7.x
  • gdm
  • pam
  • sssd

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content