/srv/irclogs.ubuntu.com/2024/01/26/#ubuntu-security.txt

=== NotEickmeyer is now known as Eickmeyer
lunaamurray: when is the first episode of 2024 planned to be released of the podcast?05:03
=== JanC is now known as Guest2655
=== JanC_ is now known as JanC
Apparmortastichey, i am trying to use libnss-resolve, when I `aa-disable ping` then i can resolve things using libnss-resolve because i can access the socket `/run/systemd/resolve/io.systemd.Resolve` but if i do `aa-complain ping` or `aa-enforce ping` i can not, why would complain block access and why is /run/systemd/resolve/io.systemd.Resolve blocked to begin16:36
Apparmortasticwith16:36
Apparmortasticthe only log entry relevant is this one, seemingly allowing the connection16:36
Apparmortasticapparmor="ALLOWED" operation="connect" info="Failed name lookup - disconnected path" error=-13 profile="ping" name="run/systemd/resolve/io.systemd.Resolve" pid=2450 comm="ping" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=10216:36
Apparmortasticbut if i aa-disable, no worries, works fine16:36
georgiagApparmortastic: the socket must be in a different namespace than the process trying to access it. to enable permission to do this, you need to add flags=(attach_disconnected) in the ping profile17:10
KarlG100Greetings, have a sanity check question.18:15
KarlG100I'm working on deploying smartcard enfocement on 22.04, and running into what I think is a pam_sss bug.18:15
KarlG100when require_cert_auth is added to the pam_sss.so line all methods of logging in seem to work and reject password based auth, except ssh.18:16
KarlG100does anyone know/tracking any issues in the stock pam_sss with the require_cert_auth and rejecting password based auth?18:17
=== user03 is now known as gchound

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!