* [PVE-User] Host console access with realm different from PAM
@ 2023-03-23 10:30 Mariusz Suchodolski
2023-03-27 11:35 ` Thomas Lamprecht
0 siblings, 1 reply; 2+ messages in thread
From: Mariusz Suchodolski @ 2023-03-23 10:30 UTC (permalink / raw)
To: pve-user
Hello,
Is custom realm <-> pam mapping in plans?
We've setup Azure AD authentication but attempting to connect to one of the
virtualization hosts yields the following message when attempting to access
console:
Connection failed (Error 403: Permission check failed (realm aad ! = pam) )
MS.
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PVE-User] Host console access with realm different from PAM
2023-03-23 10:30 [PVE-User] Host console access with realm different from PAM Mariusz Suchodolski
@ 2023-03-27 11:35 ` Thomas Lamprecht
0 siblings, 0 replies; 2+ messages in thread
From: Thomas Lamprecht @ 2023-03-27 11:35 UTC (permalink / raw)
To: Proxmox VE user list, Mariusz Suchodolski
Hi,
Am 23/03/2023 um 11:30 schrieb Mariusz Suchodolski:
> Is custom realm <-> pam mapping in plans?
Not sure what you mean here exactly..
>
> We've setup Azure AD authentication but attempting to connect to one of the
> virtualization hosts yields the following message when attempting to access
> console:
>
> Connection failed (Error 403: Permission check failed (realm aad ! = pam) )
Yeah, this is a bit of an odd virtual limitations, and I'd be open to drop
those is-realm-pam checks completely; having Sys.Console and password of a
system user (root, or some ldap exposed system user) for login into the shell
is really enough.
As we try to avoid doing ACL changes with potential implications on a rolling
package update, I'd prefer doing this on the next major release, e.g. PVE 8.0
this year; as there we can add a more prominent entry in the changelogs "noteable
changes" section.
I checked quickly, but it doesn't seem we have a request for this logged in our
bugzilla (#2170 is sounding close but effectively wants something different), so
you could open a enhancement request to keep track of this at:
https://bugzilla.proxmox.com/
- Thomas
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2023-03-27 11:35 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-03-23 10:30 [PVE-User] Host console access with realm different from PAM Mariusz Suchodolski
2023-03-27 11:35 ` Thomas Lamprecht
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal