Elevated Prompted Authentication Fails Fedora 23 SSSD Active Directory Accounts Wheel Group

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Title: Untitled Document

Hi All,

 

I have a few Fedora 23 box’s joined to an AD domain using SSSD. The AD admin users in the local default admin group wheel for these computers.

Login and using sudo in terminal is not an issue. However, any gnome GUI interface which requires elevation prompt to enter their admin password fails with a message like "Authentication failure, please try again."

Two of these  Fedora 23 desktops are clean builds and fully up to date with selinux disabled.

Error Logs

 

polkit-agent-he
pam_sss(polkit-1:auth): authentication success; logname= uid=5000 euid=0 tty= ruser=ADUSER rhost= user=ADUSER

USER_AUTH pid=11713 uid=5000 auid=5000 ses=4 msg='op=PAM:authentication grantors=pam_succeed_if,pam_sss acct="ADUSER" exe="/usr/lib/polkit-1/polkit-agent-helper-1" hostname=? addr=? terminal=? res=success'

GNOME Shell
polkit-agent-helper-1: pam_acct_mgmt failed: Permission denied

polkitd
Operator of unix-session:4 FAILED to authenticate to gain authorization for action org.opensuse.cupspkhelper.mechanism.all-edit for unix-process:10511:6995429 [gnome-control-center printers] (owned by unix-user:ADUSER)

dbus-daemon
(gnome-control-center:10511): Gtk-WARNING **: Error acquiring permission: User dismissed authentication dialog while trying to acquire permission for action-id org.opensuse.cupspkhelper.mechanism.all-edit

 

 

Has anybody seen something like this before or have hints/solution to resolve the issue. I am happy provide any additional information as required.


Thanks for your help

 

Steve

 




The information in this email is confidential and may be legally privileged. It is intended solely for the addressee. If you receive this email by mistake, please notify the sender and delete it immediately. Opinions expressed are those of the individual and do not necessarily represent the opinion of the University of Cambridge.

 

-- 
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines
Have a question? Ask away: http://ask.fedoraproject.org
[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [EPEL Devel]     [Fedora Magazine]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Desktop]     [Fedora Fonts]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Fedora Sparc]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux