[Freedombox-pkg-team] Bug#1146448: freedombox: Unable to add users - LDAP password does not work - unable to add SSH public keys
Walter Eaves
n.francis.bonaparte at gmail.com
Wed Sep 2 01:56:41 BST 2026
Package: freedombox
Version: 26.11.1~bpo13+1
Severity: normal
Dear Maintainer,
I'm installed freedombox in a systemd container. Networking is managed by systemd.network
with NetworkManager configured to ignore all the interfaces. I needed to install btrfs-progs.
I was then able to access the https://cass.6site0/freedombox URL and paste in my secret.
I entered an account called owner and gave it a password. I performed an upgrade.
I then tried to add some SSH keys and add a user. I received
some failure messages from the plinth logs.
Sep 01 18:18:13 cass freedombox[171]: » ssh..set_keys("owner", "", "owner", ****)
Sep 01 18:18:13 cass freedombox[171]: Error running action ssh..set_keys("owner", "", "owner", ****): Permissi
onError("Invalid credentials")
Action traceback:
╞ File "/usr/lib/python3/dist-packages/plinth/actions.py", line 501, i
n _privileged_call
╞ return_values = func(*arguments['args'], **arguments['kwargs'])
╞ File "/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.p
y", line 98, in set_keys
╞ _validate_user(auth_user, auth_password, must_be_admin=must_be_adm
in)
╞ ~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
^^^
╞ File "/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.py", line 32, in _validate_user
╞ raise PermissionError('Invalid credentials')
Sep 01 18:18:14 cass freedombox[171]: GET /sys/users/owner/edit/
I may have incorrectly entered the owner password in that one, but later
Sep 01 18:18:14 cass freedombox[171]: GET /sys/users/owner/edit/
Sep 01 18:18:14 cass freedombox[171]: » ssh..get_keys("owner")
Sep 01 18:18:14 cass freedombox[171]: » users..get_group_users("admin")
Sep 01 18:20:25 cass freedombox[171]: POST /sys/users/owner/edit/
Sep 01 18:20:25 cass freedombox[171]: » ssh..get_keys("owner")
Sep 01 18:20:25 cass freedombox[171]: » users..get_group_users("admin")
Sep 01 18:20:25 cass freedombox[171]: » users..get_user_groups("owner")
Sep 01 18:20:25 cass freedombox[171]: » ssh..set_keys("owner", "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJY8q6TDObPW524Vna/2UT6PBgV05nD5n77D+mbyVAnW weaves-elliptic", "owner", ****)
Sep 01 18:20:25 cass freedombox[171]: Error running action ssh..set_keys("owner", "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJY8q6TDObPW524Vna/2UT6PBgV05nD5n77D+mbyVAnW weaves-elliptic", "owner", ****): PermissionError("Invalid credentials")
Action traceback:
╞ File "/usr/lib/python3/dist-packages/plinth/actions.py", line 501, in _privileged_call
╞ return_values = func(*arguments['args'], **arguments['kwargs'])
╞ File "/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.py", line 98, in set_keys
╞ _validate_user(auth_user, auth_password, must_be_admin=must_be_admin)
╞ ~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
╞ File "/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.py", line 32, in _validate_user
╞ raise PermissionError('Invalid credentials')
Sep 01 18:20:25 cass freedombox[171]: GET /sys/users/owner/edit/
In that one, I may have gotten further. I did manage to get the notification that the Authorization Password
worked, but something else failed.
I suspected that the LDAP password wasn't working because most of the error were invalid credentials after an
LDAP operation.
I went out to the OS command line and tried to change the password of the only account in LDAP the owner
account. And the LDAP password I entered during the LDAP/nslcd installation didn't work.
The /etc/nslcd.conf file looks incomplete:
# The DN to bind with for normal lookups.
#binddn cn=annonymous,dc=example,dc=net
#bindpw secret
# The DN used for password modifications by root.
#rootpwmoddn cn=admin,dc=example,dc=com
Despite trying to create two users - neither appeared on the file system.
So I think it is a broken distribution. There's something wrong with the linkage between plinth and
the LDAP.
-- System Information:
Debian Release: 13.6
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 6.12.107+deb13-amd64 (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_USER
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
Versions of packages freedombox depends on:
ii apache2 2.4.68-1~deb13u1
ii augeas-tools 1.14.1-1.1~deb13u1
ii avahi-daemon 0.8-16
ii avahi-utils 0.8-16
ii batctl 2025.0-2
ii bind9-dnsutils 1:9.20.26-1~deb13u1
ii borgbackup 1.4.0-5
ii certbot 4.0.0-2+deb13u1
ii cockpit 337-1+deb13u2
ii curl 8.14.1-2+deb13u4
ii debconf 1.5.91
ii debsecan 0.4.20.1
ii fail2ban 1.1.0-8
ii firewalld 2.3.1-1+deb13u1
ii fuse3 3.17.2-3
ii gdisk 1.0.10-2
ii gettext 0.23.1-2
ii gir1.2-glib-2.0 2.84.4-3~deb13u3
ii gir1.2-nm-1.0 1.52.1-1
ii gir1.2-udisks-2.0 2.10.1-12.1+deb13u2
ii gpg 2.4.7-21+deb13u1+b4
ii iproute2 6.15.0-1
ii javascript-common 12+nmu1
ii ldap-utils 2.6.10+dfsg-1
ii ldapscripts 2.0.8-2
ii libapache2-mod-auth-openidc 2.4.17-1
ii libglib2.0-bin 2.84.4-3~deb13u3
ii libjs-bootstrap5 5.3.5+dfsg-4
ii libjs-htmx 2.0.4-1
ii libnss-ldapd 0.9.13-1
ii libpam-ldapd 0.9.13-1
ii lsof 4.99.4+dfsg-2
ii needrestart 3.11-1
ii netcat-openbsd 1.229-1
ii network-manager 1.52.1-1
ii nftables 1.1.3-1
ii node-popper2 2.11.2-8
ii nslcd 0.9.13-1
ii openssh-server 1:10.0p1-7+deb13u4
ii openssl 3.5.7-1~deb13u2
ii parted 3.6-5
ii php-fpm 2:8.4+96
ii php8.4-fpm [php-fpm] 8.4.24-1~deb13u1
ii popularity-contest 1.78
ii ppp 2.5.2-1+1
ii pppoe 4.0-1
ii python3 3.13.5-1
ii python3-apt 3.0.0
ii python3-argon2 21.1.0-3
ii python3-augeas 1.2.0-1
ii python3-bootstrapform 3.4-9
ii python3-cherrypy3 18.10.0-1
ii python3-configobj 5.0.9-1
ii python3-dbus 1.4.0-1
ii python3-django 3:4.2.28-0+deb13u2
ii python3-django-axes 5.39.0-6
ii python3-django-bootstrapform 3.4-9
ii python3-django-captcha 0.6.2-1
ii python3-django-ipware 4.0.2-1
ii python3-django-oauth-toolkit 3.0.1-1
ii python3-django-stronghold 0.4.0+debian-2
ii python3-fido2 1.2.0-2
ii python3-gi 3.50.0-4+b1
ii python3-markupsafe 2.1.5-1+b3
ii python3-pampy 2.0.2-3
ii python3-pexpect 4.9-3
ii python3-psutil 7.0.0-2
ii python3-requests 2.32.3+dfsg-5+deb13u1
ii python3-ruamel.yaml 0.18.10+ds-1
ii python3-systemd 235-1+b6
ii python3-yaml 6.0.2-1+b2
ii samba-common-bin 2:4.22.10+dfsg-0+deb13u2
ii slapd 2.6.10+dfsg-1
ii snapper 0.10.6-1.2
ii sshfs 3.7.3-1.2~deb13u1
ii sshpass 1.10-0.1
ii ssl-cert 1.1.3
ii sudo 1.9.16p2-3+deb13u2
ii systemd [systemd-sysusers] 257.13-1~deb13u1
ii systemd-timesyncd 257.13-1~deb13u1
ii tdb-tools 2:1.4.13+samba4.22.10+dfsg-0+deb13u2
ii udisks2 2.10.1-12.1+deb13u2
ii unattended-upgrades 2.12
ii wget 1.25.0-2
ii zram-tools 0.3.7-1
Versions of packages freedombox recommends:
ii e2fsprogs 1.47.2-3+b11
ii firmware-ath9k-htc 1.4.0-110-ge888634+dfsg1-0.1
ii freedombox-doc-en 26.11.1~bpo13+1
ii freedombox-doc-es 26.11.1~bpo13+1
ii libnss-mdns 0.15.1-4+b1
ii libnss-myhostname 257.13-1~deb13u1
ii locales 2.41-12+deb13u3
ii locales-all 2.41-12+deb13u3
ii openssh-client 1:10.0p1-7+deb13u4
ii powermgmt-base 1.38
ii psmisc 23.7-2
freedombox suggests no packages.
-- no debconf information
More information about the Freedombox-pkg-team
mailing list