[Freedombox-pkg-team] Bug#1146448: Bug#1146448: freedombox: Unable to add users - LDAP password does not work - unable to add SSH public keys

Sunil Mohan Adapa sunil at medhas.org
Wed Sep 2 04:31:52 BST 2026


On 9/1/26 17:56, Walter Eaves wrote:
> Package: freedombox
> Version: 26.11.1~bpo13+1
> Severity: normal
> 
> Dear Maintainer,
> 
> I'm installed freedombox in a systemd container. 

This is typically not supported and not well tested.  However, it would 
be a welcome change to fix any bugs and document running in a container. 
  We *do* development using systemd-nspawn.  So, it should not be too hard.

Some notes about how the nspawn container should be run:

- Boot=yes (this is needed so that systemd is started in the container, 
this is a requirement for running other daemons etc.)

- VirtualEthernet=yes (if the container has no separate network name 
space, then listening on some ports may not be possible due to 
privileges and clashes)

- PrivateUsers=no (since root privileges are used by FreedomBox, I am 
not sure what functions would fail without this)

- Container should be setup such that FreedomBox can create and manage 
containers within the container.  This is needed for some optional apps. 
In development we simply do SystemCallFilter=@known.

> Networking is managed by systemd.network
> with NetworkManager configured to ignore all the interfaces.

This should be fine.  However, firewalld will assign all interfaces as 
"external" interfaces.

> I needed to install btrfs-progs.

I wonder why that was needed.  We can fix this.

> 
> I was then able to access the https://cass.6site0/freedombox URL and paste in my secret.
> I entered an account called owner and gave it a password. I performed an upgrade.
 >

If things have progressed this far, it is likely some of the important 
conditions listed above must have been met.

> I then tried to add some SSH keys and add a user. I received
> some failure messages from the plinth logs.
> 
[...]
>                                        ╞   File "/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.py", line 32, in _validate_user
[...]
>                                        ╞   File "/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.py", line 32, in _validate_user
> 
>                                        ╞     raise PermissionError('Invalid credentials')
[...]

This is failing with validation of username and password pair.  For this 
to work password must be the password of the user who is modifying the 
account or password of the admin user modifying the account. In your 
case this must be the password for the "owner" user.

What's failing is this:

import pam
pam_authenticator = pam.pam()
pam_authenticator.authenticate("owner", "owner'spassword")

Are the slapd and nslcd services running?

systemctl status slapd.service
systemctl status nslcd.service

What happens if you try to 'su -' into this account from a non-admin 
account.

(non-admin user)$ su - owner
Password: (type the password you provided in the web form for editing 
the SSH keys)

What happens if you try this:

(admin user)# id owner

Output should be like:
uid=10001(owner) gid=100(users) groups=100(users),10002(admin)

(admin user)# getent passwd owner

Output should be like:
owner:*:10001:100:tester:/home/owner:/bin/bash

> In that one,  I may have gotten further. I did manage to get the notification that the Authorization Password
> worked, but something else failed.
> 
> I suspected that the LDAP password wasn't working because most of the error were invalid credentials after an
> LDAP operation.
> 
> I went out to the OS command line and tried to change the password of the only account in LDAP the owner
> account. And the LDAP password I entered during the LDAP/nslcd installation didn't work.
 > > The /etc/nslcd.conf file looks incomplete:
> 
> # The DN to bind with for normal lookups.
> #binddn cn=annonymous,dc=example,dc=net
> #bindpw secret
>   
> # The DN used for password modifications by root.
> #rootpwmoddn cn=admin,dc=example,dc=com
> 

The LDAP password entered during the installation of slapd package is 
not used by FreedomBox at all.  FreedomBox uses a different 
authentication mechanism with slapd that verifies admin privileges and 
skips asking for admin password.  That password also has no relationship 
with the password entered in the web interface for authorizing user 
operations.

> Despite trying to create two users - neither appeared on the file system.
> 
> So I think it is a broken distribution. There's something wrong with the linkage between plinth and
> the LDAP.

If you wish to change the password for the user and the web interface 
does not work, then try the 'freedombox-change-password' command like this:

# freedombox-change-password owner

Hope this helps,

-- 
Sunil


More information about the Freedombox-pkg-team mailing list