[pkg-apparmor] Bug#1144467: Resolving ldap users via nslcd fails due to disconnected path of its socket
pelzi at flying-snail.de
pelzi at flying-snail.de
Sat Aug 15 13:48:56 BST 2026
Package: apparmor
Version: 4.1.0-1
PAM authentication of a user provided via LDAP fails depending on the
context from where the authentication is attempted, e. g. from an
invocation of sudo, or from sshd when attempting to log in remotely. The
same operation succeeds later (possibly once the user is present in nslcd?).
The following apparmor audit logs appear:
audit: type=1400 audit(1786343451.048:532): apparmor="ALLOWED"
operation="file_perm" class="file" info="Failed name lookup -
disconnected path" error=-13 profile="unix-chkpwd"
name="run/nslcd/socket" pid=1075132 comm="unix_chkpwd"
requested_mask="r" denied_mask="r" fsuid=0 ouid=112
audit: type=1400 audit(1786343451.048:533): apparmor="ALLOWED"
operation="file_perm" class="file" info="Failed name lookup -
disconnected path" error=-13 profile="unix-chkpwd"
name="run/nslcd/socket" pid=1075132 comm="unix_chkpwd"
requested_mask="r" denied_mask="r" fsuid=0 ouid=112
Further related log messages:
authpriv,err,unix_chkpwd[2904664]: could not obtain user info (someuser)
auth,crit,sshd-session[2904662]: fatal: Access denied for user someuser
by PAM account configuration [preauth]
Kernel 7.1.3+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 7.1.3-1~bpo13+1
(2026-07-12) x86_64 GNU/Linux
nscd 2.41-12+deb13u3
nslcd 0.9.13-1
libpam-modules-bin 1.7.0-5
It seems that this can be cured by adding the attach_disconnected.path
flag to the unix_chkpwd profile giving a distinguishable path like
/att/chkpwd
and adding access to that
/att/chkpwd/run/nslcd/socket
in the chkpwd profile (alternatively, do similar using the
abstraction/ldapclient?).
More information about the pkg-apparmor-team
mailing list