Project

General

Profile

Bug #9622

Changing admins membership does not replicate correctly to HA slave

Added by Brian Candler about 1 month ago. Updated 3 days ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
User manager
Target version:
-
Start date:
07/09/2019
Due date:
% Done:

0%

Estimated time:
Affected Version:
Affected Architecture:

Description

To reproduce, on a pfSense 2.4.4-3 HA cluster

  • On the master: create a user which is not a member of the "admins" group
    - it is created on both master and slave with /sbin/nologin as the shell in /etc/passwd, and *LOCKED* in /etc/master.passwd
  • On the master: move the user into the "admins" group and save
    - on the master, the account works as expected
    - however on the slave, the shell remains as /sbin/nologin and *LOCKED* remains in /etc/master.passwd
    - as a result, the user cannot get a shell login on the slave

WORKAROUND: Delete and recreate the user with the admins group membership. But beware: this leaves the /home/USER/.ssh directory on the slave owned by the old UID, so you need to manually chown it to the new UID.

History

#1 Updated by Jim Pingle 3 days ago

  • Category set to User manager

Also available in: Atom PDF