Summary: | Не применяются переменные окружения через групповые политики (домен Windows Server 2019) | ||
---|---|---|---|
Product: | Sisyphus | Reporter: | Белая Алёна <belayaav> |
Component: | gpupdate | Assignee: | Valery Sinelnikov <greh> |
Status: | NEW --- | QA Contact: | qa-sisyphus |
Severity: | normal | ||
Priority: | P5 | CC: | glinkinvd, greh, nir, sin |
Version: | unstable | ||
Hardware: | x86_64 | ||
OS: | Linux |
Description
Белая Алёна
2024-11-27 15:50:50 MSK
Версия: gpupdate-0.13.2-alt1 Поскольку ключи прилетают, а /etc/gpupdate/environment и .gpupdate_environment настроены, то всё выглядит так, будто /etc/pam.d/system-policy-gpupdate - кривой. #%PAM-1.0 session [success=2 perm_denied=ignore default=die] pam_localuser.so session substack gpupdate-remote-policy session [default=1] pam_permit.so session [default=7] pam_permit.so session [success=1 default=ignore] pam_succeed_if.so user ingroup users quiet session [default=5] pam_permit.so session [success=1 default=ignore] pam_succeed_if.so uid >= 500 quiet session [default=3] pam_permit.so session [success=1 default=ignore] pam_succeed_if.so service = systemd-user quiet -session required pam_oddjob_gpupdate.so session optional pam_env.so user_readenv=1 conffile=/etc/gpupdate/environment user_envfile=.gpupdate_environment session required pam_permit.so Как минимум, pam_env.so настроен не по man'у: OPTIONS conffile=/path/to/pam_env.conf Indicate an alternative pam_env.conf style configuration file to override the default. This can be useful when different services need different environments. debug A lot of debug information is printed with syslog(3). envfile=/path/to/environment Indicate an alternative environment file to override the default. The syntax are simple KEY=VAL pairs on separate lines. The export instruction can be specified for bash compatibility, but will be ignored. This can be useful when different services need different environments. readenv=0|1 Turns on or off the reading of the file specified by envfile (0 is off, 1 is on). By default this option is on. user_envfile=filename Indicate an alternative .pam_environment file to override the default. The syntax is the same as for /etc/security/pam_env.conf. The filename is relative to the user home directory. This can be useful when different services need different environments. user_readenv=0|1 Turns on or off the reading of the user specific environment file. 0 is off, 1 is on. By default this option is off as user supplied environment variables in the PAM environment could affect behavior of subsequent modules in the stack without the consent of the system administrator. Due to problematic security this functionality is deprecated since the 1.5.0 version and will be removed completely at some point in the future. FILES /etc/security/pam_env.conf Default configuration file /etc/environment Default environment file $HOME/.pam_environment User specific environment file Сейчас в исходниках /etc/gpupdate/environment настраивается аналогично .gpupdate_environment, хотя там синтаксис должен быть как в /etc/environment (KEY="VAL"). Если в /etc/gpupdate/environment привести синтаксис в порядок, а после в /etc/pam.d/lightdm для Workstation K или /etc/pam.d/lightdm для GNOME добавить -session required pam_env.so envfile=/etc/gpupdate/environment readenv=1 - то переменные будут получены. Также, хочу упомянуть о использовании pam_env.so и проблемах с переменными, определёнными в /etc/profile - https://bugzilla.altlinux.org/53948 (Ответ для Vladislav Glinkin на комментарий #1) > или /etc/pam.d/lightdm для GNOME /etc/pam.d/gdm-password* |