Set Default Login Shell on SSSD for AD trust users using FreeIPA

(: June 21, 2019)

The IPA Identity Management server provides bidirectional user identity and password synchronization with Microsoft Active Directory. But after the configuration of IPA and Active Directory, the default shell for users is /bin/sh. This guide will discuss how you can change the default shell for AD trust users on FreeIPA client so that all users can enjoy better shell environments such as bash and zsh.

I assume you have installed and configured both FreeIPA server and Client. Our guides below should be helpful.

How to install FreeIPA server on Ubuntu / CentOS 7 / RHEL 8.

.td_uid_2_5d9088b43a9cb_rand.td-a-rec-img{text-align:left}.td_uid_2_5d9088b43a9cb_rand.td-a-rec-img img{margin:0 auto 0 0}

How to configure FreeIPA Client on CentOS 7 / Ubuntu/Debian / RHEL/CentOS 8

Change default Shell on SSSD

The System Security Services Daemon (SSSD) is a system service to access remote directories and authentication mechanisms. It connects a local system (an SSSD client) to an external back-end system (a domain). We will edit the SSSD client configuration file /etc/sssd/sssd.conf and define default shell under DOMAIN section.

$ sudo vim /etc/sssd/sssd.conf
.......
default_shell = /bin/bash
override_shell = /bin/bash

See screenshot below.

After making the change, remove sssd cache and restart sssd service.

sudo rm -rf /var/lib/sss/db/*
sudo systemctl restart sssd

Check user on AD.

$ id ADSRV01\ipauser
uid=1426401131([email protected]) gid=1426401131([email protected]) groups=1426401131([email protected]),1426400513(domain [email protected]),915800006(ad_users)

Try to ssh as AD user.

$ ssh ipauser@[email protected]
Password: 
Creating home directory for [email protected]
Last login: Fri Jun 21 16:41:27 2019 from localhost

Check user login shell.

$ echo $SHELL
/bin/bash

You now have /bin/bash as default shell for all your AD users accessing Linux services via SSH.

.td_uid_4_5d9088b43abfa_rand.td-a-rec-img{text-align:left}.td_uid_4_5d9088b43abfa_rand.td-a-rec-img img{margin:0 auto 0 0}

Related posts

How To Install MySQL / MariaDB on Fedora 20

SXI ADMIN

Insurance Broker Marsh Working With IBM on Blockchain Platform

SXI ADMIN

IMF and World Bank Panel: Bitcoin Block Chain Could Boost Financial Inclusion

SXI ADMIN

Bank of Canada Deputy Governor: Cooperation Needed to Advance Distributed Ledgers

SXI ADMIN

ViaBTC Rises: How A Mysterious Miner Could Decide Bitcoin’s Future

SXI ADMIN

Linux delete user command

SXI ADMIN

rpmbuild: error: Installed (but unpackaged) file(s) found Solution

SXI ADMIN

The Crypto Market Is Down Over 50% from 2018 Highs

SXI ADMIN

Automatically Apply Coupons in Cart on WooCommerce

SXI ADMIN

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More