TigerVNC / tigervnc

High performance, multi-platform VNC client and server
https://tigervnc.org
GNU General Public License v2.0
4.85k stars 907 forks source link

CentOS8 TigerVNC 1.13.1 can not set service with AD user #1765

Open stormanger opened 2 weeks ago

stormanger commented 2 weeks ago

OS: CentOS8, AD user auth with sssd $ cat vncserver-config-defaults session=gnome geometry=1920x1080

$ cat vncserver.users :1=emu ##system local user :10=zcwan ##AD user

Local user works fine $ systemctl status vncserver@:1 ● vncserver@:1.service - Remote desktop service (VNC) Loaded: loaded (/usr/lib/systemd/system/vncserver@.service; disabled; vendor preset: disabled) Active: active (running) since Sun 2024-06-16 16:24:45 CST; 2s ago Process: 1133402 ExecStart=/usr/libexec/vncsession-start :1 (code=exited, status=0/SUCCESS) Main PID: 1133409 (vncsession) Tasks: 0 (limit: 3297192) Memory: 2.4M CGroup: /system.slice/system-vncserver.slice/vncserver@:1.service ‣ 1133409 /usr/sbin/vncsession emu :1

Jun 16 16:24:45 velhost4.iluvatar.local systemd[1]: Starting Remote desktop service (VNC)... Jun 16 16:24:45 velhost4.iluvatar.local systemd[1]: Started Remote desktop service (VNC).

AD user can not start service $ systemctl status vncserver@:10 ● vncserver@:10.service - Remote desktop service (VNC) Loaded: loaded (/usr/lib/systemd/system/vncserver@.service; enabled; vendor preset: disabled) Active: inactive (dead) since Sun 2024-06-16 16:10:06 CST; 16min ago Process: 1133003 ExecStart=/usr/libexec/vncsession-start :10 (code=exited, status=0/SUCCESS) Main PID: 1133010 (code=exited, status=0/SUCCESS)

Jun 16 16:10:06 velhost4.iluvatar.local systemd[1]: Starting Remote desktop service (VNC)... Jun 16 16:10:06 velhost4.iluvatar.local systemd[1]: Started Remote desktop service (VNC). Jun 16 16:10:06 velhost4.iluvatar.local systemd[1]: vncserver@:10.service: Succeeded.

$ id zcwan uid=469401628(zcwan) gid=469400513(domain users) groups=469400513(domain users)

CendioOssman commented 2 weeks ago

Please fill out the issue template properly so we can better understand your setup.

Do you have a log file in ~/.vnc for the failing user?