SSSD加入Windows域的Ubuntu 16.04用户无GUI权限问题求助
Hey there, I’ve run into this exact problem a few times with Ubuntu 16.04 systems joined to Active Directory via SSSD/realmd. The terminal works fine with sudo, but GUI tools like system settings, user management, and Ubuntu Software Center throw permission errors or just won’t let you make changes. Let’s break down the fixes step by step:
1. Fix Polkit Permissions (Most Likely Culprit)
Most Ubuntu GUI admin tools rely on polkit to grant elevated access, and by default, domain users aren’t included in these rules. Here’s how to fix it:
- Create a local polkit rule file:
sudo nano /etc/polkit-1/localauthority/50-local.d/50-ad-admin.pkla - Paste this content (since you’ve already added your domain users to the
sudogroup, this rule lets all sudo members access GUI admin tools):[Allow AD Administrators Full System Access] Identity=unix-group:sudo Action=* ResultActive=yes ResultInactive=yes ResultAny=yes - Save the file (Ctrl+O, Enter, then Ctrl+X) and reboot your system to apply the changes.
2. Verify Home Directory Permissions
Sometimes domain user home directories get incorrect permissions during the first login, which breaks GUI-related files:
- Check the permissions of your domain user’s home folder:
ls -ld /home/<your-domain-username> - You should see the owner as
<your-domain-username>:<your-domain-group>. If not, fix it with:sudo chown -R <your-domain-username>:<your-domain-group> /home/<your-domain-username> - Also, delete the
.Xauthorityfile in the home directory (it controls X11 session permissions) and log out/in:rm /home/<your-domain-username>/.Xauthority
3. Tweak SSSD Configuration for Desktop Compatibility
Make sure SSSD is properly setting shell and home directory paths for domain users, which helps the desktop environment recognize the user correctly:
- Edit the SSSD config file:
sudo nano /etc/sssd/sssd.conf - In the
[domain/<your-domain-name>]section, add or ensure these lines exist:override_shell = /bin/bash override_homedir = /home/%u default_shell = /bin/bash homedir_substring = /home - Save the file and restart SSSD:
sudo systemctl restart sssd
4. Add Domain Users to the admin Group
Ubuntu’s Software Center and some system settings tools explicitly check for membership in the admin group. Add your domain user to it:
sudo usermod -aG admin <your-domain-username>
5. Test LightDM Configuration (Unity Desktop)
If you’re using the default Unity desktop, the LightDM display manager might need a small tweak to handle domain users properly:
- Edit the LightDM config:
sudo nano /etc/lightdm/lightdm.conf - Add these lines under the
[Seat:*]section:greeter-show-manual-login=true allow-guest=false - Restart LightDM (this will log you out immediately):
sudo systemctl restart lightdm
After trying these steps, log back in with your domain user and test the GUI tools—they should work as expected now.
内容的提问来源于stack exchange,提问作者AMACOMX

