In /etc/krb5.conf.d/freeipa there is
[libdefaults] spake_preauth_groups = edwards25519
And in /var/lib/sss/pubconf/krb5.include.d there is the following
$ more /var/lib/sss/pubconf/krb5.include.d/*|cat :::::::::::::: /var/lib/sss/pubconf/krb5.include.d/domain_realm_ghs_nl :::::::::::::: [domain_realm] :::::::::::::: /var/lib/sss/pubconf/krb5.include.d/krb5_libdefaults :::::::::::::: [libdefaults] canonicalize = true :::::::::::::: /var/lib/sss/pubconf/krb5.include.d/localauth_plugin :::::::::::::: [plugins] localauth = { module = sssd:/usr/lib/x86_64-linux-gnu/sssd/modules/sssd_krb5_localauth_plugin.so }
In /etc/krb5. conf.d/ freeipa there is
[libdefaults] preauth_ groups = edwards25519
spake_
And in /var/lib/ sss/pubconf/ krb5.include. d there is the following
$ more /var/lib/ sss/pubconf/ krb5.include. d/*|cat sss/pubconf/ krb5.include. d/domain_ realm_ghs_ nl sss/pubconf/ krb5.include. d/krb5_ libdefaults sss/pubconf/ krb5.include. d/localauth_ plugin lib/x86_ 64-linux- gnu/sssd/ modules/ sssd_krb5_ localauth_ plugin. so
::::::::::::::
/var/lib/
::::::::::::::
[domain_realm]
::::::::::::::
/var/lib/
::::::::::::::
[libdefaults]
canonicalize = true
::::::::::::::
/var/lib/
::::::::::::::
[plugins]
localauth = {
module = sssd:/usr/
}