See https://github.com/SSSD/sssd/issues/5905 for the original issue.
RHEL 8 uses SSSD 2.9.4 which is impacted by the above bug. This is problematic in virtual desktop environments where smart cards can be passed indiscriminately (e.g. Windows Hello, see Amazon DCV) leaving GDM login broken because SSSD won't iterate past the first (usually incorrect) smart card certificate.
The working patch (along with the RHEL 8.10 rpm build and spec) is available here: https://nextcloud.reeseapps.com/s/pZpbemzX57KF4yk
- is related to
-
RHEL-4976 [RFE] Continue searching other PKCS#11 tokens if certificates are not found
-
- Release Pending
-