Issue: Stonking GDM not showing input password box after clicking return button at authentication mode selection
- Dominant language
- Go
- Stars
- 308
- Forks
- 41
- Avg merge
- 2d 4h
- Merged PRs (30d)
- 58
Description
### Is there an existing issue for this?
- [x] I have searched the existing issues and found none that matched mine
### Describe the issue
Context:
In GDM, when clicking on an authd user that was previously registered in the system, if the user chooses to click twice the return button (first time to land on authentication mode page and second time to try and go back to user list) they will not be able to get back to user lists. Moreover the navigation is now in a broken state since clicking on local broker will lead to a page with no input text box to insert the password
https://github.com/user-attachments/assets/3dd22580-29e3-49b4-a968-6129f968a394
### Steps to reproduce
1. Reboot machine
2. Select authd user
3. Click return button
4. After landing on authentication mode selection click again return button
5. The UI will not go back to user list and now click an authentication method will result into a broken state
### System information and logs
#### authd version
```
authd 0.6.4+git260902+1025+ef589ea3~26.10.1
```
#### authd-msentraid broker version
```
name: authd-msentraid
summary: Microsoft Entra ID authentication for Ubuntu
publisher: Canonical**
store-url: https://snapcraft.io/authd-msentraid
license: GPL-3.0
description: |
authd is a powerful authentication service for Ubuntu, designed to
integrate with cloud identity providers like Microsoft Entra ID. It
delivers a secure, flexible solution for organizations and individuals who
are transitioning to cloud-based identity management on Ubuntu workstations
and servers.
authd uses the OAuth Device Authorization Grant and ensures a consistent
and secure login experience across Ubuntu Desktop and Server — whether
through GDM, SSH, or network services like NFS and Samba.
Key Features
* Cloud identity provider Integration: Connects with Microsoft Entra ID
* Secure Login: authd leverages the OAuth Device Authorization Grant RFC
8628-compliant workflows for reliability and security.
* Open-Source: Free and community-driven, with contributions welcomed.
* Enterprise ready: Ubuntu Pro customers will benefit from the same
expanded security and support guarantees.
* authd is free for all Ubuntu Desktop and Server 24.04 LTS users and is
under active development. Explore the official documentation for
installation and configuration steps, or visit the GitHub repository to
contribute or provide feedback.
services:
authd-msentraid: dbus, enabled, active
snap-id: vS3oJLMss6lgWwoFcPqYDUA2HB20I1Dc
tracking: 0.x/edge
refresh-date: today at 15:08 UTC
channels:
0.x/stable: 0.4.1 2026-08-10 (397) 23.7MB -
0.x/candidate: 0.4.1+c9990dc.b62bfd3 2026-09-04 (458) 24.9MB -
0.x/beta: ^
0.x/edge: 0.4.1+4bdea7f.4e5e1e3 2026-09-11 (464) 24.9MB -
installed: 0.4.1+4bdea7f.4e5e1e3 (464) 24.9MB -
```
#### authd-google broker version
```
name: authd-google
summary: Google IAM authentication for Ubuntu
publisher: Canonical**
store-url: https://snapcraft.io/authd-google
license: GPL-3.0
description: |
authd is a powerful authentication service for Ubuntu, designed to
integrate with cloud identity providers like Google IAM. It delivers a
secure, flexible solution for organizations and individuals who are
transitioning to cloud-based identity management on Ubuntu workstations and
servers.
authd uses the OAuth Device Authorization Grant and ensures a consistent
and secure login experience across Ubuntu Desktop and Server — whether
through GDM, SSH, or network services like NFS and Samba.
Key Features
* Cloud identity provider Integration: Connects with Google IAM
* Secure Login: authd leverages the OAuth Device Authorization Grant RFC
8628-compliant workflows for reliability and security.
* Open-Source: Free and community-driven, with contributions welcomed.
* Enterprise ready: Ubuntu Pro customers will benefit from the same
expanded security and support guarantees.
* authd is free for all Ubuntu Desktop and Server 24.04 LTS users and is
under active development. Explore the official documentation for
installation and configuration steps, or visit the GitHub repository to
contribute or provide feedback.
services:
authd-google: dbus, enabled, active
snap-id: f3zksk8uLqRhkYqXcKwzZbu8c5esXlKU
tracking: 0.x/edge
refresh-date: today at 15:08 UTC
channels:
0.x/stable: 0.4.1 2026-06-18 (296) 9.8MB -
0.x/candidate: 0.4.1+5df8647.b62bfd3 2026-09-04 (362) 9.9MB -
0.x/beta: ^
0.x/edge: 0.4.1+60b85d2.4e5e1e3 2026-09-11 (369) 9.9MB -
installed: 0.4.1+60b85d2.4e5e1e3 (369) 9.9MB -
```
#### authd-oidc broker version
```
name: authd-oidc
summary: OIDC authentication for Ubuntu
publisher: Canonical**
store-url: https://snapcraft.io/authd-oidc
license: GPL-3.0
description: |
authd is a powerful authentication service for Ubuntu, designed to
integrate with OIDC identity providers.
It delivers a secure, flexible solution for organizations and individuals
who are transitioning
to cloud-based identity management on Ubuntu workstations and servers.
authd uses the OAuth Device Authorization Grant and ensures a consistent
and secure login experience across
Ubuntu Desktop and Server — whether through GDM, SSH, or network services
like NFS and Samba.
Key Features
* Cloud identity provider Integration: Connects with any OpenID Connect
compliant identity provider.
* Secure Login: authd leverages the OAuth Device Authorization Grant RFC
8628-compliant workflows for reliability
and security.
* Open-Source: Free and community-driven, with contributions welcomed.
* Enterprise ready: Ubuntu Pro customers will benefit from the same
expanded security and support guarantees.
* authd is free for all Ubuntu Desktop and Server 24.04 LTS users and is
under active development.
Explore the official documentation for installation and configuration
steps, or visit the GitHub repository to
contribute or provide feedback.
snap-id: ThhyM8S89MLMuxkjb35u3a3pa4KYd3Fb
channels:
0.x/stable: 0.4.1 2026-06-18 (89) 9.8MB -
0.x/candidate: 0.4.1+4587a39.b62bfd3 2026-09-04 (153) 9.8MB -
0.x/beta: ^
0.x/edge: 0.4.1+d6776e5.4e5e1e3 2026-09-11 (159) 9.8MB -
```
#### gnome-shell version
```
gnome-shell:
Installed: 51~beta-0ubuntu1
Candidate: 51~beta-0ubuntu1
Version table:
*** 51~beta-0ubuntu1 500
500 http://archive.ubuntu.com/ubuntu stonking/main amd64 Packages
100 /var/lib/dpkg/status
51~alpha-0ubuntu4+authd2~26.10.1 500
500 https://ppa.launchpadcontent.net/ubuntu-enterprise-desktop/authd-dev/ubuntu stonking/main amd64 Packages
```
#### Distribution
```
Distributor ID: Ubuntu
Description: Ubuntu Stonking Stingray (development branch)
Release: 26.10
Codename: stonking
```
#### Logs
```
[ 51.210452] ubuntu systemd[1]: Starting authd.service - authd daemon service...
[ 51.246933] ubuntu authd[3070]: No broker configuration found, using only the local broker.
[ 51.251665] ubuntu systemd[1]: Started authd.service - authd daemon service.
[ 76.105217] ubuntu systemd[1]: Starting snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google...
[ 76.346150] ubuntu authd-google[4868]: Version: 0.4.1+60b85d2.4e5e1e3
[ 76.346190] ubuntu authd-google[4868]: Debug mode is enabled
[ 76.347384] ubuntu authd-google[4868]: Initializing broker for interface com.ubuntu.authd.Broker
[ 76.347513] ubuntu systemd[1]: Started snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google.
[ 76.386265] ubuntu authd-google[4868]: Initializing broker for interface com.ubuntu.authd.Broker2
[ 76.403404] ubuntu authd-google[4868]: Initializing broker for interface com.ubuntu.authd.Broker3
[ 76.517749] ubuntu authd-google[4868]: Building new daemon
[ 76.517764] ubuntu authd-google[4868]: Starting to serve requests
[ 76.517770] ubuntu authd-google[4868]: Serving requests as com.ubuntu.authd.Google
[ 76.605902] ubuntu systemd[1]: Starting snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid...
[ 77.249976] ubuntu authd-msentraid[4985]: Version: 0.4.1+4bdea7f.4e5e1e3
[ 77.249989] ubuntu authd-msentraid[4985]: Debug mode is enabled
[ 77.250971] ubuntu authd-msentraid[4985]: Initializing broker for interface com.ubuntu.authd.Broker
[ 77.252195] ubuntu systemd[1]: Started snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid.
[ 77.274235] ubuntu authd-msentraid[4985]: Initializing broker for interface com.ubuntu.authd.Broker2
[ 77.322877] ubuntu authd-msentraid[4985]: Initializing broker for interface com.ubuntu.authd.Broker3
[ 77.352052] ubuntu authd-msentraid[4985]: Building new daemon
[ 77.352069] ubuntu authd-msentraid[4985]: Starting to serve requests
[ 77.352078] ubuntu authd-msentraid[4985]: Serving requests as com.ubuntu.authd.MSEntraID
[ 77.464927] ubuntu systemd[1]: Stopping authd.service - authd daemon service...
[ 77.466899] ubuntu systemd[1]: authd.service: Deactivated successfully.
[ 77.467210] ubuntu systemd[1]: Stopped authd.service - authd daemon service.
[ 77.469530] ubuntu systemd[1]: Starting authd.service - authd daemon service...
[ 77.511901] ubuntu authd[5088]: Could not parse interface version from "org.freedesktop.DBus.Introspectable"
[ 77.512566] ubuntu authd[5088]: Could not parse interface version from "org.freedesktop.DBus.Introspectable"
[ 77.513166] ubuntu systemd[1]: Started authd.service - authd daemon service.
[ 77.627737] ubuntu systemd[1]: Stopping snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google...
[ 77.627930] ubuntu systemd[1]: Stopping snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid...
[ 77.630217] ubuntu authd-msentraid[4985]: Stopping daemon requested.
[ 77.632510] ubuntu authd-google[4868]: Stopping daemon requested.
[ 77.697740] ubuntu systemd[1]: snap.authd-google.authd-google.service: Deactivated successfully.
[ 77.698202] ubuntu systemd[1]: Stopped snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google.
[ 77.699728] ubuntu systemd[1]: snap.authd-msentraid.authd-msentraid.service: Deactivated successfully.
[ 77.700089] ubuntu systemd[1]: Stopped snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid.
[ 79.706963] ubuntu systemd[1]: Stopping authd.service - authd daemon service...
[ 79.711414] ubuntu systemd[1]: authd.service: Deactivated successfully.
[ 79.711636] ubuntu systemd[1]: Stopped authd.service - authd daemon service.
-- Boot 610bf77f606a44ffbcf979193b974706 --
[ 6.642502] ubuntu systemd[1]: Starting authd.service - authd daemon service...
[ 6.869028] ubuntu systemd[1]: Starting snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google...
[ 7.236727] ubuntu authd-google[1104]: Version: 0.4.1+60b85d2.4e5e1e3
[ 7.236741] ubuntu authd-google[1104]: Debug mode is enabled
[ 7.237810] ubuntu authd-google[1104]: Initializing broker for interface com.ubuntu.authd.Broker
[ 7.237853] ubuntu systemd[1]: Started snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google.
[ 7.238368] ubuntu authd[988]: Could not parse interface version from "org.freedesktop.DBus.Introspectable"
[ 7.245402] ubuntu systemd[1]: Starting snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid...
[ 7.267499] ubuntu authd-google[1104]: Initializing broker for interface com.ubuntu.authd.Broker2
[ 7.293707] ubuntu authd-google[1104]: Initializing broker for interface com.ubuntu.authd.Broker3
[ 7.412729] ubuntu authd-google[1104]: Building new daemon
[ 7.412745] ubuntu authd-google[1104]: Starting to serve requests
[ 7.412751] ubuntu authd-google[1104]: Serving requests as com.ubuntu.authd.Google
[ 7.926536] ubuntu authd-msentraid[1187]: Version: 0.4.1+4bdea7f.4e5e1e3
[ 7.926552] ubuntu authd-msentraid[1187]: Debug mode is enabled
[ 7.927599] ubuntu authd-msentraid[1187]: Initializing broker for interface com.ubuntu.authd.Broker
[ 7.927731] ubuntu systemd[1]: Started snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid.
[ 7.928171] ubuntu authd[988]: Could not parse interface version from "org.freedesktop.DBus.Introspectable"
[ 7.930040] ubuntu systemd[1]: Started authd.service - authd daemon service.
[ 7.974697] ubuntu authd-msentraid[1187]: Initializing broker for interface com.ubuntu.authd.Broker2
[ 8.045040] ubuntu authd-msentraid[1187]: Initializing broker for interface com.ubuntu.authd.Broker3
[ 8.063759] ubuntu authd-msentraid[1187]: Building new daemon
[ 8.063775] ubuntu authd-msentraid[1187]: Starting to serve requests
[ 8.063780] ubuntu authd-msentraid[1187]: Serving requests as com.ubuntu.authd.MSEntraID
[ 175.088941] ubuntu gdm-authd][6406]: accountsservice: ActUserManager: user (null) has no username (uid: -1)
[ 175.134759] ubuntu gdm-session-worker[6425]: [38B blob data]
[ 175.134759] ubuntu gdm-session-worker[6425]:
[ 175.134759] ubuntu gdm-session-worker[6425]: > 1. local
[ 175.134759] ubuntu gdm-session-worker[6425]: 2. Google
[ 177.134520] ubuntu authd-msentraid[1187]: Creating new session (v3) (username=lucio.terranova@canonical.com, lang=C, mode=auth, provider_id=)
[ 177.433926] ubuntu authd-msentraid[1187]: Created new session
[ 177.435965] ubuntu authd-msentraid[1187]: Getting authentication modes for session
[ 177.436019] ubuntu authd-msentraid[1187]: Token does not exist for user "lucio.terranova@canonical.com", so local password authentication is not available
[ 177.436038] ubuntu authd-msentraid[1187]: The "entra_auth" flow is disabled in the [flows] config, so it is not available
[ 177.436065] ubuntu authd-msentraid[1187]: Got authentication modes for session : [map[id:device_auth_qr label:Device code flow]]
[ 177.451933] ubuntu authd-msentraid[1187]: Selecting authentication mode device_auth_qr for session
[ 177.451957] ubuntu authd-msentraid[1187]: Sending Device Authorization Request to retrieve device code...
[ 177.603379] ubuntu authd-msentraid[1187]: Retrieved device code. Device Authorization Response: &oauth2.DeviceAuthResponse{DeviceCode:"ABgABIQEAAAA9VeaV3ywaSLp1O3c4_Et5RXZvU3RzQXJ0aWZhY3RzAQAAAAAANhaSxq6KBXLrJclH7ADEiJMSo6qULpDeCQfN9SkhuGFTFlFg_y_8YV2fykYmHtS_4OkYuCevf8CNzXyZyUwqljUOP8XNltD-ctIZSJEmVA3v-eRAPW1fWzYzoqtjP6tgUjecXWzQ5oR1QAs6sSNfjJnO6x4ItEvL92jvMYxZTK5fu64lqhbdDmHYwk7FiB5FRyuXMEbrmj7zrxAcxDFBRHuEkye17KfS3GcmkofDS2HACD-q60_O7h2JFHx-TsEfHkXTnjPgJyvXJxGDNHE_LEc-uR74g6mxgMjwZhY4y6VDPwDoYUax13x-Pd29qsRtz2ConolZXU-a2m14IVDwFFijxGtxTVjqFlPiv5p2t7FgQRY5B1KmFmXK4Pr4JuiDhmhVLD5L5iGpzhOsKzM3K6yhjhct06Xg3vfIQ2pOoWVGFwATDWjRrHTKhB3MZfSRUq95p-Rkg8eVBebpG6gUvaaY_MROJak-orO9-3tvbrFaEsKuunYj2esw6ESMtivoI9tj0IYb234_7e7KdBvweSmHsg6LkzI6o34AzdGifn-y7SwgPAibgW7WhJrLxV7ZwBVJ9NGXeGoEyQTvYY1sDRYXRa8VGybYx16dA4-3PunU7EXlhJ4OiSrXDFtZ5CuIA9GycFFmXyvxoZ3_fufr7v5fbgrcfO3vjjna-9WZ8AK9U6JJ1rX_cC6KV7u1KJGqKjwkHpFKJmi77CAfXlo7KfzMd__OxdJcwansm8qr_mcgAA", UserCode:"AU5A6JHHN", VerificationURI:"https://login.microsoft.com/device", VerificationURIComplete:"", Expiry:time.Date(2026, time.September, 14, 15, 26, 50, 846906063, time.UTC), Interval:5}
[ 177.603411] ubuntu authd-msentraid[1187]: Selected authentication mode device_auth_qr for session : map[button:Request new code code:AU5A6JHHN content:https://login.microsoft.com/device label:Scan the QR code or open the URL and enter the code below. type:qrcode wait:true]
[ 177.622357] ubuntu authd-msentraid[1187]: Handling IsAuthenticated call for session
[ 177.622441] ubuntu authd-msentraid[1187]: Device code expiry time: 2026-09-14 15:26:50.846906063 +0000 UTC
[ 177.622455] ubuntu authd-msentraid[1187]: Polling to exchange device code for token...
[ 199.141339] ubuntu authd-msentraid[1187]: Exchanged device code for token.
[ 199.267303] ubuntu authd-msentraid[1187]: could not get user info: username verification failed: Authentication failure: requested username "lucio.terranova@canonical.com" does not match the authenticated username "lucio-test@ubudev1.onmicrosoft.com"
[ 199.267476] ubuntu authd-msentraid[1187]: IsAuthenticated result (session ): denied, {"message":"Authentication failure: requested username \"lucio.terranova@canonical.com\" does not match the authenticated username \"lucio-test@ubudev1.onmicrosoft.com\""}
[ 199.269187] ubuntu authd-msentraid[1187]: Ending session
[ 199.381963] ubuntu authd-pam[6425]: [6425] D-Bus Connection closed: context canceled
[ 199.383135] ubuntu gdm-session-worker[6425]: [26B blob data]
[ 217.227033] ubuntu authd-msentraid[1187]: Creating new session (v3) (username=lucio-test@ubudev1.onmicrosoft.com, lang=C, mode=auth, provider_id=)
[ 217.366552] ubuntu authd-msentraid[1187]: Created new session
[ 217.368645] ubuntu authd-msentraid[1187]: Getting authentication modes for session
[ 217.368691] ubuntu authd-msentraid[1187]: Token does not exist for user "lucio-test@ubudev1.onmicrosoft.com", so local password authentication is not available
[ 217.368697] ubuntu authd-msentraid[1187]: The "entra_auth" flow is disabled in the [flows] config, so it is not available
[ 217.368714] ubuntu authd-msentraid[1187]: Got authentication modes for session : [map[id:device_auth_qr label:Device code flow]]
[ 217.382340] ubuntu authd-msentraid[1187]: Selecting authentication mode device_auth_qr for session
[ 217.382371] ubuntu authd-msentraid[1187]: Sending Device Authorization Request to retrieve device code...
[ 217.542812] ubuntu authd-msentraid[1187]: Retrieved device code. Device Authorization Response: &oauth2.DeviceAuthResponse{DeviceCode:"ABgABIQEAAAA9VeaV3ywaSLp1O3c4_Et5RXZvU3RzQXJ0aWZhY3RzAQAAAAAA_5uScfMy3hK0hicDY4m9grIbfWvSg7FqX4Lth-SI9c-CAgszFjizwONjSrvgZEiGkMTfnKJ4R00jsezYJ8owMQMOWkrXxONkQAjOsGrVNImYYeoJPiVRY0KaADGFE7iUdeINILL2LXgiJmE6DFw00gs3oCENtsZFPvknkpVNVN7oCiLjSZ5pNwIOnJueJ82boX2LL5uAdWSXAUPqT5c-rIyzevVwele27fpJyoNv34nXDPG_tmVHzWAZ_priMNV_AEBoOi9Bxt4q7aPIWFpt90SXNbVX0pOAOz3Cb8gFc_MftdujO__tr3Hi4-MprFL43S5PVc7yRY6pI7AF4vtygQPkOEO2-URhZgVWqfONegVVq4AYNsfAuM6PdMNnCIpOvukqUe3OHJhQ2H-Jmh67LrOebpci7QTyhWsQSeGTBFRyDbeZFIzzICQuay4K8vGoZ9yAvECoFBvj6_xAcpKSBOnsf5netc6uB1UzkCL2ik11ox95BJqmvcbhx1Zn-2h3d0Hlzo2Fon6eMepY3pE-xlx3i0KdB2guZ4d-lA_ZBoz_879RdCWF7Pg0BCSzXUOW5WSxOzkTgFIXwxpB0yWWnFn1BgQz4xoJ1nMQzxJRydYEqcvkOQhaJ7OVkF-EUm3MNwtgpeKypE1KR-YTjGo32IoISGH1OrpcXr5NdZjHbbrbLrRZ8n9P5iDsSqS7hYcQFA1wXcI-tNoWQ9FaQSKS3iargP7RF5odPDw7oIgKpjkgAA", UserCode:"A2L64RYSA", VerificationURI:"https://login.microsoft.com/device", VerificationURIComplete:"", Expiry:time.Date(2026, time.September, 14, 15, 27, 30, 777320751, time.UTC), Interval:5}
[ 217.542860] ubuntu authd-msentraid[1187]: Selected authentication mode device_auth_qr for session : map[button:Request new code code:A2L64RYSA content:https://login.microsoft.com/device label:Scan the QR code or open the URL and enter the code below. type:qrcode wait:true]
[ 217.594608] ubuntu authd-msentraid[1187]: Handling IsAuthenticated call for session
[ 217.594722] ubuntu authd-msentraid[1187]: Device code expiry time: 2026-09-14 15:27:30.777320751 +0000 UTC
[ 217.594734] ubuntu authd-msentraid[1187]: Polling to exchange device code for token...
[ 238.886177] ubuntu authd-msentraid[1187]: Exchanged device code for token.
[ 239.020961] ubuntu authd-msentraid[1187]: Getting user groups from Microsoft Graph API
[ 239.486895] ubuntu authd-msentraid[1187]: Got groups: e2e-test-group, linux-sudo
[ 239.486946] ubuntu authd-msentraid[1187]: IsAuthenticated result (session ): next, {}
[ 239.489093] ubuntu authd-msentraid[1187]: Getting authentication modes for session
[ 239.489167] ubuntu authd-msentraid[1187]: Got authentication modes for session : [map[id:newpassword label:Define your local password]]
[ 239.512869] ubuntu authd-msentraid[1187]: Selecting authentication mode newpassword for session
[ 239.512909] ubuntu authd-msentraid[1187]: Selected authentication mode newpassword for session : map[entry:chars_password label:Create a local password type:newpassword]
[ 249.606378] ubuntu authd-msentraid[1187]: Handling IsAuthenticated call for session
[ 249.638076] ubuntu authd-msentraid[1187]: IsAuthenticated result (session ): granted, {"userinfo":{"name":"lucio-test@ubudev1.onmicrosoft.com","provider_id":"","dir":"/home/lucio-test@ubudev1.onmicrosoft.com","shell":"/usr/bin/bash","gecos":"lucio-test","groups":[{"name":"e2e-test-group","ugid":""},{"name":"sudo","ugid":""}]}}
[ 249.660369] ubuntu authd-msentraid[1187]: Ending session
[ 249.712868] ubuntu gdm-authd][6494]: gkr-pam: unable to locate daemon control file
[ 249.712878] ubuntu gdm-authd][6494]: gkr-pam: stashed password to try later in open session
[ 249.713070] ubuntu gdm-authd][6494]: accountsservice: ActUserManager: user (null) has no username (uid: -1)
[ 249.753365] ubuntu gdm-authd][6494]: pam_unix(gdm-authd:session): session opened for user lucio-test@ubudev1.onmicrosoft.com(uid=10000) by (uid=0)
[ 249.994829] ubuntu gdm-authd][6494]: gkr-pam: unlocked login keyring
[ 266.269445] ubuntu authd-msentraid[1187]: Creating new session (v3) (username=lucio-test@ubudev1.onmicrosoft.com, lang=C, mode=auth, provider_id=)
[ 266.660166] ubuntu authd-msentraid[1187]: Created new session
[ 266.662755] ubuntu authd-msentraid[1187]: Getting authentication modes for session
[ 266.662927] ubuntu authd-msentraid[1187]: The "entra_auth" flow is disabled in the [flows] config, so it is not available
[ 266.662946] ubuntu authd-msentraid[1187]: Got authentication modes for session : [map[id:password label:Local password]]
[ 266.664674] ubuntu authd-msentraid[1187]: Selecting authentication mode password for session
[ 266.664717] ubuntu authd-msentraid[1187]: Selected authentication mode password for session : map[entry:chars_password label:Enter your password type:form]
[ 268.662407] ubuntu authd-msentraid[1187]: Handling IsAuthenticated call for session
[ 268.796522] ubuntu authd-msentraid[1187]: Authentication failure: incorrect local password for user "lucio-test@ubudev1.onmicrosoft.com"
[ 268.796579] ubuntu authd-msentraid[1187]: IsAuthenticated result (session ): retry, {"message":"Incorrect password, please try again."}
[ 270.445755] ubuntu authd-msentraid[1187]: Ending session
[ 1108.204655] ubuntu gdm-authd][6494]: pam_unix(gdm-authd:session): session closed for user lucio-test@ubudev1.onmicrosoft.com
[ 1125.773883] ubuntu authd-msentraid[1187]: Creating new session (v3) (username=lucio-test@ubudev1.onmicrosoft.com, lang=C, mode=auth, provider_id=)
[ 1125.796258] ubuntu authd-msentraid[1187]: Creating new session (v3) (username=lucio-test@ubudev1.onmicrosoft.com, lang=C, mode=auth, provider_id=)
[ 1126.053947] ubuntu authd-msentraid[1187]: Created new session
[ 1126.055539] ubuntu authd-msentraid[1187]: Getting authentication modes for session
[ 1126.055755] ubuntu authd-msentraid[1187]: The "entra_auth" flow is disabled in the [flows] config, so it is not available
[ 1126.055790] ubuntu authd-msentraid[1187]: Got authentication modes for session : [map[id:password label:Local password] map[id:device_auth_qr label:Device code flow]]
[ 1126.063110] ubuntu authd-msentraid[1187]: Created new session
[ 1126.064795] ubuntu authd-msentraid[1187]: Getting authentication modes for session
[ 1126.064976] ubuntu authd-msentraid[1187]: The "entra_auth" flow is disabled in the [flows] config, so it is not available
[ 1126.065021] ubuntu authd-msentraid[1187]: Got authentication modes for session : [map[id:password label:Local password] map[id:device_auth_qr label:Device code flow]]
[ 1126.066302] ubuntu authd-msentraid[1187]: Selecting authentication mode password for session
[ 1126.066371] ubuntu authd-msentraid[1187]: Selected authentication mode password for session : map[entry:chars_password label:Enter your password type:form]
[ 1126.077510] ubuntu authd-msentraid[1187]: Selecting authentication mode password for session
[ 1126.077541] ubuntu authd-msentraid[1187]: Selected authentication mode password for session : map[entry:chars_password label:Enter your password type:form]
[ 1126.608276] ubuntu gdm-session-worker[12203]: [39B blob data]
[ 1126.608276] ubuntu gdm-session-worker[12203]: >
[ 1126.608276] ubuntu gdm-session-worker[12203]:
[ 1128.600676] ubuntu gdm-session-wor[12183]: GDM Stage changed to authModeSelection
[ 1130.934494] ubuntu gdm-session-wor[12183]: GDM Stage changed to brokerSelection
[ 1130.935643] ubuntu authd-msentraid[1187]: Ending session
[ 1182.241633] ubuntu systemd[1]: Stopping snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google...
[ 1182.241691] ubuntu authd-google[1104]: Stopping daemon requested.
[ 1182.243128] ubuntu systemd[1]: Stopping snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid...
[ 1182.243306] ubuntu authd-msentraid[1187]: Stopping daemon requested.
[ 1182.262836] ubuntu systemd[1]: snap.authd-google.authd-google.service: Deactivated successfully.
[ 1182.263086] ubuntu systemd[1]: Stopped snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google.
[ 1182.264808] ubuntu systemd[1]: snap.authd-msentraid.authd-msentraid.service: Deactivated successfully.
[ 1182.264958] ubuntu systemd[1]: Stopped snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid.
[ 1182.266895] ubuntu systemd[1]: snap.authd-msentraid.authd-msentraid.service: Consumed 1.547s CPU time over 19min 35.019s wall clock time, 191.4M memory peak.
[ 1182.406137] ubuntu gdm-authd][12183]: Gdm: GdmSessionWorker: custom JSON request failed: The connection is closed
[ 1182.406371] ubuntu gdm-authd][12183]: Gdm: GdmSessionWorker: custom JSON request failed: The connection is closed
[ 1182.423425] ubuntu gdm-session-wor[12183]: Failed sending message to pam: Conversation error
[ 1182.423450] ubuntu gdm-session-wor[12183]: Impossible to send PAM message: Conversation error
[ 1182.454383] ubuntu gdm-session-worker[12183]: module returned error: gdm-authd failed: System error: Changing GDM stage failed: Conversation error
[ 1182.662396] ubuntu gdm-session-worker[12203]: [66B blob data]
[ 1182.979615] ubuntu systemd[1]: Stopping authd.service - authd daemon service...
[ 1182.981898] ubuntu systemd[1]: authd.service: Deactivated successfully.
[ 1182.982157] ubuntu systemd[1]: Stopped authd.service - authd daemon service.
[ 1182.983200] ubuntu systemd[1]: authd.service: Consumed 1.170s CPU time over 19min 36.339s wall clock time, 30.1M memory peak.
-- Boot 2f705fd7f64d438e8cbeffd017e118c5 --
[ 6.566489] ubuntu systemd[1]: Starting authd.service - authd daemon service...
[ 6.767513] ubuntu systemd[1]: Starting snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google...
[ 7.223118] ubuntu authd-google[1115]: Version: 0.4.1+60b85d2.4e5e1e3
[ 7.223139] ubuntu authd-google[1115]: Debug mode is enabled
[ 7.225049] ubuntu authd-google[1115]: Initializing broker for interface com.ubuntu.authd.Broker
[ 7.225097] ubuntu systemd[1]: Started snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google.
[ 7.225817] ubuntu authd[992]: Could not parse interface version from "org.freedesktop.DBus.Introspectable"
[ 7.233961] ubuntu systemd[1]: Starting snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid...
[ 7.255947] ubuntu authd-google[1115]: Initializing broker for interface com.ubuntu.authd.Broker2
[ 7.307616] ubuntu authd-google[1115]: Initializing broker for interface com.ubuntu.authd.Broker3
[ 7.334445] ubuntu authd-google[1115]: Building new daemon
[ 7.334748] ubuntu authd-google[1115]: Starting to serve requests
[ 7.334896] ubuntu authd-google[1115]: Serving requests as com.ubuntu.authd.Google
[ 7.972457] ubuntu authd-msentraid[1191]: Version: 0.4.1+4bdea7f.4e5e1e3
[ 7.972471] ubuntu authd-msentraid[1191]: Debug mode is enabled
[ 7.973638] ubuntu authd-msentraid[1191]: Initializing broker for interface com.ubuntu.authd.Broker
[ 7.973730] ubuntu systemd[1]: Started snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid.
[ 7.974264] ubuntu authd[992]: Could not parse interface version from "org.freedesktop.DBus.Introspectable"
[ 7.975939] ubuntu systemd[1]: Started authd.service - authd daemon service.
[ 8.074510] ubuntu authd-msentraid[1191]: Initializing broker for interface com.ubuntu.authd.Broker2
[ 8.107297] ubuntu authd-msentraid[1191]: Initializing broker for interface com.ubuntu.authd.Broker3
[ 8.118747] ubuntu authd-msentraid[1191]: Building new daemon
[ 8.118762] ubuntu authd-msentraid[1191]: Starting to serve requests
[ 8.118768] ubuntu authd-msentraid[1191]: Serving requests as com.ubuntu.authd.MSEntraID
[ 15.093569] ubuntu authd-msentraid[1191]: Creating new session (v3) (username=lucio-test@ubudev1.onmicrosoft.com, lang=C, mode=auth, provider_id=)
[ 15.107430] ubuntu authd-msentraid[1191]: Creating new session (v3) (username=lucio-test@ubudev1.onmicrosoft.com, lang=C, mode=auth, provider_id=)
[ 15.354870] ubuntu authd-msentraid[1191]: Created new session
[ 15.356507] ubuntu authd-msentraid[1191]: Getting authentication modes for session
[ 15.357250] ubuntu authd-msentraid[1191]: The "entra_auth" flow is disabled in the [flows] config, so it is not available
[ 15.357298] ubuntu authd-msentraid[1191]: Got authentication modes for session : [map[id:password label:Local password] map[id:device_auth_qr label:Device code flow]]
[ 15.377156] ubuntu authd-msentraid[1191]: Selecting authentication mode password for session
[ 15.377185] ubuntu authd-msentraid[1191]: Selected authentication mode password for session : map[entry:chars_password label:Enter your password type:form]
[ 15.629168] ubuntu authd-msentraid[1191]: Created new session
[ 15.630922] ubuntu authd-msentraid[1191]: Getting authentication modes for session
[ 15.631109] ubuntu authd-msentraid[1191]: The "entra_auth" flow is disabled in the [flows] config, so it is not available
[ 15.631144] ubuntu authd-msentraid[1191]: Got authentication modes for session : [map[id:password label:Local password] map[id:device_auth_qr label:Device code flow]]
[ 15.633254] ubuntu authd-msentraid[1191]: Selecting authentication mode password for session
[ 15.633304] ubuntu authd-msentraid[1191]: Selected authentication mode password for session : map[entry:chars_password label:Enter your password type:form]
[ 16.170814] ubuntu gdm-session-worker[2435]: [39B blob data]
[ 16.170814] ubuntu gdm-session-worker[2435]: >
[ 16.170814] ubuntu gdm-session-worker[2435]:
[ 17.203473] ubuntu gdm-session-wor[2414]: GDM Stage changed to authModeSelection
[ 19.972223] ubuntu gdm-session-wor[2414]: GDM Stage changed to brokerSelection
[ 19.973099] ubuntu authd-msentraid[1191]: Ending session
[ 235.452971] ubuntu systemd[1]: Stopping snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google...
[ 235.453385] ubuntu systemd[1]: Stopping snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid...
[ 235.454442] ubuntu authd-google[1115]: Stopping daemon requested.
[ 235.459791] ubuntu authd-msentraid[1191]: Stopping daemon requested.
[ 235.508866] ubuntu systemd[1]: snap.authd-google.authd-google.service: Deactivated successfully.
[ 235.509362] ubuntu systemd[1]: Stopped snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google.
[ 235.510264] ubuntu systemd[1]: snap.authd-msentraid.authd-msentraid.service: Deactivated successfully.
[ 235.510705] ubuntu systemd[1]: Stopped snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid.
[ 235.667243] ubuntu gdm-authd][2414]: Gdm: GdmSessionWorker: custom JSON request failed: The connection is closed
[ 235.667538] ubuntu gdm-authd][2414]: Gdm: GdmSessionWorker: custom JSON request failed: The connection is closed
[ 235.684717] ubuntu gdm-session-wor[2414]: Failed sending message to pam: Conversation error
[ 235.684746] ubuntu gdm-session-wor[2414]: Impossible to send PAM message: Conversation error
[ 235.715821] ubuntu gdm-session-worker[2414]: module returned error: gdm-authd failed: System error: Changing GDM stage failed: Conversation error
[ 235.908306] ubuntu gdm-session-worker[2435]: [66B blob data]
[ 236.228320] ubuntu systemd[1]: Stopping authd.service - authd daemon service...
[ 236.231434] ubuntu systemd[1]: authd.service: Deactivated successfully.
[ 236.231639] ubuntu systemd[1]: Stopped authd.service - authd daemon service.
-- Boot 43abb2a68c1040f880206d5772935e6e --
[ 6.277481] ubuntu systemd[1]: Starting authd.service - authd daemon service...
[ 6.430639] ubuntu systemd[1]: Starting snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google...
[ 6.814413] ubuntu authd-google[1098]: Version: 0.4.1+60b85d2.4e5e1e3
[ 6.814464] ubuntu authd-google[1098]: Debug mode is enabled
[ 6.816227] ubuntu systemd[1]: Started snap.authd-google.authd-google.service - Service for snap application authd-google.authd-google.
[ 6.816358] ubuntu authd-google[1098]: Initializing broker for interface com.ubuntu.authd.Broker
[ 6.817291] ubuntu authd[994]: Could not parse interface version from "org.freedesktop.DBus.Introspectable"
[ 6.822236] ubuntu systemd[1]: Starting snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid...
[ 6.857575] ubuntu authd-google[1098]: Initializing broker for interface com.ubuntu.authd.Broker2
[ 6.872528] ubuntu authd-google[1098]: Initializing broker for interface com.ubuntu.authd.Broker3
[ 7.013667] ubuntu authd-google[1098]: Building new daemon
[ 7.013684] ubuntu authd-google[1098]: Starting to serve requests
[ 7.013690] ubuntu authd-google[1098]: Serving requests as com.ubuntu.authd.Google
[ 7.537846] ubuntu authd-msentraid[1187]: Version: 0.4.1+4bdea7f.4e5e1e3
[ 7.537882] ubuntu authd-msentraid[1187]: Debug mode is enabled
[ 7.539760] ubuntu systemd[1]: Started snap.authd-msentraid.authd-msentraid.service - Service for snap application authd-msentraid.authd-msentraid.
[ 7.539794] ubuntu authd-msentraid[1187]: Initializing broker for interface com.ubuntu.authd.Broker
[ 7.540428] ubuntu authd[994]: Could not parse interface version from "org.freedesktop.DBus.Introspectable"
[ 7.543774] ubuntu systemd[1]: Started authd.service - authd daemon service.
[ 7.558940] ubuntu authd-msentraid[1187]: Initializing broker for interface com.ubuntu.authd.Broker2
[ 7.657694] ubuntu authd-msentraid[1187]: Initializing broker for interface com.ubuntu.authd.Broker3
[ 7.690412] ubuntu authd-msentraid[1187]: Building new daemon
[ 7.690426] ubuntu authd-msentraid[1187]: Starting to serve requests
[ 7.690433] ubuntu authd-msentraid[1187]: Serving requests as com.ubuntu.authd.MSEntraID
```
#### authd apt history
```
Start-Date: 2026-09-14 15:08:18
Commandline: apt-get install -y authd
Install: authd:amd64 (0.6.4+git260902+1025+ef589ea3~26.10.1)
End-Date: 2026-09-14 15:08:20
```
#### authd broker configuration
#### /etc/authd/brokers.d/google.conf
```
# This section is used by authd to identify and communicate with the broker.
# It should not be edited.
[authd]
name = Google
brand_icon = /snap/authd-google/current/broker_icon.png
dbus_name = com.ubuntu.authd.Google
dbus_object = /com/ubuntu/authd/Google
```
#### /etc/authd/brokers.d/msentraid.conf
```
# This section is used by authd to identify and communicate with the broker.
# It should not be edited.
[authd]
name = Microsoft Entra ID
brand_icon = /snap/authd-msentraid/current/broker_icon.png
dbus_name = com.ubuntu.authd.MSEntraID
dbus_object = /com/ubuntu/authd/MSEntraID
```
#### authd-msentraid configuration
```
[oidc]
## The OIDC issuer URL for your Entra ID tenant.
## Replace with your tenant ID.
issuer = https://login.microsoftonline.com//v2.0
## The client ID of the application registered in Entra ID.
client_id =
## Optional: Client secret for the OIDC application registered in Entra ID.
#client_secret =
## Force verification with the identity provider during login.
##
## When enabled, authd always verifies during login that the user still
## has permission to access the system according to the identity provider.
##
## When disabled (default), authd only performs this verification if there
## is a working network connection and the identity provider is reachable
## during login.
##
## Important: Enabling this option prevents authd users from logging in
## if the identity provider is unreachable (e.g. due to network issues).
#force_access_check_with_provider = false
[msentraid]
## Enable automatic device registration with Microsoft Entra ID
## when a user logs in through this broker.
##
## If set to true, authd will attempt to register the local machine
## as a device in Entra ID upon successful login.
##
## If set to false (the default), device registration will be skipped.
register_device = false
[users]
## The directory where the home directories of new users are created.
## Existing users will keep their current home directory.
## The home directories are created in the format /
#home_base_dir = /home
## By default, SSH only allows logins from users that already exist on the
## system.
## New authd users (who have never logged in before) are *not* allowed to log
## in for the first time via SSH unless this option is configured.
##
## If configured, only users with a suffix in this list are allowed to
## authenticate for the first time directly through SSH.
## Note that this does not affect users that already authenticated for
## the first time and already exist on the system.
##
## Suffixes must be comma-separated (e.g., '@example.com,@example.org').
## To allow all suffixes, use a single asterisk ('*').
##
## Example:
## ssh_allowed_suffixes_first_auth = @example.com,@anotherexample.org
##
## Example (allow all):
## ssh_allowed_suffixes_first_auth = *
##
#ssh_allowed_suffixes_first_auth =
## 'allowed_users' specifies the users who are permitted to log in after
## successfully authenticating with the identity provider.
## Values are separated by commas. Supported values:
## - 'OWNER': Grants access to the user specified in the 'owner' option
## (see below). This is the default.
## - 'ALL': Grants access to all users who successfully authenticate
## with the identity provider.
## - : Grants access to specific additional users
## (e.g. user1@example.com).
## Example: allowed_users = OWNER,user1@example.com,admin@example.com
#allowed_users = OWNER
## 'owner' specifies the user assigned the owner role. This user is
## permitted to log in if 'OWNER' is included in the 'allowed_users'
## option.
##
## If this option is left unset, the first user to successfully log in
## via this broker will automatically be assigned the owner role. A
## drop-in configuration file will be created in broker.conf.d/ to set
## the 'owner' option.
##
## To disable automatic assignment, you can either:
## 1. Explicitly set this option to an empty value (e.g. owner = "")
## 2. Remove 'OWNER' from the 'allowed_users' option
##
## Example: owner = user2@example.com
#owner =
## A comma-separated list of local groups which authd users will be
## added to upon login.
## Example: extra_groups = users
#extra_groups =
## Like 'extra_groups', but only the user assigned the owner role
## (see 'owner' option) will be added to these groups.
## Example: owner_extra_groups = sudo,lpadmin
#owner_extra_groups =
[flows]
## Control which authentication flows are offered to users.
##
## device_code: When true (the default), users can authenticate with the
## device code flow (scanning a QR code or visiting a URL and entering
## a code).
device_code = true
## entra_auth: When true, users can authenticate with the
## Microsoft Entra ID direct-auth flow.
## When the user has enrolled passwordless methods (FIDO2 security keys,
## Microsoft Authenticator, or a Temporary Access Pass), the flow negotiates
## those automatically; otherwise it falls back to password + MFA.
##
## If this option is omitted, it defaults to the value of register_device for
## compatibility with existing configurations. Keep it disabled by default in
## new configurations until the required group lookup setup is complete.
entra_auth = false
```
##### /var/snap/authd-msentraid/current/broker.conf.d/20-owner-autoregistration.conf
```
## This file was generated automatically by the broker. DO NOT EDIT.
##
## This file registers the first authenticated user as the owner of
## this device.
##
## The 'owner' option is only considered for authentication if
## 'allowed_users' contains the 'OWNER' keyword.
##
## To register a different owner for the machine on the next
## successful authentication, delete this file.
[users]
owner = lucio-test@ubudev1.onmicrosoft.com
```
#### authd-google configuration
```
[oidc]
## The issuer URL for Google's OIDC service.
issuer = https://accounts.google.com
## The client ID of the application registered with Google.
client_id =
## The client secret of the application registered with Google.
client_secret =
## Force verification with the identity provider during login.
##
## When enabled, authd always verifies during login that the user still
## has permission to access the system according to the identity provider.
##
## When disabled (default), authd only performs this verification if there
## is a working network connection and the identity provider is reachable
## during login.
##
## Important: Enabling this option prevents authd users from logging in
## if the identity provider is unreachable (e.g. due to network issues).
#force_access_check_with_provider = false
[users]
## The directory where the home directories of new users are created.
## Existing users will keep their current home directory.
## The home directories are created in the format /
#home_base_dir = /home
## By default, SSH only allows logins from users that already exist on the
## system.
## New authd users (who have never logged in before) are *not* allowed to log
## in for the first time via SSH unless this option is configured.
##
## If configured, only users with a suffix in this list are allowed to
## authenticate for the first time directly through SSH.
## Note that this does not affect users that already authenticated for
## the first time and already exist on the system.
##
## Suffixes must be comma-separated (e.g., '@example.com,@example.org').
## To allow all suffixes, use a single asterisk ('*').
##
## Example:
## ssh_allowed_suffixes_first_auth = @example.com,@anotherexample.org
##
## Example (allow all):
## ssh_allowed_suffixes_first_auth = *
##
#ssh_allowed_suffixes_first_auth =
## 'allowed_users' specifies the users who are permitted to log in after
## successfully authenticating with the identity provider.
## Values are separated by commas. Supported values:
## - 'OWNER': Grants access to the user specified in the 'owner' option
## (see below). This is the default.
## - 'ALL': Grants access to all users who successfully authenticate
## with the identity provider.
## - : Grants access to specific additional users
## (e.g. user1@example.com).
## Example: allowed_users = OWNER,user1@example.com,admin@example.com
#allowed_users = OWNER
## 'owner' specifies the user assigned the owner role. This user is
## permitted to log in if 'OWNER' is included in the 'allowed_users'
## option.
##
## If this option is left unset, the first user to successfully log in
## via this broker will automatically be assigned the owner role. A
## drop-in configuration file will be created in broker.conf.d/ to set
## the 'owner' option.
##
## To disable automatic assignment, you can either:
## 1. Explicitly set this option to an empty value (e.g. owner = "")
## 2. Remove 'OWNER' from the 'allowed_users' option
##
## Example: owner = user2@example.com
#owner =
## A comma-separated list of local groups which authd users will be
## added to upon login.
## Example: extra_groups = users
#extra_groups =
## Like 'extra_groups', but only the user assigned the owner role
## (see 'owner' option) will be added to these groups.
## Example: owner_extra_groups = sudo,lpadmin
#owner_extra_groups =
```
#### authd-oidc configuration
```
cat: /var/snap/authd-oidc/current/broker.conf: No such file or directory
```
### Double check your logs
- [x] I have redacted any sensitive information from the logs
Contributor guide
Assessment
This issue has not been assessed yet.