Concept and mechanism
Finding a user does not demonstrate that the user can establish a session. NSS resolves identity information; the service applies authentication and other conditions. PAM separates management groups such as auth, account, password, and session. In a simple stack, a required failure is retained while remaining applicable modules are processed; requisite can return failure immediately. Advanced syntax with jumps or resets requires separate analysis and should not be reduced to that simple rule. An accepted password can coexist with an expired account or denied access. Investigate the rejection point before changing credentials or groups.
Guided application
SSSD can allow offline authentication with cached credentials. That availability requires decisions about validity and revocation while the directory is unavailable. Do not promise an immediate query to an unavailable source. In SSH, AuthenticationMethods uses commas to compose a sequence and spaces for alternatives; methods must also be enabled. Two steps are not automatically two factor types. In a fictional scenario, a PAM change blocks new logins. Use the authorized recovery path, restore known configuration, and test representative sessions before retrying. Retain stack and outcome evidence; an old session remaining open does not demonstrate working new access.
Getent finds the account; the account rule can still deny the session.
Common pitfalls
Identity as authorization; later success as cancellation of required; offline cache as immediate revocation.
Related topics: Automate with evidence · Operate and recover systems · Networking, tunnels, and policies
Diagnose the failed phase and retain an approved recovery path.
Reference: Linux PAM stack controls · Historical LFCE V3.18 (2018-06-12); exam retired 2022-05-01; technical references inspected 2026-09-30