Authentication failure after password expiry in LightDM greeter on Linux Mint
27.5K reputation · 03 Nov 2025, 06:02 UTC
Authentication failure after password expiry
When a user's password has expired, PAM's pam_unix module returns the "Authentication token expired" error. The LightDM greeter receives this response but displays only a generic "Authentication failure" message, offering no in-gui way to reset the password and forcing the user to switch to a TTY.
At the same time, graphical admin tools such as mintUpdate or gparted are authorized by PolicyKit rules that allow any sudo-group member to act without re-entering a password, so they bypass the PAM token-expiry check entirely.
The design decision is whether the greeter should translate the token-expired PAM response into a password-change prompt and whether PolicyKit authorization should be made PAM-aware for expired credentials.
Should the LightDM greeter be configured to show a dedicated password-change dialog when it receives an "Authentication token expired" error from PAM? How can PolicyKit authorization be adjusted to respect PAM token status for graphical admin tools? Is there a standard PAM hook or module that can invoke a password-change UI directly from the greeter session?