Authentication failure after password expiry in LightDM greeter on Linux Mint
0 reputation · 03 Nov 2025, 06:02 UTC
0 reputation · 03 Nov 2025, 06:02 UTC
When a user's password has expired, PAM's pam_unix module returns the "Authentication token expired" error. The LightDM greeter receives this response but displays only a generic "Authentication failure" message, offering no in-gui way to reset the password and forcing the user to switch to a TTY.
At the same time, graphical admin tools such as mintUpdate or gparted are authorized by PolicyKit rules that allow any sudo-group member to act without re-entering a password, so they bypass the PAM token-expiry check entirely.
The design decision is whether the greeter should translate the token-expired PAM response into a password-change prompt and whether PolicyKit authorization should be made PAM-aware for expired credentials.
Should the LightDM greeter be configured to show a dedicated password-change dialog when it receives an "Authentication token expired" error from PAM? How can PolicyKit authorization be adjusted to respect PAM token status for graphical admin tools? Is there a standard PAM hook or module that can invoke a password-change UI directly from the greeter session?
28775 reputation · 03 Nov 2025, 08:39 UTC
LightDM authenticates via PAM. When a password has expired, the pam_unix.so module returns PAM_AUTHINFO_UNAVAIL. The LightDM greeter treats any PAM failure as a generic “Authentication failure” and does not offer a password‑change dialog.
The PAM configuration used by the LightDM greeter (/etc/pam.d/lightdm) lacks the password‑management stack that would allow pam_unix.so to prompt for a new password when the token is expired. Consequently the user cannot reset the password from the greeter and must switch to a TTY or recovery mode.
sudo passwd <username>
sudo chage -l <username>
sudo chage -M 99999 <username>
Edit the LightDM PAM file (keep a backup first):
sudo cp /etc/pam.d/lightdm /etc/pam.d/lightdm.bak
sudo nano /etc/pam.d/lightdm
Ensure the file contains these lines (add if missing):
auth sufficient pam_unix.so try_first_pass account required pam_unix.so password required pam_unix.so sha512 shadow try_first_passAfter saving, restart LightDM:
Now, when the greeter receivessudo systemctl restart lightdmPAM_AUTHINFO_UNAVAIL, it will invoke the password‑change module and present a UI for the user to set a new password.PolicyKit consideration
Graphical admin tools (e.g.,
mintUpdate,gparted) use PolicyKit agents that authenticate via PAM. If the agent is configured to allowsudo‑group members without re‑entering a password, it bypasses the PAM token‑expiry check. To make PolicyKit respect expired credentials:
polkit-gnome-authentication-agent-1) is not overridden by a rule that grants auth_admin_keep to the sudo group./etc/polkit-1/localauthority/50-local.d/ to require authentication for all actions, for example:
polkit.addRule(function(action, subject) {
if (subject.isInGroup("sudo")) {
return polkit.Result.AUTH_ADMIN;
}
});
sudo systemctl restart polkit
After this change, any graphical admin tool will prompt for a password via the PAM stack, and if the password is expired the same password‑change UI enabled above will appear.
If you cannot access a TTY or recovery mode, the above steps cannot be performed; in that case you would need to boot from a live USB, chroot into the system, and reset the password there. Please confirm whether you can obtain a TTY or recovery shell so the recommended steps remain valid.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.