Linux Identity and Access
29 incident problems about Linux Identity and Access. Start with the reviewed ones.
Read first
How to split Linux failures by systemd, permission, and filesystem signalsAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a service fails but you need to isolate whether the cause is a systemd unit, permission, inode, mount, or process.Linux3 min readWhen sudo works in the shell but fails under automationAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when only automation jobs fail because of TTY, sudoers, environment reset, or service user differences.Linux3 min readWhen permissions are fixed but only new directories are created with the wrong groupAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when existing file permissions are correct but group inheritance breaks for newly created files and directories.Linux3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
All problems (29)
LINUX-481A sudo rule allows the target subcommand (Permission Denied)A sudo rule allows the target subcommand (Permission Denied) focuses on linux-identity-and-access and asks the reader to isolate Permission Denied. 실무에서는 linux-identity-and-access 문제를 볼 때 서비스 로그만 보지 말고 inode, 파일시스템 여유, 포트 점유, systemd 상태, 최근 패키지 변경까지 같이 확인해야 원인을 빨리 좁힐 수 있습니다.ReviewedLinuxIntermediate17 minProLINUX-140SSH certificate authentication is configured, but the principals file permissions are too open and the daemon ignores it for security reasonsThe CA trust path is valid, yet certificate login falls back to password prompts because the principal mapping file fails ownership checks.LinuxAdvanced16 minProLINUX-141A package update rewrites the PAM stack include order, and MFA still prompts but account validation now happens after the wrong moduleAuthentication appears normal until edge-case users begin failing account checks after successful factors.LinuxAdvanced17 minProLINUX-108A sudoers include file loads later and quietly re-enables a broad NOPASSWD rule the team thought it removedPrivilege hardening seems complete, yet one lexical include order detail restores broad administrative access after the next package update.LinuxAdvanced17 minProLINUX-162A PAM include reorder leaves the visible prompts intact while the account phase now runs under the wrong module stack during a failover rehearsalLogin looks normal until a user path reaches the control phase the new order broke. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxAdvanced18 minProLINUX-363A sudo rule allows the target subcommand while PAM account restrictions on time or host still block the noninteractive invocation during a staged decommissionPath authorization is correct, but session policy still denies execution. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.LinuxIntermediate15 minProLINUX-123sudo timestamp caching is per-tty, but the automation wrapper assumes a shared session and fails only on the second commandPrivilege escalation seems inconsistent because the execution environment changed the terminal scope of the cached credential.LinuxIntermediate15 minProLINUX-160A backup restore repopulates ACLs correctly, but default ACL inheritance on the parent directory is missing and new files drift immediatelyRecovered state looks right at first, yet the future behavior of the directory no longer matches the original design.LinuxAdvanced16 minProLINUX-399A restored permission model looks right (Permission Denied)A restored permission model looks right (Permission Denied) focuses on Linux Storage and Filesystems and asks the reader to isolate Permission Denied. 실무에서는 linux-identity-and-access 문제를 볼 때 서비스 로그만 보지 말고 inode, 파일시스템 여유, 포트 점유, systemd 상태, 최근 패키지 변경까지 같이 확인해야 원인을 빨리 좁힐 수 있습니다.LinuxAdvanced16 minProLINUX-240A sudo rule matches a command path before alternatives flips the symlink to a new binary during a failover rehearsalPrivilege logic was tied to one pathname and the real executable moved beneath it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxIntermediate16 minProLINUX-300A sudoers include grants the right command path while the shell wrapper now invokes a different binary via env indirection during a failover rehearsalThe human command looks the same and the executed path is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxIntermediate16 minProLINUX-133A custom SELinux fcontext regex loads before the broader application path rule and restorecon applies the wrong label setThe policy file looks correct, yet precedence inside the matching rules changes the final label assignment.LinuxAdvanced17 minProLINUX-336A restore repopulates ACLs correctly while default inheritance and newly created subpaths drift immediately from the recovered design during a failover rehearsalThe present state is right and the future state starts drifting with the next write. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxAdvanced17 minProLINUX-381An SELinux file context restore fixes the target path while a transient tmpfiles rule recreates it at boot with the wrong type again during a staged decommissionManual recovery works and the next boot silently undoes it. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.LinuxAdvanced17 minProLINUX-151SELinux module priority causes a vendor policy package to override the local custom allow rule after patchingThe local fix still exists on disk, but load order changed which rule wins at runtime.LinuxAdvanced17 minProLINUX-541A sudo rule allows the target subcommand (Permission Denied)A sudo rule allows the target subcommand (Permission Denied) focuses on linux-identity-and-access and asks the reader to isolate Permission Denied. 실무에서는 linux-identity-and-access 문제를 볼 때 서비스 로그만 보지 말고 inode, 파일시스템 여유, 포트 점유, systemd 상태, 최근 패키지 변경까지 같이 확인해야 원인을 빨리 좁힐 수 있습니다.LinuxIntermediate18 minProLINUX-117An SELinux boolean is enabled but the domain still cannot transition to the target type the app needsThe operator toggles the obvious control, yet access stays blocked because the denial depends on a type transition rule not covered by the boolean.LinuxAdvanced18 minProLINUX-318An SELinux boolean is enabled while a later package update reloads a policy module that still denies the exact type transition the app needs during a failover rehearsalThe expected switch is on, yet the effective policy path still blocks the workflow. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxAdvanced18 minProLINUX-264An SSSD cache stays warm while the identity provider rotates usernames with a new realm suffix during a failover rehearsalAuthentication works in one place and the cached identity model remains anchored to the old directory naming contract. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxAdvanced18 minProLINUX-601A sudo rule allows the target subcommand (Permission Denied)A sudo rule allows the target subcommand (Permission Denied) focuses on linux-identity-and-access and asks the reader to isolate Permission Denied. 실무에서는 linux-identity-and-access 문제를 볼 때 서비스 로그만 보지 말고 inode, 파일시스템 여유, 포트 점유, systemd 상태, 최근 패키지 변경까지 같이 확인해야 원인을 빨리 좁힐 수 있습니다.LinuxIntermediate19 minPro