Jim Kinney via FreeIPA-users wrote: It seems if valid ssh keys exist, the expired account status doesn't block login with ssh keys. Any operation that touches a password is blocking. Is there a pam setting in sshd that needs tweaking to deny access if account is expired?
You may want to cross post this on sssd-users.
rob