Jim Kinney via FreeIPA-users wrote:
It seems if valid ssh keys exist, the expired account status doesn't
block login with ssh keys. Any operation that touches a password is
blocking.
Is there a pam setting in sshd that needs tweaking to deny access if
account is expired?

You may want to cross post this on sssd-users.

rob
--
Computers amplify human error
Super computers are really cool