-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
51d2256
commit 1305b5a
Showing
1 changed file
with
28 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,28 @@ | ||
# | ||
# /etc/pam.d/common-auth - authentication settings common to all services | ||
# | ||
# This file is included from other service-specific PAM config files, | ||
# and should contain a list of the authentication modules that define | ||
# the central authentication scheme for use on the system | ||
# (e.g., /etc/shadow, LDAP, Kerberos, etc.). The default is to use the | ||
# traditional Unix authentication mechanisms. | ||
# | ||
# As of pam 1.0.1-6, this file is managed by pam-auth-update by default. | ||
# To take advantage of this, it is recommended that you configure any | ||
# local modules either before or after the default block, and use | ||
# pam-auth-update to manage selection of other modules. See | ||
# pam-auth-update(8) for details. | ||
|
||
# here are the per-package modules (the "Primary" block) | ||
auth [success=3 default=ignore] pam_unix.so nullok | ||
auth [success=2 default=ignore] pam_sss.so use_first_pass | ||
auth [success=1 default=ignore] pam_ldap.so minimum_uid=1000 use_first_pass | ||
# here's the fallback if no module succeeds | ||
auth requisite pam_deny.so | ||
# prime the stack with a positive return value if there isn't one already; | ||
# this avoids us returning an error just because nothing sets a success code | ||
# since the modules above will each just jump around | ||
auth required pam_permit.so | ||
# and here are more per-package modules (the "Additional" block) | ||
auth optional pam_cap.so | ||
# end of pam-auth-update config |