- restored (but disabled) pam_shells (works just like RequireValidShell option)
- restored required session group! (consider using system-auth here)
Changed files:
ftp.pamd -> 1.9
#%PAM-1.0
auth required pam_listfile.so item=user sense=deny file=/etc/ftpd/ftpusers onerr=succeed
+auth required pam_listfile.so item=user sense=deny file=/etc/security/blacklist.ftp onerr=succeed
+#auth required pam_shells.so
auth include system-auth
account required pam_nologin.so
account include system-auth
+session required pam_unix.so