]> git.pld-linux.org Git - packages/util-linux.git/commitdiff
- uniformized configs to use system-auth where possible auto/th/pwdutils-3_1_3-3 auto/th/pwdutils-3_1_3-4 auto/th/pwdutils-3_1_3-5 auto/th/util-linux-ng-2_13-1 auto/th/util-linux-ng-2_13-1_20070619_1 auto/th/util-linux-ng-2_13-2 auto/th/util-linux-ng-2_13-3 auto/th/util-linux-ng-2_13-4 auto/th/util-linux-ng-2_13-5 auto/th/util-linux-ng-2_13_0_1-1 auto/ti/pwdutils-3_1_3-3 auto/ti/pwdutils-3_1_3-4 auto/ti/pwdutils-3_1_3-5
authorJan Rękorajski <baggins@pld-linux.org>
Tue, 27 Mar 2007 15:43:42 +0000 (15:43 +0000)
committercvs2git <feedback@pld-linux.org>
Sun, 24 Jun 2012 12:13:13 +0000 (12:13 +0000)
- sanitized
- uniform blacklist for pop3, imap and smtp services

Changed files:
    chfn.pamd -> 1.8
    chsh.pamd -> 1.8
    login.pamd -> 1.10

chfn.pamd
chsh.pamd
login.pamd

index 64167a2972a421b7bef5dfd2112e9cbacc56a4c8..0aa09c4dc9be568a5f7dbcbe7ec60ff2d7541cc0 100644 (file)
--- a/chfn.pamd
+++ b/chfn.pamd
@@ -1,9 +1,6 @@
 #%PAM-1.0
 auth           sufficient      pam_rootok.so
 auth           required        pam_listfile.so item=user sense=allow file=/etc/security/chfn.allow onerr=fail
-auth           required        pam_unix.so
-account                required        pam_unix.so
-password       required        pam_cracklib.so difok=2 minlen=8 dcredit=2 ocredit=2 retry=3
-password       required        pam_unix.so md5 shadow use_authtok
-password       required        pam_exec.so failok seteuid /usr/bin/make -C /var/db
-session                required        pam_unix.so
+auth           include         system-auth
+account                include         system-auth
+password       include         system-auth
index 3f9afbba5d6029774eb98c1735a863a98ba11103..ac578e1903a7c258dce3dbcc5c93c06736a193e9 100644 (file)
--- a/chsh.pamd
+++ b/chsh.pamd
@@ -1,9 +1,6 @@
 #%PAM-1.0
 auth           sufficient      pam_rootok.so
 auth           required        pam_listfile.so item=user sense=allow file=/etc/security/chsh.allow onerr=fail
-auth           required        pam_unix.so
-account                required        pam_unix.so
-password       required        pam_cracklib.so difok=2 minlen=8 dcredit=2 ocredit=2 retry=3
-password       required        pam_unix.so md5 shadow use_authtok
-password       required        pam_exec.so failok seteuid /usr/bin/make -C /var/db
-session                required        pam_unix.so
+auth           include         system-auth
+account                include         system-auth
+password       include         system-auth
index eb2ca5de14734796a380ba682918ba7fb6661e8f..bab67203ae1cdc3abff728d254eff69b685094f1 100644 (file)
@@ -1,21 +1,17 @@
 #%PAM-1.0
-auth           required        pam_listfile.so item=user sense=deny file=/etc/security/blacklist onerr=succeed
 auth           required        pam_listfile.so item=user sense=deny file=/etc/security/blacklist.login onerr=succeed
 auth           required        pam_securetty.so
-auth           required        pam_unix.so
-auth           required        pam_tally.so deny=0 file=/var/log/faillog onerr=succeed
-auth           required        pam_shells.so
-auth           required        pam_nologin.so
-auth           optional        pam_mail.so
-account                required        pam_tally.so file=/var/log/faillog onerr=succeed
+auth           include         system-auth
+account                required        pam_shells.so
+account                required        pam_nologin.so
 account                required        pam_access.so
-account                required        pam_time.so
-account                required        pam_unix.so
-password       required        pam_cracklib.so difok=2 minlen=8 dcredit=2 ocredit=2 retry=3
-password       required        pam_unix.so md5 shadow use_authtok
-password       required        pam_exec.so failok seteuid /usr/bin/make -C /var/db
-session                required        pam_unix.so
-session                required        pam_env.so
-session                required        pam_limits.so change_uid
-#session       required        pam_selinux.so
+account                include         system-auth
+password       include         system-auth
+# pam_selinux.so close should be the first session rule
+# session              required        pam_selinux.so close
+session                include         system-auth
 session                optional        pam_console.so
+session                optional        pam_mail.so
+# pam_selinux.so open should only be followed by sessions to be executed in the user context
+#session               required        pam_selinux.so open
+#session               optional        pam_keyinit.so force revoke
This page took 0.039794 seconds and 4 git commands to generate.