summaryrefslogtreecommitdiff
path: root/nonsystemd/pambase/system-auth
diff options
context:
space:
mode:
authorDavid P <megver83@parabola.nu>2020-08-20 13:58:22 -0400
committerDavid P <megver83@parabola.nu>2020-08-20 13:58:22 -0400
commit345ee6fdadae636ce50f4876a47129596d6c0d94 (patch)
treed3288dfaa6787ebd72af1a6613b816d8dbf780d1 /nonsystemd/pambase/system-auth
parent2638950323143e5d59c8de023d2283b8eae6c9d3 (diff)
downloadabslibre-345ee6fdadae636ce50f4876a47129596d6c0d94.tar.gz
abslibre-345ee6fdadae636ce50f4876a47129596d6c0d94.tar.bz2
abslibre-345ee6fdadae636ce50f4876a47129596d6c0d94.zip
updpkg: nonsystemd/pambase 20200721.1-2.nonsystemd1
Signed-off-by: David P <megver83@parabola.nu>
Diffstat (limited to 'nonsystemd/pambase/system-auth')
-rw-r--r--nonsystemd/pambase/system-auth29
1 files changed, 18 insertions, 11 deletions
diff --git a/nonsystemd/pambase/system-auth b/nonsystemd/pambase/system-auth
index 264504360..9b2da4567 100644
--- a/nonsystemd/pambase/system-auth
+++ b/nonsystemd/pambase/system-auth
@@ -1,16 +1,23 @@
#%PAM-1.0
-auth required pam_unix.so try_first_pass nullok
-auth optional pam_permit.so
-auth required pam_env.so
+auth required pam_faillock.so preauth
+# Optionally use requisite above if you do not want to prompt for the password
+# on locked accounts.
+auth [success=1 default=ignore] pam_unix.so try_first_pass nullok
+auth [default=die] pam_faillock.so authfail
+auth optional pam_permit.so
+auth required pam_env.so
+auth required pam_faillock.so authsucc
+# If you drop the above call to pam_faillock.so the lock will be done also
+# on non-consecutive authentication failures.
-account required pam_unix.so
-account optional pam_permit.so
-account required pam_time.so
+account required pam_unix.so
+account optional pam_permit.so
+account required pam_time.so
-password required pam_unix.so try_first_pass nullok sha512 shadow
-password optional pam_permit.so
+password required pam_unix.so try_first_pass nullok shadow
+password optional pam_permit.so
-session required pam_limits.so
-session required pam_unix.so
-session optional pam_permit.so
+session required pam_limits.so
+session required pam_unix.so
+session optional pam_permit.so