Files
smeserver-base/root/etc/e-smith/templates/etc/pam.d/system-auth/30account
Jean-Philippe Pialasse 4c64e91235 * Wed Feb 12 2025 Jean-Philippe Pialasse <jpp@koozali.org> 11.0.0-26.sme
- add pam_abl requirement [SME: 12914]
- add isdn4k-utils requirement for ippp isdn connections [SME: 12909]
- remove pam_tally as deprecated in favor of pam_faillock [SME: 12913]
- fix CGI::param called in list context [SME: 12888]
2025-02-12 22:17:17 -05:00

16 lines
617 B
Plaintext

account required pam_unix.so broken_shadow
account sufficient pam_succeed_if.so uid < 100 quiet
{
my $status = $ldap{Authentication} || 'disabled';
return unless $status eq 'enabled';
$OUT .= "account [default=bad success=ok user_unknown=ignore] pam_ldap.so";
}
account required pam_permit.so
{
my $status = $pam_faillock{status} || 'disabled';
return unless $status eq 'enabled';
# if you drop this call to pam_faillock.so the lock will be done also
# on non-consecutive authentication failures
$OUT .= "account required pam_faillock.so";
}