salt/states/productionize/freeipa/manual/pam.d/sss

16 lines
665 B
Text

auth sufficient pam_unix.so nullok try_first_pass
auth sufficient pam_sss.so use_first_pass
auth required pam_deny.so
account required pam_unix.so
#account [default=bad success=ok user_unknown=ignore] pam_sss.so
account optional pam_sss.so
password requisite pam_cracklib.so try_first_pass retry=3 minlen=8 dcredit=0 ucredit=0 ocredit=0 lcredit=0 type=
password sufficient pam_unix.so try_first_pass nullok sha512 shadow
password sufficient pam_sss.so use_authtok
password required pam_deny.so
session required pam_mkhomedir.so skel=/etc/skel umask=0077
session required pam_unix.so
session optional pam_sss.so