@@ -4,7 +4,7 @@ auth sufficient pam_ssh.so
44{% endif %}
55
66{% if krb5 %}
7- auth [success= {{ 4 if homed else 3 }} default= ignore] pam_krb5.so {{ krb5_params }}
7+ auth [success= {{ 4 if homed else 3 }} default= ignore] pam_krb5.so {{ krb5_params }}
88{% endif %}
99
1010{% if sssd %}
@@ -15,13 +15,13 @@ auth [default=3 ignore=ignore success=ok] pam_localuser.so
1515auth requisite pam_faillock.so preauth
1616
1717{% if homed %}
18- auth [success= 2 default= ignore] pam_systemd_home.so
18+ auth [success= 2 default= ignore] pam_systemd_home.so
1919{% endif %}
2020
2121{% if sssd %}
22- auth sufficient pam_unix.so {{ nullok| default('', true) }} {{ debug| default('', true) }}
22+ auth sufficient pam_unix.so {{ nullok| default('', true) }} {{ debug| default('', true) }}
2323{% else %}
24- auth [success= 1 new_authtok_reqd= 1 ignore= ignore default= bad] pam_unix.so {{ nullok| default('', true) }} {{ debug| default('', true) }} try_first_pass
24+ auth [success= 1 new_authtok_reqd= 1 ignore= ignore default= bad] pam_unix.so {{ nullok| default('', true) }} {{ debug| default('', true) }} try_first_pass
2525{% endif %}
2626auth [default= die] pam_faillock.so authfail
2727{% if sssd %}
@@ -38,15 +38,15 @@ account [success=2 default=ignore] pam_krb5.so {{ krb5_params }}
3838{% endif %}
3939
4040{% if homed %}
41- account [success= {{ 2 if sssd else 1 }} default= ignore] pam_systemd_home.so
41+ account [success= {{ 2 if sssd else 1 }} default= ignore] pam_systemd_home.so
4242{% endif %}
4343
4444account required pam_unix.so {{ debug| default('', true) }}
45- account required pam_faillock.so
45+ account required pam_faillock.so
4646{% if sssd %}
4747account sufficient pam_localuser.so
4848account sufficient pam_usertype.so issystem
49- account [default= bad success= ok user_unknown= ignore] pam_sss.so {{ debug| default('', true) }}
49+ account [default= bad success= ok user_unknown= ignore] pam_sss.so {{ debug| default('', true) }}
5050account required pam_permit.so
5151{% endif %}
5252
@@ -55,25 +55,25 @@ password required pam_passwdqc.so config=/etc/security/passwdqc.conf
5555{% endif %}
5656
5757{% if pwquality %}
58- password required pam_pwquality.so {{ local_users_only| default('', true ) }}
58+ password required pam_pwquality.so {{ local_users_only| default('', true ) }}
5959{% endif %}
6060
6161{% if pwhistory %}
62- password required pam_pwhistory.so use_authtok remember= 5 retry= 3
62+ password required pam_pwhistory.so use_authtok remember= 5 retry= 3
6363{% endif %}
6464
6565{% if krb5 %}
6666password [success= 1 default= ignore] pam_krb5.so {{ krb5_params }}
6767{% endif %}
6868
6969{% if homed %}
70- password [success= 1 default= ignore] pam_systemd_home.so
70+ password [success= 1 default= ignore] pam_systemd_home.so
7171{% endif %}
7272
7373{% if passwdqc or pwquality %}
7474password {{ 'sufficient' if sssd else 'required' }} pam_unix.so try_first_pass {{ unix_authtok| default('', true) }} {{ nullok| default('', true) }} {{ unix_extended_encryption| default('', true) }} {{ debug| default('', true) }}
7575{% else %}
76- password {{ 'sufficient' if sssd else 'required' }} pam_unix.so try_first_pass {{ nullok| default('', true) }} {{ unix_extended_encryption| default('', true) }} {{ debug| default('', true) }}
76+ password {{ 'sufficient' if sssd else 'required' }} pam_unix.so try_first_pass {{ nullok| default('', true) }} {{ unix_extended_encryption| default('', true) }} {{ debug| default('', true) }}
7777{% endif %}
7878
7979{% if sssd %}
0 commit comments