2bd19e3f8f
Use pam-config package to package config files for pam package. We can remove related patch of pam and use RPM instead of SRPM for pam. Deployment test and ping test between VMs pass Config files check pass. Story: 2003768 Task: 27589 Depends-on: https://review.openstack.org/#/c/617454/ Change-Id: Ib19aa8ef023c184c7dcf0e4086adb516be0d947d Signed-off-by: zhipengl <zhipengs.liu@intel.com>
28 lines
1.4 KiB
Plaintext
Executable File
28 lines
1.4 KiB
Plaintext
Executable File
#
|
|
# /etc/pam.d/common-account - authorization settings common to all services
|
|
#
|
|
# This file is included from other service-specific PAM config files,
|
|
# and should contain a list of the authorization modules that define
|
|
# the central access policy for use on the system. The default is to
|
|
# only deny service to users whose accounts are expired in /etc/shadow.
|
|
#
|
|
# As of pam 1.0.1-6, this file is managed by pam-auth-update by default.
|
|
# To take advantage of this, it is recommended that you configure any
|
|
# local modules either before or after the default block, and use
|
|
# pam-auth-update to manage selection of other modules. See
|
|
# pam-auth-update(8) for details.
|
|
#
|
|
|
|
# here are the per-package modules (the "Primary" block)
|
|
account required pam_tally2.so
|
|
account [success=2 new_authtok_reqd=done default=ignore] pam_unix.so
|
|
account [success=1 new_authtok_reqd=done default=ignore] pam_ldap.so
|
|
# here's the fallback if no module succeeds
|
|
account requisite pam_deny.so
|
|
# prime the stack with a positive return value if there isn't one already;
|
|
# this avoids us returning an error just because nothing sets a success code
|
|
# since the modules above will each just jump around
|
|
account required pam_permit.so
|
|
# and here are more per-package modules (the "Additional" block)
|
|
# end of pam-auth-update config
|