Files
ansible-role-auth-duo/files/etc.pam.d.sshd
Aaron Guise e22ae689df
Some checks failed
CI / lint (push) Successful in 1m50s
CI / Molecule Test (almalinux8) (push) Successful in 2m54s
CI / Molecule Test (almalinux9) (push) Successful in 2m32s
CI / release (push) Successful in 35s
CI / notify (push) Failing after 5s
fix: Updated with default configs from RHEL 9
2024-12-30 08:25:51 +13:00

20 lines
832 B
Plaintext

#%PAM-1.0
auth substack password-auth
auth required pam_env.so
auth sufficient pam_duo.so
auth required pam_deny.so
auth include postlogin
account required pam_sepermit.so
account required pam_nologin.so
account include password-auth
password include password-auth
# pam_selinux.so close should be the first session rule
session required pam_selinux.so close
session required pam_loginuid.so
# pam_selinux.so open should only be followed by sessions to be executed in the user context
session required pam_selinux.so open env_params
session required pam_namespace.so
session optional pam_keyinit.so force revoke
session optional pam_motd.so
session include password-auth
session include postlogin