Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | templates/system-auth.tpl: fix libcap module namepambase-20201026 | Sam James | 2020-10-26 | 1 | -1/+1 |
| | | | | | Bug: https://bugs.gentoo.org/750524 Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | templates/system-auth.tpl: skip pam_unix with krb5 | Sam James | 2020-10-26 | 1 | -4/+4 |
| | | | | | | | | | | | Before this change, success on pam_krb5 would result in jumping one line (over pam_permit) back into pam_unix. Incidentally, we did the later stanza correctly. This was a regression from old pambase. Bug: https://bugs.gentoo.org/748405 Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | templates/system-login.tpl: always need faillock | Sam James | 2020-10-26 | 2 | -4/+0 |
| | | | | | Fixes: eb138196aa2d3cb860d5eb5ab1d05985df34ad2c Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | templates/system-auth.tpl: use faillock in minimal casepambase-20201020 | Sam James | 2020-10-20 | 1 | -5/+2 |
| | | | | | Bug: https://bugs.gentoo.org/748405 Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | templates/system-auth.tpl: drop superfluous conf param on faillockpambase-20201013 | Sam James | 2020-10-12 | 1 | -1/+1 |
| | | | | | | | pam_faillock defaults to /etc/security/faillock.conf anyway. Closes: https://bugs.gentoo.org/747967 Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | templates/system-login.tpl: remove duplicate block already in system-auth | Sam James | 2020-10-12 | 2 | -6/+5 |
| | | | | | | Do it right this time! Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | templates/system-login.tpl: remove duplicate block from system-auth (again) | Sam James | 2020-10-12 | 2 | -5/+6 |
|\ | | | | | | | Signed-off-by: Sam James <sam@gentoo.org> | ||||
| * | switch pam_faillock.so to its config filepambase-20201010 | Mikle Kolyada | 2020-10-10 | 2 | -4/+4 |
| | | | | | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | | templates/system-login.tpl: move systemd, elogind blocks here | Sam James | 2020-10-12 | 2 | -8/+8 |
| | | | | | | | | Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | | templates/system-login.tpl: remove duplicate block from system-auth | Sam James | 2020-10-12 | 1 | -5/+0 |
| | | | | | | | | | | Bug: https://bugs.gentoo.org/747868 Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | | templates/system-session.tpl: include pam_krb5.so module name | Sam James | 2020-10-12 | 1 | -4/+1 |
|/ | | | | Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | system-auth: introduce pam_pwhistorypambase-20200917 | Mikle Kolyada | 2020-09-13 | 2 | -0/+5 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | system-auth: switch password modules to configs | Mikle Kolyada | 2020-09-09 | 1 | -2/+2 |
| | | | | | | | | | | * pam_passwdqc.so can by managed by the /etc/security/passwdqc.conf * pam_pwquality.so can be managed by the /etc/security/pwquality.conf Both allow users to create their own password polices without touching files in the /etc/pam.d directory Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | make pam_gnome_keyring optionalpambase-20200817 | Mikle Kolyada | 2020-08-17 | 2 | -72/+76 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | Add pam_pwquality.so supportpambase-20200815 | Mikle Kolyada | 2020-08-15 | 2 | -0/+5 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | pambase.py: rename system-service -> system-servicespambase-20200806 | Sam James | 2020-08-06 | 2 | -1/+1 |
| | | | | | | | | Some of e.g. OpenRC's installed pam files assume 'system-services': ./supervise-daemon:2:session include system-services ./start-stop-daemon:2:session include system-services Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | pambase.py: strip trailing whitespace in stackpambase-20200805 | Sam James | 2020-08-05 | 1 | -1/+1 |
| | | | | Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | templates/*: remove unnecessary strips | Sam James | 2020-08-05 | 4 | -44/+44 |
| | | | | | | Now obsolete as of 732fb3bbfd7d007fdca78dd4587f1a7bd34bfa6c. Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | pambase.py: strip all blank lines | Sam James | 2020-08-05 | 1 | -1/+6 |
| | | | | | | | It's simpler to do this in pambase.py than with Jinja 2, at least for now. Signed-off-by: Sam James <sam@gentoo.org> | ||||
* | fix pam_ssh formattingpambase-20200804 | Mikle Kolyada | 2020-08-04 | 1 | -1/+1 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | fix a typo in logic | Mikle Kolyada | 2020-08-04 | 1 | -1/+1 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | New pambase era | Mikle Kolyada | 2020-08-04 | 23 | -365/+252 |
| | | | | | | pambase was simplified and rewritten in python Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | move faillock last in authpambase-20200618historical | Mikle Kolyada | 2020-06-18 | 2 | -11/+12 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | fix a typo | Mikle Kolyada | 2020-06-17 | 1 | -1/+1 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | iprove faillock support | Mikle Kolyada | 2020-06-16 | 2 | -2/+17 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | Revert "allow clang-cpp" | Mikle Kolyada | 2020-06-10 | 1 | -1/+1 |
| | | | | | | This reverts commit 4a97472903679c7d85ca391aeedaea3ce7797acf. Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | New release | Mikle Kolyada | 2020-06-10 | 5 | -19/+7 |
| | | | | | | | - disable cracklib in favor of passwdqc - disable tally{,2} in favor of faillock Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | allow clang-cpp | Mikle Kolyada | 2020-04-30 | 1 | -1/+1 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | Run pam_env.so after pam_systemd.so for better socket supportpambase-20200304 | David Seifert | 2020-03-04 | 1 | -1/+1 |
| | | | | | | | | | * Running pam_systemd.so before setting user environment variables makes it possible for the user to use variables such as `XDG_RUNTIME_DIR` in their own definitions. Bug: https://bugs.gentoo.org/711450 Signed-off-by: David Seifert <soap@gentoo.org> | ||||
* | handle envfile with pam_env.sopambase-20191128 | Mikle Kolyada | 2019-11-28 | 2 | -1/+1 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | fix libcap function call | Mikle Kolyada | 2019-11-27 | 1 | -1/+1 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | integrate libcap support | Mikle Kolyada | 2019-11-24 | 3 | -0/+8 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | remove openpam support | Mikle Kolyada | 2019-11-15 | 2 | -30/+1 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | add vital patches into the sourcespambase-20190402 | Mikle Kolyada | 2019-04-02 | 4 | -13/+13 |
| | | | | Signed-off-by: Mikle Kolyada <zlogene@gentoo.org> | ||||
* | system-login: fix nested selinux comment | Sven Vermeulen | 2015-05-17 | 1 | -1/+1 |
| | | | | URL: https://bugs.gentoo.org/540096 | ||||
* | system-login: move pam_gnome_keyring after pam_selinuxpambase-20150213 | Mike Frysinger | 2015-02-13 | 1 | -3/+4 |
| | | | | URL: https://bugs.gentoo.org/511600 | ||||
* | trim trailing whitespace | Mike Frysinger | 2015-02-13 | 3 | -8/+6 |
| | |||||
* | make nullok into a build time option | Mike Frysinger | 2015-02-13 | 3 | -2/+12 |
| | |||||
* | make securetty optional | Mike Frysinger | 2015-02-13 | 2 | -0/+6 |
| | | | | URL: https://bugs.gentoo.org/539508 | ||||
* | Use xz instead of bzip2 for dist. | Samuli Suominen | 2014-03-13 | 1 | -3/+3 |
| | |||||
* | Import -lastlog-silent.patch from gentoo-x86, see bug #468798pambase-20140313 | Samuli Suominen | 2014-03-13 | 2 | -1/+3 |
| | |||||
* | Import -systemd.patch and -systemd-auth.patch from gentoo-x86, see both bugs ↵ | Samuli Suominen | 2014-03-13 | 2 | -0/+8 |
| | | | | #372229 and #485470 | ||||
* | Add pam.d files for login, passwd and su.pambase-20120417 | Pawel Hajdan, Jr | 2012-03-20 | 5 | -1/+28 |
| | | | | Those should be shared between shadow implementations. | ||||
* | Implement support for pam_loginuid as needed for bug #342345pambase-20101024 | Diego Elio Pettenò | 2010-10-24 | 3 | -0/+7 |
| | |||||
* | Add support for building minimal PAM chains.pambase-20100925pambase-20100903 | Diego Elio Pettenò | 2010-09-03 | 3 | -8/+20 |
| | | | | | | When setting the MINIMAL flag on, the generated PAM chains will not use tally, motd, mail or lastlog modules, making th elogin quiet and skipping over the update of the login files. | ||||
* | Also protect account and password from pam_krb5 bad jumps.pambase-20100819 | Diego Elio 'Flameeyes' Pettenò | 2010-08-19 | 1 | -0/+4 |
| | | | | Thanks to Simon Alman for reporting, in bug #333393 | ||||
* | Make sure that there is a space between password and session.pambase-20100724 | Diego Elio 'Flameeyes' Pettenò | 2010-07-24 | 1 | -1/+1 |
| | |||||
* | Fix kerberos authentication. | Diego Elio 'Flameeyes' Pettenò | 2010-07-24 | 1 | -1/+3 |
| | |||||
* | Don't define UNIX_AUTHTOK to use_authtok if no former module is called.pambase-20100723 | Diego Elio 'Flameeyes' Pettenò | 2010-07-23 | 1 | -1/+1 |
| | |||||
* | Add support for pam_krb5 module for Kerberos authentication. | Diego Elio 'Flameeyes' Pettenò | 2010-07-23 | 4 | -4/+55 |
| | | | | | | | | This implements drop-in support for Kerberos (pam_krb5) in Gentoo systems; if the kerberos USE flag has been enabled, it'll use pam_krb5 for login, ignoring pam_unix, but no other module in the chain. It requires Linux-PAM. |