kanidm/platform/debian/kanidm-unixd/kanidm.pam
jian c66a401b31
Reduce pam_kanidm's priority in Debian platforms (#2209)
`pam_kanidm` doesn't set AUTHTOK after reading from user input, so modules down the stack will have to ask for passwords redundantly. This is only a workaround, and might not be the desired behaviour in all cases.
2023-10-11 13:16:19 +10:00

20 lines
425 B
Plaintext

Name: Kanidm Authentication
Default: yes
Priority: 128
Auth-Type: Primary
Auth:
[success=end new_authtok_reqd=done default=ignore] pam_kanidm.so ignore_unknown_user
Account-Type: Primary
Account:
[success=end new_authtok_reqd=done default=ignore] pam_kanidm.so ignore_unknown_user
Session-Type: Additional
Session:
optional pam_kanidm.so
Password-Type: Additional
Password:
optional pam_kanidm.so