X-Git-Url: https://git.stderr.nl/gitweb?a=blobdiff_plain;ds=sidebyside;f=etc%2Fpam.d%2Fcommon-account;fp=etc%2Fpam.d%2Fcommon-account;h=c2e28cb63cfba5a05ecd5a4ac3d131dea167b1b9;hb=6729d356bc9bb1c6b0e625fd68d2c4cdc3ed75fa;hp=6798301962a745e7d5a8ea9b2f9d26b172eb3cbd;hpb=124843581cd36d647cc396209f695b7f45d198bd;p=matthijs%2Fservers%2Fdrsnuggles.git diff --git a/etc/pam.d/common-account b/etc/pam.d/common-account index 6798301..c2e28cb 100644 --- a/etc/pam.d/common-account +++ b/etc/pam.d/common-account @@ -6,4 +6,12 @@ # the central access policy for use on the system. The default is to # only deny service to users whose accounts are expired in /etc/shadow. # -account required pam_unix.so +# Default was: +#account required pam_unix.so +# +# LDAP config copied from http://wiki.debian.org/LDAP/PAM +account required pam_unix.so +account sufficient pam_succeed_if.so uid < 1000 quiet +account [default=bad success=ok user_unknown=ignore] pam_ldap.so +account required pam_permit.so +