summaryrefslogtreecommitdiff
path: root/src/pam-configs/radius-mandatory
diff options
context:
space:
mode:
authorChristian Breunig <christian@breunig.cc>2023-11-21 10:08:20 +0100
committerGitHub <noreply@github.com>2023-11-21 10:08:20 +0100
commitbdf0a3b288f93f2e8257106de968ddaa3fca0e21 (patch)
treeb44029f81f1a47a86b475a00d0b22587addfd2db /src/pam-configs/radius-mandatory
parent471e26233e2e1c7b4ad20aff673a18ac5d745296 (diff)
parentd7457268fcaa5626e512eb00a9aab36f4a617f28 (diff)
downloadvyos-1x-bdf0a3b288f93f2e8257106de968ddaa3fca0e21.tar.gz
vyos-1x-bdf0a3b288f93f2e8257106de968ddaa3fca0e21.zip
Merge pull request #2513 from zdc/T5577-equuleus
PAM: T5577: Optimized RADIUS PAM config (backport from circinus)
Diffstat (limited to 'src/pam-configs/radius-mandatory')
-rw-r--r--src/pam-configs/radius-mandatory19
1 files changed, 19 insertions, 0 deletions
diff --git a/src/pam-configs/radius-mandatory b/src/pam-configs/radius-mandatory
new file mode 100644
index 000000000..3368fe7ff
--- /dev/null
+++ b/src/pam-configs/radius-mandatory
@@ -0,0 +1,19 @@
+Name: RADIUS authentication (mandatory mode)
+Default: no
+Priority: 576
+
+Auth-Type: Primary
+Auth-Initial:
+ [default=ignore success=end auth_err=die perm_denied=die user_unknown=die] pam_radius_auth.so
+Auth:
+ [default=ignore success=end auth_err=die perm_denied=die user_unknown=die] pam_radius_auth.so use_first_pass
+
+Account-Type: Primary
+Account:
+ [default=ignore success=1] pam_succeed_if.so user notingroup radius quiet
+ [default=ignore success=end] pam_radius_auth.so
+
+Session-Type: Additional
+Session:
+ [default=ignore success=1] pam_succeed_if.so user notingroup radius quiet
+ [default=bad success=ok] pam_radius_auth.so