diff options
author | Christian Breunig <christian@breunig.cc> | 2023-09-29 07:26:31 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2023-09-29 07:26:31 +0200 |
commit | 400df973d3518e9f18cb84b52ca89e08a399e461 (patch) | |
tree | 9b9e06d73009065ecbac1d5a4da2cb94018d7e53 /src/pam-configs/radius-mandatory | |
parent | fed59f9bddead060275f368de69e4e4470015ca9 (diff) | |
parent | 784fb7dc2ccc63789ed85d803e3ae41eef0e0253 (diff) | |
download | vyos-1x-400df973d3518e9f18cb84b52ca89e08a399e461.tar.gz vyos-1x-400df973d3518e9f18cb84b52ca89e08a399e461.zip |
Merge pull request #2256 from zdc/T5577-circinus
T5577: Optimized PAM configs for RADIUS/TACACS+
Diffstat (limited to 'src/pam-configs/radius-mandatory')
-rw-r--r-- | src/pam-configs/radius-mandatory | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/src/pam-configs/radius-mandatory b/src/pam-configs/radius-mandatory new file mode 100644 index 000000000..3368fe7ff --- /dev/null +++ b/src/pam-configs/radius-mandatory @@ -0,0 +1,19 @@ +Name: RADIUS authentication (mandatory mode) +Default: no +Priority: 576 + +Auth-Type: Primary +Auth-Initial: + [default=ignore success=end auth_err=die perm_denied=die user_unknown=die] pam_radius_auth.so +Auth: + [default=ignore success=end auth_err=die perm_denied=die user_unknown=die] pam_radius_auth.so use_first_pass + +Account-Type: Primary +Account: + [default=ignore success=1] pam_succeed_if.so user notingroup radius quiet + [default=ignore success=end] pam_radius_auth.so + +Session-Type: Additional +Session: + [default=ignore success=1] pam_succeed_if.so user notingroup radius quiet + [default=bad success=ok] pam_radius_auth.so |