summaryrefslogtreecommitdiff
path: root/src/pam-configs/tacplus-optional
diff options
context:
space:
mode:
authorChristian Breunig <christian@breunig.cc>2023-11-21 10:08:03 +0100
committerGitHub <noreply@github.com>2023-11-21 10:08:03 +0100
commit916adfaf0774df0731522bf3cbd886d794735c50 (patch)
treeb043c0e29103c814467239ea8d729c6ecc4d6d49 /src/pam-configs/tacplus-optional
parentcec47950a5d30944c0063723d3967cd17502d6b1 (diff)
parente1bf5516bbb00de5689a1091a6e21b1fc45a7340 (diff)
downloadvyos-1x-916adfaf0774df0731522bf3cbd886d794735c50.tar.gz
vyos-1x-916adfaf0774df0731522bf3cbd886d794735c50.zip
Merge pull request #2512 from zdc/T5577-sagitta
PAM: T5577: Backported PAM settings from circinus
Diffstat (limited to 'src/pam-configs/tacplus-optional')
-rw-r--r--src/pam-configs/tacplus-optional17
1 files changed, 17 insertions, 0 deletions
diff --git a/src/pam-configs/tacplus-optional b/src/pam-configs/tacplus-optional
new file mode 100644
index 000000000..095c3a164
--- /dev/null
+++ b/src/pam-configs/tacplus-optional
@@ -0,0 +1,17 @@
+Name: TACACS+ authentication (optional mode)
+Default: no
+Priority: 576
+
+Auth-Type: Primary
+Auth:
+ [default=ignore success=end] pam_tacplus.so include=/etc/tacplus_servers login=login
+
+Account-Type: Primary
+Account:
+ [default=ignore success=1] pam_succeed_if.so user notingroup tacacs quiet
+ [default=ignore success=end auth_err=bad perm_denied=bad user_unknown=bad] pam_tacplus.so include=/etc/tacplus_servers login=login
+
+Session-Type: Additional
+Session:
+ [default=ignore success=1] pam_succeed_if.so user notingroup tacacs quiet
+ [default=ignore success=ok session_err=bad user_unknown=bad] pam_tacplus.so include=/etc/tacplus_servers login=login