<feed xmlns='http://www.w3.org/2005/Atom'>
<title>vyos-1x.git/src/pam-configs/radius, branch current-merge-commit-handling</title>
<subtitle>VyOS command definitions, scripts, and utilities (mirror of https://github.com/vyos/vyos-1x.git)
</subtitle>
<id>https://git.amelek.net/vyos/vyos-1x.git/atom?h=current-merge-commit-handling</id>
<link rel='self' href='https://git.amelek.net/vyos/vyos-1x.git/atom?h=current-merge-commit-handling'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/'/>
<updated>2023-09-13T17:41:43+00:00</updated>
<entry>
<title>RADIUS: T5577: Added `mandatory` and `optional` modes for RADIUS</title>
<updated>2023-09-13T17:41:43+00:00</updated>
<author>
<name>zsdc</name>
<email>taras@vyos.io</email>
</author>
<published>2023-09-13T09:41:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=5181ab60bb6d936505967d6667adc12c5ecb9b64'/>
<id>urn:sha1:5181ab60bb6d936505967d6667adc12c5ecb9b64</id>
<content type='text'>
In CLI we can choose authentication logic:

  - `mandatory` - if RADIUS answered with `Access-Reject`, authentication must
  be stopped and access denied immediately.
  - `optional` (default) - if RADIUS answers with `Access-Reject`,
  authentication continues using the next module.

In `mandatory` mode authentication will be stopped only if RADIUS clearly
answered that access should be denied (no user in RADIUS database, wrong
password, etc.). If RADIUS is not available or other errors happen, it will be
skipped and authentication will continue with the next module, like in
`optional` mode.
</content>
</entry>
<entry>
<title>T5554: Disable sudo for PAM RADIUS</title>
<updated>2023-09-08T12:24:16+00:00</updated>
<author>
<name>Viacheslav Hletenko</name>
<email>v.gletenko@vyos.io</email>
</author>
<published>2023-09-07T17:18:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=01b30eb6d83cdb2ae43b956d29ac7ac1d4445776'/>
<id>urn:sha1:01b30eb6d83cdb2ae43b956d29ac7ac1d4445776</id>
<content type='text'>
Disable sudo for PAM RADIUS template that slows down the CLI commands
To fix it add:

session [default=ignore success=2] pam_succeed_if.so service = sudo
</content>
</entry>
<entry>
<title>tacacs: T141: create new UNIX group for aaa</title>
<updated>2023-06-21T21:17:27+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2023-06-21T20:08:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=edc753ad22c03a7e96c6e2323cd551f50588d686'/>
<id>urn:sha1:edc753ad22c03a7e96c6e2323cd551f50588d686</id>
<content type='text'>
</content>
</entry>
<entry>
<title>radius: T3510: authenticated users must use /sbin/radius_shell as shell</title>
<updated>2021-05-02T15:13:40+00:00</updated>
<author>
<name>Christian Poessinger</name>
<email>christian@poessinger.com</email>
</author>
<published>2021-05-02T13:53:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=0e5a90ad70edbcc6334f1737a6855d02f8ffd130'/>
<id>urn:sha1:0e5a90ad70edbcc6334f1737a6855d02f8ffd130</id>
<content type='text'>
</content>
</entry>
<entry>
<title>login: radius: T2089: only query servers when uid matches ...</title>
<updated>2020-03-01T19:03:45+00:00</updated>
<author>
<name>Christian Poessinger</name>
<email>christian@poessinger.com</email>
</author>
<published>2020-03-01T19:03:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=fb3eba1d4623e63323c439682e2c7cc2dcb949e1'/>
<id>urn:sha1:fb3eba1d4623e63323c439682e2c7cc2dcb949e1</id>
<content type='text'>
Do not query RADIUS servers when commit is running started from a non RADIUS
user (localuser, root). This should reduce the overall system boot time.
</content>
</entry>
<entry>
<title>radius: T2022: support both local and radius login at the same time</title>
<updated>2020-02-09T14:14:34+00:00</updated>
<author>
<name>Christian Poessinger</name>
<email>christian@poessinger.com</email>
</author>
<published>2020-02-09T14:14:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=e76325e6902b9a857b9e544accd5b020439aa8e7'/>
<id>urn:sha1:e76325e6902b9a857b9e544accd5b020439aa8e7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>radius: T1948: supply PAM configuration template</title>
<updated>2020-02-05T18:35:32+00:00</updated>
<author>
<name>Christian Poessinger</name>
<email>christian@poessinger.com</email>
</author>
<published>2020-02-05T18:33:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=74329734d3c465675ec3650cb2b8d1cbe8ec0885'/>
<id>urn:sha1:74329734d3c465675ec3650cb2b8d1cbe8ec0885</id>
<content type='text'>
</content>
</entry>
</feed>
