summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorViacheslav Hletenko <v.gletenko@vyos.io>2023-09-07 17:18:53 +0000
committerViacheslav Hletenko <v.gletenko@vyos.io>2023-09-08 15:44:07 +0000
commit7682e148fcf7e54baad71e3126e3b7b6232cd696 (patch)
treeaeec3fa23c89bdebd9a090c5f65b1d768d226fe5
parentbf287c6ef35fea6d4deb04c88c56a99e9768d36d (diff)
downloadvyos-1x-7682e148fcf7e54baad71e3126e3b7b6232cd696.tar.gz
vyos-1x-7682e148fcf7e54baad71e3126e3b7b6232cd696.zip
T5554: Disable sudo for PAM RADIUS
Disable sudo for PAM RADIUS template that slows down the CLI commands To fix it add: session [default=ignore success=2] pam_succeed_if.so service = sudo (cherry picked from commit 01b30eb6d83cdb2ae43b956d29ac7ac1d4445776)
-rw-r--r--src/pam-configs/radius3
1 files changed, 3 insertions, 0 deletions
diff --git a/src/pam-configs/radius b/src/pam-configs/radius
index 08247f77c..eee9cb93e 100644
--- a/src/pam-configs/radius
+++ b/src/pam-configs/radius
@@ -3,15 +3,18 @@ Default: no
Priority: 257
Auth-Type: Primary
Auth:
+ [default=ignore success=2] pam_succeed_if.so service = sudo
[default=ignore success=ignore] pam_succeed_if.so user ingroup aaa quiet
[authinfo_unavail=ignore success=end default=ignore] pam_radius_auth.so
Account-Type: Primary
Account:
+ [default=ignore success=2] pam_succeed_if.so service = sudo
[default=ignore success=ignore] pam_succeed_if.so user ingroup aaa quiet
[authinfo_unavail=ignore success=end perm_denied=bad default=ignore] pam_radius_auth.so
Session-Type: Additional
Session:
+ [default=ignore success=2] pam_succeed_if.so service = sudo
[default=ignore success=ignore] pam_succeed_if.so user ingroup aaa quiet
[authinfo_unavail=ignore success=ok default=ignore] pam_radius_auth.so