diff options
author | Viacheslav Hletenko <v.gletenko@vyos.io> | 2023-09-07 17:18:53 +0000 |
---|---|---|
committer | Viacheslav Hletenko <v.gletenko@vyos.io> | 2023-09-08 12:24:16 +0000 |
commit | 01b30eb6d83cdb2ae43b956d29ac7ac1d4445776 (patch) | |
tree | b2c42e622f2b3f7ab19530f4574e4da36d4cc865 /src/pam-configs | |
parent | c57a519ea9af262f410e9e6887684e772f34fe69 (diff) | |
download | vyos-1x-01b30eb6d83cdb2ae43b956d29ac7ac1d4445776.tar.gz vyos-1x-01b30eb6d83cdb2ae43b956d29ac7ac1d4445776.zip |
T5554: Disable sudo for PAM RADIUS
Disable sudo for PAM RADIUS template that slows down the CLI commands
To fix it add:
session [default=ignore success=2] pam_succeed_if.so service = sudo
Diffstat (limited to 'src/pam-configs')
-rw-r--r-- | src/pam-configs/radius | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/src/pam-configs/radius b/src/pam-configs/radius index 08247f77c..eee9cb93e 100644 --- a/src/pam-configs/radius +++ b/src/pam-configs/radius @@ -3,15 +3,18 @@ Default: no Priority: 257 Auth-Type: Primary Auth: + [default=ignore success=2] pam_succeed_if.so service = sudo [default=ignore success=ignore] pam_succeed_if.so user ingroup aaa quiet [authinfo_unavail=ignore success=end default=ignore] pam_radius_auth.so Account-Type: Primary Account: + [default=ignore success=2] pam_succeed_if.so service = sudo [default=ignore success=ignore] pam_succeed_if.so user ingroup aaa quiet [authinfo_unavail=ignore success=end perm_denied=bad default=ignore] pam_radius_auth.so Session-Type: Additional Session: + [default=ignore success=2] pam_succeed_if.so service = sudo [default=ignore success=ignore] pam_succeed_if.so user ingroup aaa quiet [authinfo_unavail=ignore success=ok default=ignore] pam_radius_auth.so |