Merge pull request #25502 from keszybz/pam-namespace-add

Add pam_namespace to user@.service pam stack
This commit is contained in:
Luca Boccassi 2022-12-07 13:01:50 +01:00 committed by GitHub
commit 87edf80b1b
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -4,18 +4,19 @@
# Used by systemd --user instances.
{% if ENABLE_HOMED %}
-account sufficient pam_systemd_home.so
-account sufficient pam_systemd_home.so
{% endif %}
account sufficient pam_unix.so no_pass_expiry
account required pam_permit.so
account sufficient pam_unix.so no_pass_expiry
account required pam_permit.so
{% if HAVE_SELINUX %}
session required pam_selinux.so close
session required pam_selinux.so nottys open
session required pam_selinux.so close
session required pam_selinux.so nottys open
{% endif %}
session required pam_loginuid.so
session optional pam_keyinit.so force revoke
session required pam_loginuid.so
session optional pam_keyinit.so force revoke
session required pam_namespace.so
{% if ENABLE_HOMED %}
-session optional pam_systemd_home.so
-session optional pam_systemd_home.so
{% endif %}
session optional pam_systemd.so
session optional pam_systemd.so