diff --git a/pam.spec b/pam.spec index c528256..bd7b374 100644 --- a/pam.spec +++ b/pam.spec @@ -19,7 +19,7 @@ Epoch: 1 Summary: A security tool which provides authentication for applications Name: pam Version: 1.1.4 -Release: 11 +Release: 12 # The library is BSD licensed with option to relicense as GPLv2+ - this option is redundant # as the BSD license allows that anyway. pam_timestamp and pam_console modules are GPLv2+, License: BSD and GPLv2+ diff --git a/system-auth.pamd b/system-auth.pamd index 54011bc..e87961c 100644 --- a/system-auth.pamd +++ b/system-auth.pamd @@ -1,17 +1,17 @@ #%PAM-1.0 auth required pam_env.so -auth sufficient pam_tcb.so shadow nullok prefix=$2a$ count=8 +auth sufficient pam_unix.so try_first_pass nullok auth required pam_deny.so -account required pam_tcb.so shadow +account required pam_unix.so -password required pam_cracklib.so try_first_pass retry=3 -password sufficient pam_tcb.so shadow write_to=shadow nullok prefix=$2a$ count=8 +password required pam_cracklib.so try_first_pass use_authtok retry=3 +password sufficient pam_unix.so try_first_pass shadow nullok md5 password required pam_deny.so session optional pam_keyinit.so revoke session required pam_limits.so session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid -session required pam_tcb.so +session required pam_unix.so -session optional pam_systemd.so