[arch-commits] Commit in pambase/repos (8 files)

Jan Steffens heftig at gemini.archlinux.org
Fri Dec 10 13:55:25 UTC 2021


    Date: Friday, December 10, 2021 @ 13:55:25
  Author: heftig
Revision: 431821

archrelease: copy trunk to testing-any

Added:
  pambase/repos/testing-any/
  pambase/repos/testing-any/PKGBUILD
    (from rev 431820, pambase/trunk/PKGBUILD)
  pambase/repos/testing-any/other
    (from rev 431820, pambase/trunk/other)
  pambase/repos/testing-any/system-auth
    (from rev 431820, pambase/trunk/system-auth)
  pambase/repos/testing-any/system-local-login
    (from rev 431820, pambase/trunk/system-local-login)
  pambase/repos/testing-any/system-login
    (from rev 431820, pambase/trunk/system-login)
  pambase/repos/testing-any/system-remote-login
    (from rev 431820, pambase/trunk/system-remote-login)
  pambase/repos/testing-any/system-services
    (from rev 431820, pambase/trunk/system-services)

---------------------+
 PKGBUILD            |   34 ++++++++++++++++++++++++++++++++++
 other               |    9 +++++++++
 system-auth         |   27 +++++++++++++++++++++++++++
 system-local-login  |    6 ++++++
 system-login        |   19 +++++++++++++++++++
 system-remote-login |    6 ++++++
 system-services     |   11 +++++++++++
 7 files changed, 112 insertions(+)

Copied: pambase/repos/testing-any/PKGBUILD (from rev 431820, pambase/trunk/PKGBUILD)
===================================================================
--- testing-any/PKGBUILD	                        (rev 0)
+++ testing-any/PKGBUILD	2021-12-10 13:55:25 UTC (rev 431821)
@@ -0,0 +1,34 @@
+# Maintainer: Dave Reisner <dreisner at archlinux.org>
+
+pkgname=pambase
+pkgver=20211210
+pkgrel=1
+pkgdesc="Base PAM configuration for services"
+arch=('any')
+url="https://www.archlinux.org"
+license=('GPL')
+source=('system-auth'
+        'system-local-login'
+        'system-login'
+        'system-remote-login'
+        'system-services'
+        'other')
+backup=('etc/pam.d/system-auth'
+        'etc/pam.d/system-local-login'
+        'etc/pam.d/system-login'
+        'etc/pam.d/system-remote-login'
+        'etc/pam.d/system-services'
+        'etc/pam.d/other')
+sha256sums=('d3f6c7465198415df7bc3b365595642c7255dd69f2d7db548eb071123f43164c'
+            '005736b9bd650ff5e5d82a7e288853776d5bb8c90185d5774c07231c1e1c64a9'
+            '0f06cbc63a4b95fd3f863561e2ff193f231d749f69ce23c57393234dbca6edfd'
+            '005736b9bd650ff5e5d82a7e288853776d5bb8c90185d5774c07231c1e1c64a9'
+            '6eb1acdd3fa9f71a7f93fbd529be57ea65bcafc6e3a98a06af4d88013fc6a567'
+            'd5ed59ec2157c19c87964a162f7ca84d53c19fb2bd68d3fbc1671ba8d906346f')
+
+package() {
+  install -dm755 "$pkgdir/etc/pam.d"
+  install -m644 -t "$pkgdir/etc/pam.d" "${source[@]}"
+}
+
+# vim:set ts=2 sw=2 et:

Copied: pambase/repos/testing-any/other (from rev 431820, pambase/trunk/other)
===================================================================
--- testing-any/other	                        (rev 0)
+++ testing-any/other	2021-12-10 13:55:25 UTC (rev 431821)
@@ -0,0 +1,9 @@
+#%PAM-1.0
+auth      required   pam_deny.so
+auth      required   pam_warn.so
+account   required   pam_deny.so
+account   required   pam_warn.so
+password  required   pam_deny.so
+password  required   pam_warn.so
+session   required   pam_deny.so
+session   required   pam_warn.so

Copied: pambase/repos/testing-any/system-auth (from rev 431820, pambase/trunk/system-auth)
===================================================================
--- testing-any/system-auth	                        (rev 0)
+++ testing-any/system-auth	2021-12-10 13:55:25 UTC (rev 431821)
@@ -0,0 +1,27 @@
+#%PAM-1.0
+
+auth       required                    pam_faillock.so      preauth
+# Optionally use requisite above if you do not want to prompt for the password
+# on locked accounts.
+-auth      [success=2 default=ignore]  pam_systemd_home.so
+auth       [success=1 default=bad]     pam_unix.so          try_first_pass nullok
+auth       [default=die]               pam_faillock.so      authfail
+auth       optional                    pam_permit.so
+auth       required                    pam_env.so
+auth       required                    pam_faillock.so      authsucc
+# If you drop the above call to pam_faillock.so the lock will be done also
+# on non-consecutive authentication failures.
+
+-account   [success=1 default=ignore]  pam_systemd_home.so
+account    required                    pam_unix.so
+account    optional                    pam_permit.so
+account    required                    pam_time.so
+
+-password  [success=1 default=ignore]  pam_systemd_home.so
+password   required                    pam_unix.so          try_first_pass nullok shadow sha512
+password   optional                    pam_permit.so
+
+-session   optional                    pam_systemd_home.so
+session    required                    pam_limits.so
+session    required                    pam_unix.so
+session    optional                    pam_permit.so

Copied: pambase/repos/testing-any/system-local-login (from rev 431820, pambase/trunk/system-local-login)
===================================================================
--- testing-any/system-local-login	                        (rev 0)
+++ testing-any/system-local-login	2021-12-10 13:55:25 UTC (rev 431821)
@@ -0,0 +1,6 @@
+#%PAM-1.0
+
+auth      include   system-login
+account   include   system-login
+password  include   system-login
+session   include   system-login

Copied: pambase/repos/testing-any/system-login (from rev 431820, pambase/trunk/system-login)
===================================================================
--- testing-any/system-login	                        (rev 0)
+++ testing-any/system-login	2021-12-10 13:55:25 UTC (rev 431821)
@@ -0,0 +1,19 @@
+#%PAM-1.0
+
+auth       required   pam_shells.so
+auth       requisite  pam_nologin.so
+auth       include    system-auth
+
+account    required   pam_access.so
+account    required   pam_nologin.so
+account    include    system-auth
+
+password   include    system-auth
+
+session    optional   pam_loginuid.so
+session    optional   pam_keyinit.so       force revoke
+session    include    system-auth
+session    optional   pam_motd.so
+session    optional   pam_mail.so          dir=/var/spool/mail standard quiet
+-session   optional   pam_systemd.so
+session    required   pam_env.so           user_readenv=1

Copied: pambase/repos/testing-any/system-remote-login (from rev 431820, pambase/trunk/system-remote-login)
===================================================================
--- testing-any/system-remote-login	                        (rev 0)
+++ testing-any/system-remote-login	2021-12-10 13:55:25 UTC (rev 431821)
@@ -0,0 +1,6 @@
+#%PAM-1.0
+
+auth      include   system-login
+account   include   system-login
+password  include   system-login
+session   include   system-login

Copied: pambase/repos/testing-any/system-services (from rev 431820, pambase/trunk/system-services)
===================================================================
--- testing-any/system-services	                        (rev 0)
+++ testing-any/system-services	2021-12-10 13:55:25 UTC (rev 431821)
@@ -0,0 +1,11 @@
+#%PAM-1.0
+
+auth      sufficient  pam_permit.so
+
+account   include     system-auth
+
+session   optional    pam_loginuid.so
+session   required    pam_limits.so
+session   required    pam_unix.so
+session   optional    pam_permit.so
+session   required    pam_env.so



More information about the arch-commits mailing list