aboutsummaryrefslogtreecommitdiffstats
path: root/modules/pam
diff options
context:
space:
mode:
authorOlivier Blin <dev@blino.org>2017-02-21 00:03:35 +0100
committerOlivier Blin <dev@blino.org>2017-02-21 00:21:18 +0100
commit614b8e6ccd66758b82e01ac569c0860f9ec603d1 (patch)
treecad479db7259487be6d8d56f12931d8c644f529d /modules/pam
parentaf5755008e0b640979d321bc2019e9c7be8fe194 (diff)
downloadpuppet-614b8e6ccd66758b82e01ac569c0860f9ec603d1.tar
puppet-614b8e6ccd66758b82e01ac569c0860f9ec603d1.tar.gz
puppet-614b8e6ccd66758b82e01ac569c0860f9ec603d1.tar.bz2
puppet-614b8e6ccd66758b82e01ac569c0860f9ec603d1.tar.xz
puppet-614b8e6ccd66758b82e01ac569c0860f9ec603d1.zip
Allow mga-unrestricted_shell_access group login on all nodes
Diffstat (limited to 'modules/pam')
-rw-r--r--modules/pam/templates/system-auth1
1 files changed, 1 insertions, 0 deletions
diff --git a/modules/pam/templates/system-auth b/modules/pam/templates/system-auth
index 4afe24a5..6ce40a9d 100644
--- a/modules/pam/templates/system-auth
+++ b/modules/pam/templates/system-auth
@@ -11,6 +11,7 @@ auth required pam_deny.so
account sufficient pam_localuser.so
# not sure if the following bring something useful
account required pam_ldap.so
+account sufficient pam_succeed_if.so quiet user ingroup mga-unrestricted_shell_access
<%- access_classes = scope.lookupvar('pam::multiple_ldap_access::access_classes') -%>
<%- if access_classes -%>
<%- access_classes.each { |ldap_group| -%>