From aec2005b7a601fafc6a4332a69ea06bbf085fa9c Mon Sep 17 00:00:00 2001 From: Michael Scherer Date: Mon, 22 Nov 2010 13:15:21 +0000 Subject: - use the first pass if proposed ( or pam ask the password 2 times ) --- modules/pam/templates/system-auth | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'modules/pam') diff --git a/modules/pam/templates/system-auth b/modules/pam/templates/system-auth index b02aec3a..b98dd362 100644 --- a/modules/pam/templates/system-auth +++ b/modules/pam/templates/system-auth @@ -3,7 +3,7 @@ auth required pam_env.so # basically, the idea is to copy the exact detail of sufficient, # and add abort=ignore auth [abort=ignore success=done new_authtok_reqd=done default=ignore] pam_tcb.so shadow fork nullok prefix=$2a$ count=8 -auth sufficient pam_unix.so likeauth nullok +auth sufficient pam_unix.so likeauth nullok try_first_pass auth sufficient pam_ldap.so use_first_pass <% if access_class = 'admin' %> auth required pam_wheel.so group=mga-sysadmin -- cgit v1.2.1