From 3c5eca74e04fad95927a07e13eec0744f407584d Mon Sep 17 00:00:00 2001 From: Eric Hameleers Date: Tue, 26 May 2020 13:25:55 +0200 Subject: SDDM: updated PAM configs allow root login --- kde/post-install/sddm-qt5/pam.d/sddm | 31 ++++++++++++++++++++----------- 1 file changed, 20 insertions(+), 11 deletions(-) (limited to 'kde/post-install/sddm-qt5/pam.d/sddm') diff --git a/kde/post-install/sddm-qt5/pam.d/sddm b/kde/post-install/sddm-qt5/pam.d/sddm index bb435ce..f0b2345 100644 --- a/kde/post-install/sddm-qt5/pam.d/sddm +++ b/kde/post-install/sddm-qt5/pam.d/sddm @@ -1,16 +1,25 @@ #%PAM-1.0 -auth substack login --auth optional pam_gnome_keyring.so --auth optional pam_kwallet5.so +auth substack system-auth -account include login +# Uncomment this line to restrict login to users with a UID greater +# than 999 (in other words, don't allow login for root): +#auth required pam_succeed_if.so uid >= 1000 quiet -password substack login --password optional pam_gnome_keyring.so use_authtok --password optional pam_kwallet5.so use_authtok +-auth optional pam_gnome_keyring.so +-auth optional pam_kwallet5.so +auth include postlogin -session optional pam_keyinit.so force revoke -session substack login --session optional pam_gnome_keyring.so auto_start --session optional pam_kwallet5.so auto_start +account include system-auth + +password substack system-auth +-password optional pam_gnome_keyring.so use_authtok +-password optional pam_kwallet5.so use_authtok + +session optional pam_keyinit.so force revoke +session substack system-auth +session required pam_loginuid.so +session optional pam_ck_connector.so nox11 +-session optional pam_gnome_keyring.so auto_start +-session optional pam_kwallet5.so auto_start +session include postlogin -- cgit v1.2.3