Merge pull request #25502 from keszybz/pam-namespace-add

Add pam_namespace to user@.service pam stack
This commit is contained in:
Luca Boccassi
2022-12-07 13:01:50 +01:00
committed by GitHub

View File

@@ -4,18 +4,19 @@
# Used by systemd --user instances.
{% if ENABLE_HOMED %}
-account sufficient pam_systemd_home.so
-account sufficient pam_systemd_home.so
{% endif %}
account sufficient pam_unix.so no_pass_expiry
account required pam_permit.so
account sufficient pam_unix.so no_pass_expiry
account required pam_permit.so
{% if HAVE_SELINUX %}
session required pam_selinux.so close
session required pam_selinux.so nottys open
session required pam_selinux.so close
session required pam_selinux.so nottys open
{% endif %}
session required pam_loginuid.so
session optional pam_keyinit.so force revoke
session required pam_loginuid.so
session optional pam_keyinit.so force revoke
session required pam_namespace.so
{% if ENABLE_HOMED %}
-session optional pam_systemd_home.so
-session optional pam_systemd_home.so
{% endif %}
session optional pam_systemd.so
session optional pam_systemd.so