Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | We don't use this any more. | des | 2002-06-19 | 2 | -10/+1 |
| | | | | Sponsored by: DARPA, NAI Labs | ||||
* | Enable OPIE for sshd and telnetd. I thought I'd done this a long time | des | 2002-06-19 | 2 | -0/+4 |
| | | | | | | ago... Sponsored by: DARPA, NAI Labs | ||||
* | Use pam_lastlog(8)'s new no_fail option. | des | 2002-05-08 | 3 | -3/+3 |
| | | | | Sponsored by: DARPA, NAI Labs | ||||
* | Add a PAM policy for rexecd(8). | des | 2002-05-02 | 2 | -1/+17 |
| | | | | Sponsored by: DARPA, NAI Labs | ||||
* | xdm plays horrid tricks with PAM, and dumps core if it's allowed to call | des | 2002-05-02 | 2 | -0/+2 |
| | | | | | | | | pam_lastlog, so add a dummy session chain to avoid using the one from pam.d/other. I assume gdm does something similar, so give it a dummy session chain as well. Sponsored by: DARPA, NAI Labs. | ||||
* | Add no_warn to pam_lastlog. This should prevent xdm from dumping core | des | 2002-04-29 | 1 | -1/+1 |
| | | | | when linked with Linux-PAM. | ||||
* | Don't list pam_unix in the session chain, since it does not provide any | des | 2002-04-18 | 9 | -11/+1 |
| | | | | | | session management services. Sponsored by: DARPA, NAI Labs | ||||
* | Fixed bugs in previous revision: | ru | 2002-04-18 | 1 | -20/+6 |
| | | | | | | | | | | | | | Added NOOBJ if anyone even attempts to "make obj" here. Revert to installing files with mode 644 except README. Make this overall look like a BSD-style Makefile rather than roll-your-own (this is not a bug). For the record. Previous revision also fixed the breakage introduced by the sys.mk,v 1.60 commit: bsd.own.mk is no longer automatically included from sys.mk. Reported by: jhay | ||||
* | Use ${FILES} and <bsd.prog.mk> rather than roll-your-own. | des | 2002-04-18 | 1 | -22/+21 |
| | |||||
* | Add PAM policy for the "passwd" service, including a sample config line | des | 2002-04-15 | 2 | -0/+12 |
| | | | | | | for pam_passwdqc. Sponsored by: DARPA, NAI Labs | ||||
* | Add pam_lastlog(8) here since I removed lastlog support from sshd. | des | 2002-04-15 | 1 | -0/+1 |
| | | | | Sponsored by: DARPA, NAI Labs | ||||
* | Use pam_rhosts(8). | des | 2002-04-12 | 1 | -1/+1 |
| | |||||
* | If used, pam_ssh should be marked "sufficient", not "required". | des | 2002-04-08 | 1 | -1/+1 |
| | | | | Sponsored by: DARPA, NAI Labs | ||||
* | Switch over to using pam_login_access(8) module in sshd(8). | ru | 2002-03-26 | 1 | -0/+1 |
| | | | | | | (Fixes static compilation. Reduces diffs to OpenSSH.) Reviewed by: bde | ||||
* | Add missing "nullok" option to pam_unix. | des | 2002-02-08 | 1 | -1/+1 |
| | |||||
* | Add pam_self(8) so users can login(1) as themselves without authentication, | des | 2002-01-30 | 1 | -0/+4 |
| | | | | | | | | pam_login_access(8) and pam_securetty(8) to enforce various checks previously done by login(1) but now handled by PAM, and pam_lastlog(8) to record login sessions in utmp / wtmp / lastlog. Sponsored by: DARPA, NAI Labs | ||||
* | Use pam_self(8) to allow users to su(1) to themselves without authentication. | des | 2002-01-30 | 1 | -0/+1 |
| | | | | Sponsored by: DARPA, NAI Labs | ||||
* | Enable OPIE by default, using the no_fake_prompts option to hide it from | des | 2002-01-21 | 9 | -23/+40 |
| | | | | | | | | | | | | | | users who don't wish to use it. If the admin is worried about leaking information about which users exist and which have OPIE enabled, the no_fake_prompts option can simply be removed. Also insert the appropriate pam_opieaccess lines after pam_opie to break the chain in case the user is logging in from an untrusted host, or has a .opiealways file. The entire opieaccess / opiealways concept is slightly unpammish, but admins familiar with OPIE will expect it to work. Reviewed by: ache, markm Sponsored by: DARPA, NAI Labs | ||||
* | Really back out ache's commits. These files are now precisely as they were | des | 2002-01-19 | 3 | -4/+7 |
| | | | | twentyfour hours ago, except for RCS ids. | ||||
* | Back out recent changes | ache | 2002-01-19 | 3 | -3/+3 |
| | |||||
* | Turn on pam_opie by default. It should not affect non-OPIE users. | ache | 2002-01-19 | 1 | -1/+1 |
| | |||||
* | Turn on pam_opie by default. It not affect non-OPIE users | ache | 2002-01-19 | 1 | -2/+1 |
| | |||||
* | Previous commit was incomplete, use | ache | 2002-01-19 | 1 | -1/+1 |
| | | | | | "[default=ignore success=done cred_err=die]" options instead of "required" | ||||
* | Remove explaining comment and pam_unix commented out, now pam_unix can be | ache | 2002-01-19 | 1 | -4/+1 |
| | | | | chained with pam_opie | ||||
* | Change comment since fallback provided now not by ftpd but by pam_opie | ache | 2002-01-19 | 1 | -1/+2 |
| | |||||
* | Unmunge the version preservation code and obfuscate it so CVS won't munge | des | 2002-01-12 | 1 | -2/+2 |
| | | | | it all over again. | ||||
* | Back out previous commit, which erroneously removed essential comments. I | des | 2002-01-12 | 1 | -1/+3 |
| | | | | | | definitely need coffee. Apologies to: ache | ||||
* | Update copyright | des | 2002-01-12 | 1 | -1/+1 |
| | |||||
* | Sync with pam.conf revision 1.25. | des | 2002-01-12 | 1 | -3/+1 |
| | |||||
* | Preserve FreeBSD version strings in target files. | des | 2002-01-12 | 1 | -1/+11 |
| | |||||
* | Improve pam_unix/opie related ftpd comment even more | ache | 2002-01-02 | 1 | -1/+3 |
| | |||||
* | Clarify comment about pam_unix fallback for ftpd | ache | 2002-01-01 | 1 | -1/+1 |
| | |||||
* | Turn on pam_opie.so for ftpd by default | ache | 2002-01-01 | 1 | -3/+3 |
| | | | | It not affect non-OPIE users | ||||
* | Install pam.d files with mode 0644, not 0755. | des | 2001-12-06 | 1 | -1/+1 |
| | |||||
* | Makefile for pam.d configuration files. | des | 2001-12-06 | 1 | -0/+24 |
| | | | | Sponsored by: DARPA, NAI Labs | ||||
* | Awright, egg on my face. I should have taken more time with this. The | des | 2001-12-05 | 17 | -135/+139 |
| | | | | | | | conversion script generated the wrong format, so the configuration files didn't actually work. Good thing I hadn't thrown the switch yet... Sponsored by: DARPA, NAI Labs (but the f***ups are all mine) | ||||
* | pam.d-style configuration, auto-generated from pam.conf. | des | 2001-12-05 | 15 | -0/+286 |
| | | | | Sponsored by: DARPA, NAI Labs | ||||
* | Short README for /etc/pam.d, mostly extracted from the comments in pam.conf. | des | 2001-12-05 | 1 | -0/+60 |
| | |||||
* | Perl script that splits pam.conf into separate files suitable for pam.d. | des | 2001-12-05 | 1 | -0/+73 |
Sponsored by: DARPA, NAI Labs |