summaryrefslogtreecommitdiffstats
path: root/roles/password_policy/templates
diff options
context:
space:
mode:
authorAhmed Abdelhalim <[email protected]>2025-08-11 00:32:07 +0200
committerAhmed Abdelhalim <[email protected]>2025-08-11 00:32:07 +0200
commit652734b570bc728f02df99a7c570b119ddc5c4be (patch)
tree356460fb60f2d8d13e6e1a8b1a7aaba9d04aa501 /roles/password_policy/templates
parent2d45a9b60a008581672af7a901258f488d3cde16 (diff)
Refactor: move password policy to its own role
Diffstat (limited to 'roles/password_policy/templates')
-rw-r--r--roles/password_policy/templates/archlinux-pam-pw.j245
-rw-r--r--roles/password_policy/templates/debian-pam-pw.j249
2 files changed, 94 insertions, 0 deletions
diff --git a/roles/password_policy/templates/archlinux-pam-pw.j2 b/roles/password_policy/templates/archlinux-pam-pw.j2
new file mode 100644
index 00000000..b5e3914e
--- /dev/null
+++ b/roles/password_policy/templates/archlinux-pam-pw.j2
@@ -0,0 +1,45 @@
+#%PAM-1.0
+
+auth required pam_faillock.so preauth
+# Optionally use requisite above if you do not want to prompt for the password
+# on locked accounts.
+-auth [success=2 default=ignore] pam_systemd_home.so
+auth [success=1 default=bad] pam_unix.so try_first_pass nullok
+auth [default=die] pam_faillock.so authfail
+auth optional pam_permit.so
+auth required pam_env.so
+auth required pam_faillock.so authsucc
+# If you drop the above call to pam_faillock.so the lock will be done also
+# on non-consecutive authentication failures.
+
+-account [success=1 default=ignore] pam_systemd_home.so
+account required pam_unix.so
+account optional pam_permit.so
+account required pam_time.so
+
+{% if password_policy_enabled %}
+-password [success=2 default=ignore] pam_systemd_home.so
+password requisite pam_pwquality.so retry=3 \
+ difok={{ password_policy_difok }} \
+ minlen={{ password_policy_minlen }} \
+ dcredit={{ password_policy_dcredit }} \
+ ucredit={{ password_policy_ucredit }} \
+ ocredit={{ password_policy_ocredit }} \
+ lcredit={{ password_policy_lcredit }} \
+ minclass={{ password_policy_minclass }} \
+ maxrepeat={{ password_policy_maxrepeat }} \
+ maxclassrepeat={{ password_policy_maxclassrepeat }} \
+ gecoscheck={{ password_policy_gecoscheck }}
+{% else %}
+-password [success=1 default=ignore] pam_systemd_home.so
+{% endif %}
+password required pam_unix.so try_first_pass \
+ nullok \
+ shadow \
+ minlen={{ password_policy_minlen }}
+password optional pam_permit.so
+
+-session optional pam_systemd_home.so
+session required pam_limits.so
+session required pam_unix.so
+session optional pam_permit.so
diff --git a/roles/password_policy/templates/debian-pam-pw.j2 b/roles/password_policy/templates/debian-pam-pw.j2
new file mode 100644
index 00000000..dceedf97
--- /dev/null
+++ b/roles/password_policy/templates/debian-pam-pw.j2
@@ -0,0 +1,49 @@
+#
+# /etc/pam.d/common-password - password-related modules common to all services
+#
+# This file is included from other service-specific PAM config files,
+# and should contain a list of modules that define the services to be
+# used to change user passwords. The default is pam_unix.
+
+# Explanation of pam_unix options:
+# The "yescrypt" option enables
+#hashed passwords using the yescrypt algorithm, introduced in Debian
+#11. Without this option, the default is Unix crypt. Prior releases
+#used the option "sha512"; if a shadow password hash will be shared
+#between Debian 11 and older releases replace "yescrypt" with "sha512"
+#for compatibility . The "obscure" option replaces the old
+#`OBSCURE_CHECKS_ENAB' option in login.defs. See the pam_unix manpage
+#for other options.
+
+# As of pam 1.0.1-6, this file is managed by pam-auth-update by default.
+# To take advantage of this, it is recommended that you configure any
+# local modules either before or after the default block, and use
+# pam-auth-update to manage selection of other modules. See
+# pam-auth-update(8) for details.
+
+# here are the per-package modules (the "Primary" block)
+{% if password_policy_enabled %}
+password requisite pam_pwquality.so retry=3 \
+ difok={{ password_policy_difok }} \
+ minlen={{ password_policy_minlen }} \
+ dcredit={{ password_policy_dcredit }} \
+ ucredit={{ password_policy_ucredit }} \
+ ocredit={{ password_policy_ocredit }} \
+ lcredit={{ password_policy_lcredit }} \
+ minclass={{ password_policy_minclass }} \
+ maxrepeat={{ password_policy_maxrepeat }} \
+ maxclassrepeat={{ password_policy_maxclassrepeat }} \
+ gecoscheck={{ password_policy_gecoscheck }}
+password [success=1 default=ignore] pam_unix.so obscure use_authtok try_first_pass yescrypt
+{% else %}
+password [success=1 default=ignore] pam_unix.so obsecure sha512 minlen={{ password_policy_minlen }}
+{% endif %}
+# here's the fallback if no module succeeds
+password requisite pam_deny.so
+# prime the stack with a positive return value if there isn't one already;
+# this avoids us returning an error just because nothing sets a success code
+# since the modules above will each just jump around
+password required pam_permit.so
+# and here are more per-package modules (the "Additional" block)
+password optional pam_gnome_keyring.so
+# end of pam-auth-update config