diff options
| author | Ahmed Abdelhalim <[email protected]> | 2025-08-11 00:32:07 +0200 |
|---|---|---|
| committer | Ahmed Abdelhalim <[email protected]> | 2025-08-11 00:32:07 +0200 |
| commit | 652734b570bc728f02df99a7c570b119ddc5c4be (patch) | |
| tree | 356460fb60f2d8d13e6e1a8b1a7aaba9d04aa501 /roles/password_policy/templates | |
| parent | 2d45a9b60a008581672af7a901258f488d3cde16 (diff) | |
Refactor: move password policy to its own role
Diffstat (limited to 'roles/password_policy/templates')
| -rw-r--r-- | roles/password_policy/templates/archlinux-pam-pw.j2 | 45 | ||||
| -rw-r--r-- | roles/password_policy/templates/debian-pam-pw.j2 | 49 |
2 files changed, 94 insertions, 0 deletions
diff --git a/roles/password_policy/templates/archlinux-pam-pw.j2 b/roles/password_policy/templates/archlinux-pam-pw.j2 new file mode 100644 index 00000000..b5e3914e --- /dev/null +++ b/roles/password_policy/templates/archlinux-pam-pw.j2 @@ -0,0 +1,45 @@ +#%PAM-1.0 + +auth required pam_faillock.so preauth +# Optionally use requisite above if you do not want to prompt for the password +# on locked accounts. +-auth [success=2 default=ignore] pam_systemd_home.so +auth [success=1 default=bad] pam_unix.so try_first_pass nullok +auth [default=die] pam_faillock.so authfail +auth optional pam_permit.so +auth required pam_env.so +auth required pam_faillock.so authsucc +# If you drop the above call to pam_faillock.so the lock will be done also +# on non-consecutive authentication failures. + +-account [success=1 default=ignore] pam_systemd_home.so +account required pam_unix.so +account optional pam_permit.so +account required pam_time.so + +{% if password_policy_enabled %} +-password [success=2 default=ignore] pam_systemd_home.so +password requisite pam_pwquality.so retry=3 \ + difok={{ password_policy_difok }} \ + minlen={{ password_policy_minlen }} \ + dcredit={{ password_policy_dcredit }} \ + ucredit={{ password_policy_ucredit }} \ + ocredit={{ password_policy_ocredit }} \ + lcredit={{ password_policy_lcredit }} \ + minclass={{ password_policy_minclass }} \ + maxrepeat={{ password_policy_maxrepeat }} \ + maxclassrepeat={{ password_policy_maxclassrepeat }} \ + gecoscheck={{ password_policy_gecoscheck }} +{% else %} +-password [success=1 default=ignore] pam_systemd_home.so +{% endif %} +password required pam_unix.so try_first_pass \ + nullok \ + shadow \ + minlen={{ password_policy_minlen }} +password optional pam_permit.so + +-session optional pam_systemd_home.so +session required pam_limits.so +session required pam_unix.so +session optional pam_permit.so diff --git a/roles/password_policy/templates/debian-pam-pw.j2 b/roles/password_policy/templates/debian-pam-pw.j2 new file mode 100644 index 00000000..dceedf97 --- /dev/null +++ b/roles/password_policy/templates/debian-pam-pw.j2 @@ -0,0 +1,49 @@ +# +# /etc/pam.d/common-password - password-related modules common to all services +# +# This file is included from other service-specific PAM config files, +# and should contain a list of modules that define the services to be +# used to change user passwords. The default is pam_unix. + +# Explanation of pam_unix options: +# The "yescrypt" option enables +#hashed passwords using the yescrypt algorithm, introduced in Debian +#11. Without this option, the default is Unix crypt. Prior releases +#used the option "sha512"; if a shadow password hash will be shared +#between Debian 11 and older releases replace "yescrypt" with "sha512" +#for compatibility . The "obscure" option replaces the old +#`OBSCURE_CHECKS_ENAB' option in login.defs. See the pam_unix manpage +#for other options. + +# As of pam 1.0.1-6, this file is managed by pam-auth-update by default. +# To take advantage of this, it is recommended that you configure any +# local modules either before or after the default block, and use +# pam-auth-update to manage selection of other modules. See +# pam-auth-update(8) for details. + +# here are the per-package modules (the "Primary" block) +{% if password_policy_enabled %} +password requisite pam_pwquality.so retry=3 \ + difok={{ password_policy_difok }} \ + minlen={{ password_policy_minlen }} \ + dcredit={{ password_policy_dcredit }} \ + ucredit={{ password_policy_ucredit }} \ + ocredit={{ password_policy_ocredit }} \ + lcredit={{ password_policy_lcredit }} \ + minclass={{ password_policy_minclass }} \ + maxrepeat={{ password_policy_maxrepeat }} \ + maxclassrepeat={{ password_policy_maxclassrepeat }} \ + gecoscheck={{ password_policy_gecoscheck }} +password [success=1 default=ignore] pam_unix.so obscure use_authtok try_first_pass yescrypt +{% else %} +password [success=1 default=ignore] pam_unix.so obsecure sha512 minlen={{ password_policy_minlen }} +{% endif %} +# here's the fallback if no module succeeds +password requisite pam_deny.so +# prime the stack with a positive return value if there isn't one already; +# this avoids us returning an error just because nothing sets a success code +# since the modules above will each just jump around +password required pam_permit.so +# and here are more per-package modules (the "Additional" block) +password optional pam_gnome_keyring.so +# end of pam-auth-update config |
