blob: 35be0ee4ea91b04e8b28938c011d1c69f70b4f15 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
|
#
# /etc/pam.d/common-password - password-related modules common to all services
#
# This file is included from other service-specific PAM config files,
# and should contain a list of modules that define the services to be
# used to change user passwords. The default is pam_unix.
# Explanation of pam_unix options:
# The "yescrypt" option enables
#hashed passwords using the yescrypt algorithm, introduced in Debian
#11. Without this option, the default is Unix crypt. Prior releases
#used the option "sha512"; if a shadow password hash will be shared
#between Debian 11 and older releases replace "yescrypt" with "sha512"
#for compatibility . The "obscure" option replaces the old
#`OBSCURE_CHECKS_ENAB' option in login.defs. See the pam_unix manpage
#for other options.
# As of pam 1.0.1-6, this file is managed by pam-auth-update by default.
# To take advantage of this, it is recommended that you configure any
# local modules either before or after the default block, and use
# pam-auth-update to manage selection of other modules. See
# pam-auth-update(8) for details.
# here are the per-package modules (the "Primary" block)
{% if password_policy_enabled %}
password requisite pam_pwquality.so retry=3 \
difok={{ password_policy_difok }} \
minlen={{ password_policy_minlen }} \
dcredit={{ password_policy_dcredit }} \
ucredit={{ password_policy_ucredit }} \
ocredit={{ password_policy_ocredit }} \
lcredit={{ password_policy_lcredit }} \
minclass={{ password_policy_minclass }} \
maxrepeat={{ password_policy_maxrepeat }} \
maxclassrepeat={{ password_policy_maxclassrepeat }} \
gecoscheck={{ password_policy_gecoscheck }}
password [success=1 default=ignore] pam_unix.so obscure use_authtok try_first_pass yescrypt
{% else %}
password [success=1 default=ignore] pam_unix.so obsecure sha512 minlen={{ password_policy_minlen }}
{% endif %}
# here's the fallback if no module succeeds
password requisite pam_deny.so
# prime the stack with a positive return value if there isn't one already;
# this avoids us returning an error just because nothing sets a success code
# since the modules above will each just jump around
password required pam_permit.so
{% if ansible_facts['distribution'] == "Ubuntu" %}
# and here are more per-package modules (the "Additional" block)
password optional pam_gnome_keyring.so
{% endif %}
# end of pam-auth-update config
|