summaryrefslogtreecommitdiffstats
path: root/meta-openstack/recipes-extended/libpam/files/common-auth
diff options
context:
space:
mode:
authorAmy Fong <amy.fong@windriver.com>2014-07-22 09:55:30 -0400
committerBruce Ashfield <bruce.ashfield@windriver.com>2014-07-30 00:50:21 -0400
commit91f39a6e38e6e6fd1e9b6582fb85cd273f3249bb (patch)
tree9d936adcd87c0b814d13f135340d81c48fe82aed /meta-openstack/recipes-extended/libpam/files/common-auth
parent9ec30c79de0764d8c45518644e539e18ddde8b84 (diff)
downloadmeta-cloud-services-91f39a6e38e6e6fd1e9b6582fb85cd273f3249bb.tar.gz
ldap/pam: enable pam/ldap authentication
- modify pam configuration files to use ldap - modify sshd to enable pam - modify nsswitch.conf to use ldap Signed-off-by: Amy Fong <amy.fong@windriver.com>
Diffstat (limited to 'meta-openstack/recipes-extended/libpam/files/common-auth')
-rw-r--r--meta-openstack/recipes-extended/libpam/files/common-auth21
1 files changed, 21 insertions, 0 deletions
diff --git a/meta-openstack/recipes-extended/libpam/files/common-auth b/meta-openstack/recipes-extended/libpam/files/common-auth
new file mode 100644
index 0000000..e5b429d
--- /dev/null
+++ b/meta-openstack/recipes-extended/libpam/files/common-auth
@@ -0,0 +1,21 @@
1#
2# /etc/pam.d/common-auth - authentication settings common to all services
3#
4# This file is included from other service-specific PAM config files,
5# and should contain a list of the authentication modules that define
6# the central authentication scheme for use on the system
7# (e.g., /etc/shadow, LDAP, Kerberos, etc.). The default is to use the
8# traditional Unix authentication mechanisms.
9
10# here are the per-package modules (the "Primary" block)
11auth [success=2 default=ignore] pam_unix.so nullok_secure
12auth [success=1 default=ignore] pam_ldap.so minimum_uid=1000 use_first_pass
13# here's the fallback if no module succeeds
14auth requisite pam_deny.so
15# prime the stack with a positive return value if there isn't one already;
16# this avoids us returning an error just because nothing sets a success code
17# since the modules above will each just jump around
18auth required pam_permit.so
19# and here are more per-package modules (the "Additional" block)
20auth optional pam_cap.so
21# end of pam-auth-update config