diff options
| author | Ming Liu <ming.liu@windriver.com> | 2013-07-26 17:51:02 +0800 |
|---|---|---|
| committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2013-07-31 06:59:58 +0100 |
| commit | 82ac6aaa29e00944eaf70c586d70be1019b699d9 (patch) | |
| tree | 4ea3d7a75e6d58e22f4fa4664776d8ccd509c74a | |
| parent | f02e5a656ab4150e96890f61be3957244d424ff2 (diff) | |
| download | poky-82ac6aaa29e00944eaf70c586d70be1019b699d9.tar.gz | |
libpam: deny all services for the OTHER entries
To be secure, change behavior of the OTHER entries to warn and deny
access to everything by stating pam_deny.so on all services.
(From OE-Core rev: 4ca0af699b5b4b3cf95b3e76482651949fd922ac)
Signed-off-by: Ming Liu <ming.liu@windriver.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
| -rw-r--r-- | meta/recipes-extended/pam/libpam/pam.d/other | 15 |
1 files changed, 6 insertions, 9 deletions
diff --git a/meta/recipes-extended/pam/libpam/pam.d/other b/meta/recipes-extended/pam/libpam/pam.d/other index 6e40cd0c02..ec970ecbe0 100644 --- a/meta/recipes-extended/pam/libpam/pam.d/other +++ b/meta/recipes-extended/pam/libpam/pam.d/other | |||
| @@ -6,22 +6,19 @@ | |||
| 6 | #pam_open_session, the session module out of /etc/pam.d/other is | 6 | #pam_open_session, the session module out of /etc/pam.d/other is |
| 7 | #used. | 7 | #used. |
| 8 | 8 | ||
| 9 | #If you really want nothing to happen then use pam_permit.so or | ||
| 10 | #pam_deny.so as appropriate. | ||
| 11 | |||
| 12 | # We use pam_warn.so to generate syslog notes that the 'other' | 9 | # We use pam_warn.so to generate syslog notes that the 'other' |
| 13 | #fallback rules are being used (as a hint to suggest you should setup | 10 | #fallback rules are being used (as a hint to suggest you should setup |
| 14 | #specific PAM rules for the service and aid to debugging). We then | 11 | #specific PAM rules for the service and aid to debugging). Then to be |
| 15 | #fall back to the system default in /etc/pam.d/common-* | 12 | #secure, deny access to all services by default. |
| 16 | 13 | ||
| 17 | auth required pam_warn.so | 14 | auth required pam_warn.so |
| 18 | auth include common-auth | 15 | auth required pam_deny.so |
| 19 | 16 | ||
| 20 | account required pam_warn.so | 17 | account required pam_warn.so |
| 21 | account include common-account | 18 | account required pam_deny.so |
| 22 | 19 | ||
| 23 | password required pam_warn.so | 20 | password required pam_warn.so |
| 24 | password include common-password | 21 | password required pam_deny.so |
| 25 | 22 | ||
| 26 | session required pam_warn.so | 23 | session required pam_warn.so |
| 27 | session include common-session | 24 | session required pam_deny.so |
