Merge pull request #282 from ArrayBolt3/arraybolt3/umask

Enable umask hardening
This commit is contained in:
Patrick Schleizer 2024-12-19 00:08:56 -05:00 committed by GitHub
commit 4cf5757575
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 22 additions and 5 deletions

View file

@ -0,0 +1,8 @@
Name: Restrict umask to 027 (by package security-misc)
Default: yes
Priority: 100
Session-Type: Additional
Session-Interactive-Only: yes
Session:
[success=1 default=ignore] pam_succeed_if.so uid eq 0
optional pam_umask.so umask=027