use pam_tally2 only for login

to skip counting failed login attempts over ssh and mail login
This commit is contained in:
Patrick Schleizer 2021-01-24 05:04:48 -05:00
parent 126c31c37d
commit 6757104aa4
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -4,6 +4,7 @@ Priority: 290
Auth-Type: Primary Auth-Type: Primary
Auth: Auth:
optional pam_exec.so debug stdout seteuid /usr/lib/security-misc/pam_tally2-info optional pam_exec.so debug stdout seteuid /usr/lib/security-misc/pam_tally2-info
[success=1 default=ignore] pam_exec.so seteuid quiet /usr/lib/security-misc/pam_only_if_login
requisite pam_tally2.so even_deny_root deny=50 onerr=fail audit debug requisite pam_tally2.so even_deny_root deny=50 onerr=fail audit debug
Account-Type: Primary Account-Type: Primary
Account: Account: