change priories so "pam_umask.so usergroups umask=006" runs before pam_exec.so /usr/lib/security-misc/permission-lockdown

This commit is contained in:
Patrick Schleizer 2019-08-14 09:31:58 +00:00
parent f8c828b69a
commit a085d46c56
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48
2 changed files with 2 additions and 2 deletions

View File

@ -1,6 +1,6 @@
Name: Create home directory on login (by package security-misc) Name: Create home directory on login (by package security-misc)
Default: yes Default: yes
Priority: 0 Priority: 100
Session-Type: Additional Session-Type: Additional
Session-Interactive-Only: yes Session-Interactive-Only: yes
Session: Session:

View File

@ -1,6 +1,6 @@
Name: prevent others from reading one's home folder (by package security-misc) Name: prevent others from reading one's home folder (by package security-misc)
Default: yes Default: yes
Priority: 500 Priority: 50
Session-Type: Additional Session-Type: Additional
Session: Session:
optional pam_exec.so debug seteuid log=/var/log/permission-lockdown-security-misc /usr/lib/security-misc/permission-lockdown optional pam_exec.so debug seteuid log=/var/log/permission-lockdown-security-misc /usr/lib/security-misc/permission-lockdown