effectively (not directly) add "required pam_tally2.so debug" to /etc/pam.d/common-account

This is required because otherwise something like "sudo bash" would count as a
failed login for pam_tally2 even though it was successful.

https://bugzilla.redhat.com/show_bug.cgi?id=707660

https://forums.whonix.org/t/restrict-root-access/7658
This commit is contained in:
Patrick Schleizer 2019-08-10 06:06:39 -04:00
parent 0f896a9d8d
commit d17e25272b
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -4,3 +4,6 @@ Priority: 260
Auth-Type: Primary Auth-Type: Primary
Auth: Auth:
required pam_tally2.so deny=5 onerr=fail audit debug required pam_tally2.so deny=5 onerr=fail audit debug
Account-Type: Primary
Account:
required pam_tally2.so debug