mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-03-13 03:16:28 -04:00
fix: apply PAM wheal only to su
PAM service
This commit is contained in:
parent
40b23cfad4
commit
d4767b7520
17
usr/libexec/security-misc/pam_only_if_su
Executable file
17
usr/libexec/security-misc/pam_only_if_su
Executable file
@ -0,0 +1,17 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
## Copyright (C) 2019 - 2025 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
|
||||||
|
## See the file COPYING for copying conditions.
|
||||||
|
|
||||||
|
## Similar to:
|
||||||
|
## /usr/libexec/security-misc/pam_only_if_login
|
||||||
|
|
||||||
|
set -x
|
||||||
|
|
||||||
|
true "PAM_SERVICE: $PAM_SERVICE"
|
||||||
|
|
||||||
|
if [ "$PAM_SERVICE" = "su" ]; then
|
||||||
|
exit 1
|
||||||
|
else
|
||||||
|
exit 0
|
||||||
|
fi
|
@ -3,4 +3,5 @@ Default: yes
|
|||||||
Priority: 280
|
Priority: 280
|
||||||
Auth-Type: Primary
|
Auth-Type: Primary
|
||||||
Auth:
|
Auth:
|
||||||
|
[success=1 default=ignore] pam_exec.so seteuid quiet /usr/libexec/security-misc/pam_only_if_su
|
||||||
requisite pam_wheel.so group=sudo debug
|
requisite pam_wheel.so group=sudo debug
|
||||||
|
Loading…
x
Reference in New Issue
Block a user