informational output during PAM:

* Show failed and remaining password attempts.
* Document unlock procedure if Linux user account got locked.
* Point out, that there is no password feedback for `su`.
* Explain locked (root) account if locked.
* /usr/share/pam-configs/tally2-security-misc
* /usr/lib/security-misc/pam_tally2-info
This commit is contained in:
Patrick Schleizer 2019-08-15 13:37:28 +00:00
parent 454e135822
commit ff9bc1d7ea
No known key found for this signature in database
GPG key ID: CB8D50BB77BB3C48
3 changed files with 119 additions and 0 deletions

View file

@ -3,6 +3,7 @@ Default: yes
Priority: 260
Auth-Type: Primary
Auth:
optional pam_exec.so debug stdout seteuid /usr/lib/security-misc/pam_tally2-info
requisite pam_tally2.so even_deny_root deny=100 onerr=fail audit debug
Account-Type: Primary
Account: