security-misc/usr/share/pam-configs/console-lockdown-security-misc
Patrick Schleizer 729fa26eca
use pam_acccess only for /etc/pam.d/login
remove "Allow members of group 'ssh' to login."
remove "+:ssh:ALL EXCEPT LOCAL"
2019-12-12 09:00:08 -05:00

8 lines
315 B
Plaintext

Name: allow only members of group console to use login (by package security-misc)
Default: no
Priority: 280
Account-Type: Primary
Account:
[success=1 default=ignore] pam_exec.so seteuid quiet /usr/lib/security-misc/pam_only_if_login
required pam_access.so accessfile=/etc/security/access-security-misc.conf debug