|
|
f42647 |
From 6effb1671a917adb3ed8f77f5e13324e8b455c32 Mon Sep 17 00:00:00 2001
|
|
|
f42647 |
From: Ray Strode <rstrode@redhat.com>
|
|
|
f42647 |
Date: Tue, 30 Jan 2018 10:32:08 -0500
|
|
|
f42647 |
Subject: [PATCH] data: drop pam_gdm, reintroduce pam_env/postlogin
|
|
|
f42647 |
|
|
|
f42647 |
The current upstream pam configuration upstream doesn't really
|
|
|
f42647 |
make sense in RHEL.
|
|
|
f42647 |
|
|
|
f42647 |
systemd doesn't handle /etc/environment on its own in RHEL and it
|
|
|
f42647 |
doesn't populate the kernel keyring with disk encrypt passwords,
|
|
|
f42647 |
so pam_gdm is not useful.
|
|
|
f42647 |
|
|
|
f42647 |
This commit restores the pam configuration to something closer to
|
|
|
f42647 |
what was shipped in 7.3
|
|
|
f42647 |
---
|
|
|
f42647 |
data/pam-redhat/gdm-autologin.pam | 7 +++----
|
|
|
f42647 |
1 file changed, 3 insertions(+), 4 deletions(-)
|
|
|
f42647 |
|
|
|
f42647 |
diff --git a/data/pam-redhat/gdm-autologin.pam b/data/pam-redhat/gdm-autologin.pam
|
|
|
f42647 |
index c31ff27a..aa99e1b0 100644
|
|
|
f42647 |
--- a/data/pam-redhat/gdm-autologin.pam
|
|
|
f42647 |
+++ b/data/pam-redhat/gdm-autologin.pam
|
|
|
f42647 |
@@ -1,16 +1,15 @@
|
|
|
f42647 |
#%PAM-1.0
|
|
|
f42647 |
-auth [success=ok default=1] pam_gdm.so
|
|
|
f42647 |
--auth optional pam_gnome_keyring.so
|
|
|
f42647 |
-auth sufficient pam_permit.so
|
|
|
f42647 |
+auth required pam_env.so
|
|
|
f42647 |
+auth required pam_permit.so
|
|
|
f42647 |
+auth include postlogin
|
|
|
f42647 |
account required pam_nologin.so
|
|
|
f42647 |
account include system-auth
|
|
|
f42647 |
password include system-auth
|
|
|
f42647 |
session required pam_selinux.so close
|
|
|
f42647 |
session required pam_loginuid.so
|
|
|
f42647 |
session optional pam_console.so
|
|
|
f42647 |
session required pam_selinux.so open
|
|
|
f42647 |
session optional pam_keyinit.so force revoke
|
|
|
f42647 |
session required pam_namespace.so
|
|
|
f42647 |
session include system-auth
|
|
|
f42647 |
-session optional pam_gnome_keyring.so auto_start
|
|
|
f42647 |
session include postlogin
|
|
|
f42647 |
--
|
|
|
f42647 |
2.14.3
|
|
|
f42647 |
|