Blob Blame History Raw
From 3a2300353e5f6e81f3e0cdf9a86747516d20d41d Mon Sep 17 00:00:00 2001
From: Ray Strode <rstrode@redhat.com>
Date: Wed, 12 Mar 2014 15:03:12 -0400
Subject: [PATCH] pam: run pam_gnome_keyring in password stack at login time

This way it has the hook it needs to deal with password
changes in the middle of first login.
---
 data/pam-redhat/gdm-password.pam | 1 +
 1 file changed, 1 insertion(+)

diff --git a/data/pam-redhat/gdm-password.pam b/data/pam-redhat/gdm-password.pam
index 6e20568..99ad2c6 100644
--- a/data/pam-redhat/gdm-password.pam
+++ b/data/pam-redhat/gdm-password.pam
@@ -1,20 +1,21 @@
 auth     [success=done ignore=ignore default=bad] pam_selinux_permit.so
 auth        substack      password-auth
 auth        optional      pam_gnome_keyring.so
 auth        include       postlogin
 
 account     required      pam_nologin.so
 account     include       password-auth
 
-password    include       password-auth
+password    substack      password-auth
+password    optional      pam_gnome_keyring.so use_authtok
 
 session     required      pam_selinux.so close
 session     required      pam_loginuid.so
 session     optional      pam_console.so
 -session    optional    pam_ck_connector.so
 session     required      pam_selinux.so open
 session     optional      pam_keyinit.so force revoke
 session     required      pam_namespace.so
 session     include       password-auth
 session     optional      pam_gnome_keyring.so auto_start
 session     include       postlogin
-- 
1.8.4.2