]> git.ipfire.org Git - thirdparty/systemd.git/commit
man: document new pam_systemd features in man page
authorLennart Poettering <lennart@poettering.net>
Tue, 19 Nov 2019 10:30:41 +0000 (11:30 +0100)
committerLennart Poettering <lennart@poettering.net>
Wed, 15 Jan 2020 14:30:06 +0000 (15:30 +0100)
commitfc89f88e56cd13a0caec4fa2adfecf9ae9c04c0c
tree04688c8bb225a93b09b894983e8c41d090481640
parentf9c1f4e19308c00a4f5b76fdf18549a75fa418ff
man: document new pam_systemd features in man page

This also updates the suggested PAM snippet in a number of way:

1. Be closer to the logic nowadays implemented in Fedora where the
   auth/account/password stacks are all finished off with
   pam_{deny|permit}.so

2. Make pam_unix.so just "sufficient" instead of "required" (paving
   ground for pam_systemd_home.so being hooked in as additional
   sufficient module.

3. Only do pam_nologin in the "account" stack, since it's about account
   validity really.

4. Use modern parameters to pam_unix when changing passwords, i.e.
   sha512 and shadow, and use already set up passwords (preparing ground
   for pam_systemd_home again)
man/pam_systemd.xml