From 251f8546c938e18f6cfa7e073aad32b7f76a11cc Mon Sep 17 00:00:00 2001 From: Eelco Dolstra Date: Mon, 17 Dec 2012 21:08:29 +0100 Subject: [PATCH] pam_ssh_agent_auth: Use /etc/ssh/authorized_keys.d --- modules/security/pam.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/security/pam.nix b/modules/security/pam.nix index 940c596e367..32721205b99 100644 --- a/modules/security/pam.nix +++ b/modules/security/pam.nix @@ -82,7 +82,7 @@ let ${optionalString rootOK "auth sufficient pam_rootok.so"} ${optionalString (config.security.pam.enableSSHAgentAuth && sshAgentAuth) - "auth sufficient ${pkgs.pam_ssh_agent_auth}/libexec/pam_ssh_agent_auth.so file=~/.ssh/authorized_keys"} + "auth sufficient ${pkgs.pam_ssh_agent_auth}/libexec/pam_ssh_agent_auth.so file=~/.ssh/authorized_keys:~/.ssh/authorized_keys2:/etc/ssh/authorized_keys.d/%u"} ${optionalString usbAuth "auth sufficient ${pkgs.pam_usb}/lib/security/pam_usb.so"} auth sufficient pam_unix.so ${optionalString allowNullPassword "nullok"} likeauth