Apply pam_loginuid before pam_systemd
As recommended by the pam_systemd manpage.
This commit is contained in:
parent
f0a9703f77
commit
5378da25a0
@ -187,6 +187,8 @@ let
|
|||||||
|
|
||||||
# Session management.
|
# Session management.
|
||||||
session required pam_unix.so
|
session required pam_unix.so
|
||||||
|
${optionalString cfg.setLoginUid
|
||||||
|
"session required pam_loginuid.so"}
|
||||||
${optionalString cfg.updateWtmp
|
${optionalString cfg.updateWtmp
|
||||||
"session required ${pkgs.pam}/lib/security/pam_lastlog.so silent"}
|
"session required ${pkgs.pam}/lib/security/pam_lastlog.so silent"}
|
||||||
${optionalString config.users.ldap.enable
|
${optionalString config.users.ldap.enable
|
||||||
@ -197,8 +199,6 @@ let
|
|||||||
"session optional ${pkgs.otpw}/lib/security/pam_otpw.so"}
|
"session optional ${pkgs.otpw}/lib/security/pam_otpw.so"}
|
||||||
${optionalString cfg.startSession
|
${optionalString cfg.startSession
|
||||||
"session optional ${pkgs.systemd}/lib/security/pam_systemd.so"}
|
"session optional ${pkgs.systemd}/lib/security/pam_systemd.so"}
|
||||||
${optionalString cfg.setLoginUid
|
|
||||||
"session required pam_loginuid.so"}
|
|
||||||
${optionalString cfg.forwardXAuth
|
${optionalString cfg.forwardXAuth
|
||||||
"session optional pam_xauth.so xauthpath=${pkgs.xorg.xauth}/bin/xauth systemuser=99"}
|
"session optional pam_xauth.so xauthpath=${pkgs.xorg.xauth}/bin/xauth systemuser=99"}
|
||||||
${optionalString (cfg.limits != [])
|
${optionalString (cfg.limits != [])
|
||||||
|
Loading…
x
Reference in New Issue
Block a user