be9157e1c0
When SELinux support is enabled, the login pam file installed by linux-pam should be adjusted to use the pam_selinux.so module. To achieve this in a reasonably simple manner, we introduce the SELinux related lines in login.pam as comments, and if SELinux support is enabled, turn those commented lines into real lines. Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com> Tested-by: Bryce Ferguson <bryce.ferguson@rockwellcollins.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
13 lines
307 B
Plaintext
13 lines
307 B
Plaintext
auth required pam_unix.so nullok
|
|
|
|
account required pam_unix.so
|
|
|
|
password required pam_unix.so nullok
|
|
|
|
# session required pam_selinux.so close
|
|
session required pam_limits.so
|
|
session required pam_env.so
|
|
session required pam_unix.so
|
|
session optional pam_lastlog.so
|
|
# session required pam_selinux.so open
|