Make rsh(d) more secure (Hah!) by not defaulting PAM to promiscuously

accepting connections.

Add KDE entries.

Committed From:	BSDConEU Terminal Room
This commit is contained in:
Mark Murray 2001-11-10 14:23:07 +00:00
parent da995dc92b
commit 92678c2908

View File

@ -62,7 +62,7 @@ login session required pam_unix.so
login password required pam_unix.so no_warn try_first_pass
rsh auth required pam_nologin.so no_warn
rsh auth required pam_permit.so no_warn
rsh auth required pam_deny.so no_warn
rsh account required pam_unix.so
rsh session required pam_permit.so
@ -161,6 +161,14 @@ xdm account required pam_unix.so
xdm session required pam_unix.so
xdm password required pam_deny.so
# KDE (screensavers etc)
kde auth required pam_nologin.so no_warn
#kde auth sufficient pam_opie.so no_warn
#kde auth sufficient pam_kerberosIV.so no_warn try_first_pass
#kde auth sufficient pam_krb5.so no_warn try_first_pass
#kde auth required pam_ssh.so no_warn try_first_pass
kde auth required pam_unix.so no_warn try_first_pass
# Mail services
#imap auth required pam_nologin.so no_warn
#imap auth required pam_opie.so no_warn