freebsd-skq/etc/pam.d/su
Robert Watson 64ac587b8a Exempt the "wheel group requirement" by default when su'ing to root if
the wheel group has no explicit members listed in /etc/group.  This adds
the "exempt_if_empty" flag to pam_wheel in the default configuration;
in some environments, it may be appropriate to remove this flag, however,
this default is the same as pre-pam_wheel.

Reviewed by:	markm
Sponsored by:	DARPA, Network Associates Laboratories
2002-10-18 02:39:21 +00:00

54 lines
1.4 KiB
Plaintext

#
# $FreeBSD$
#
# PAM configuration for the "su" service
#
# auth
auth sufficient pam_rootok.so no_warn
auth sufficient pam_self.so no_warn
auth requisite pam_wheel.so no_warn auth_as_self noroot_ok exempt_if_empty
#auth sufficient pam_kerberosIV.so no_warn
#auth sufficient pam_krb5.so no_warn try_first_pass auth_as_self
auth sufficient pam_opie.so no_warn no_fake_prompts
auth requisite pam_opieaccess.so no_warn
#auth required pam_ssh.so no_warn try_first_pass
auth required pam_unix.so no_warn try_first_pass nullok
# account
#account required pam_kerberosIV.so
#account required pam_krb5.so
account required pam_unix.so
# session
#session required pam_kerberosIV.so
#session required pam_krb5.so
#session required pam_ssh.so
# password
password required pam_permit.so
# If you want a "WHEELSU"-type su(1), then comment out the
# above, and uncomment the entries below.
## auth
#auth sufficient pam_rootok.so no_warn
##auth sufficient pam_kerberosIV.so no_warn
##auth sufficient pam_krb5.so no_warn
#auth required pam_opie.so no_warn auth_as_self no_fake_prompts
#auth required pam_unix.so no_warn try_first_pass auth_as_self
## account
##account required pam_kerberosIV.so
##account required pam_krb5.so
#account required pam_unix.so
## session
##session required pam_kerberosIV.so
##session required pam_krb5.so
##session required pam_ssh.so
#session required pam_unix.so
## password
#password required pam_permit.so