[Decaf-devel] Re: [pam_mount] Why does it want my password?

Joachim Breitner nomeata at debian.org
Mon Dec 18 23:20:59 CET 2006


Hi,

Am Montag, den 18.12.2006, 22:42 +0100 schrieb Jan Engelhardt:
> >auth    [ignore=reset system_err=reset default=done]        pam_decaf.so
> >auth    requisite       pam_nologin.so
> >auth    required        pam_env.so read_env=1
> >envfile=/etc/default/locale
> >@include common-auth
> >#auth    sufficient      pam_poldi.so try-pin=123456 quiet timeout=30
> >#auth    required        pam_unix.so nullok_secure
> >
> >@include common-account
> >session required        pam_limits.so
> >@include common-session
> >session  required   pam_mount.so
> >@include common-password
> 
> pam_mount should always be optional. (Though that won't solve
> the problem.)

Really? In this case, a failure in pam_mount should abort the login, as
that would leave the home directory unprotected. (It is protected by a
tmpfs overlay using unionfs)


Greetings,
Joachim
-- 
Joachim "nomeata" Breitner
Debian Developer
  nomeata at debian.org | ICQ# 74513189 | GPG-Keyid: 4743206C
  JID: joachimbreitner at amessage.de | http://people.debian.org/~nomeata




More information about the Decaf-devel mailing list