summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDennis Kobert <dennis@kobert.dev>2026-03-10 20:47:05 +0100
committerDennis Kobert <dennis@kobert.dev>2026-03-10 20:47:05 +0100
commit8117e6589eba29de4581b5770176b55807b0212f (patch)
tree5c7258f59c1667daacce7b33197ad7b1e32e9d8b
parent3341e1e694ad64c12055c42008c4927c327950de (diff)
Use required control and disable default unix auth on pam-any services
-rw-r--r--flake.nix17
1 files changed, 12 insertions, 5 deletions
diff --git a/flake.nix b/flake.nix
index ee980c4..d21c347 100644
--- a/flake.nix
+++ b/flake.nix
@@ -66,11 +66,18 @@
'';
} // lib.genAttrs cfg.services (_name: {
fprintAuth = false;
- rules.auth.pam-any = {
- order = cfg.order;
- control = "sufficient";
- modulePath = "${pam-any}/lib/security/pam_any.so";
- args = [ "${pamAnyConfigFile}" ];
+ rules.auth = {
+ pam-any = {
+ order = cfg.order;
+ control = "required";
+ modulePath = "${pam-any}/lib/security/pam_any.so";
+ args = [ "${pamAnyConfigFile}" ];
+ };
+ # Disable the default unix password auth since pam-any
+ # handles it via the pam-any-password helper service.
+ unix.enable = false;
+ # Keep deny as a safety net (it won't be reached if
+ # pam-any is required and returns success/failure).
};
});
};