summaryrefslogtreecommitdiff
path: root/flake.nix
diff options
context:
space:
mode:
authorDennis Kobert <dennis@kobert.dev>2026-03-10 21:09:32 +0100
committerDennis Kobert <dennis@kobert.dev>2026-03-10 21:09:32 +0100
commit116bd5a46adc7e9caa27f58b19cafe68d3e085f0 (patch)
treee6e8ef72bb5e78fb2f956abdc1fc3646da308a55 /flake.nix
parent29bc563cf1aee51f73ddbce9451fdc3e7ae1e4f9 (diff)
Safe fallback: success=done for pam-any, keep unix without nullok
Diffstat (limited to 'flake.nix')
-rw-r--r--flake.nix17
1 files changed, 11 insertions, 6 deletions
diff --git a/flake.nix b/flake.nix
index 6da2041..efe6a05 100644
--- a/flake.nix
+++ b/flake.nix
@@ -67,17 +67,22 @@
} // lib.genAttrs cfg.services (_name: {
fprintAuth = false;
rules.auth = {
+ # If pam-any succeeds (fingerprint or password in parallel), auth is done.
+ # If it fails/crashes, fall through to normal password prompt as safety net.
pam-any = {
order = cfg.order;
- control = "required";
+ control = "[success=done default=ignore]";
modulePath = "${pam-any}/lib/security/pam_any.so";
args = [ "${pamAnyConfigFile}" ];
};
- # Disable the default unix password auth since pam-any
- # handles it via the pam-any-password helper service.
- unix.enable = lib.mkForce false;
- # Keep deny as a safety net (it won't be reached if
- # pam-any is required and returns success/failure).
+ # Fallback: keep normal password auth but without nullok
+ # so empty passwords are never accepted.
+ unix = {
+ order = 11700;
+ control = "sufficient";
+ modulePath = "${pkgs.linux-pam}/lib/security/pam_unix.so";
+ args = lib.mkForce [ "likeauth" "try_first_pass" ];
+ };
};
});
};