diff options
| -rw-r--r-- | flake.nix | 17 |
1 files changed, 11 insertions, 6 deletions
@@ -67,17 +67,22 @@ } // lib.genAttrs cfg.services (_name: { fprintAuth = false; rules.auth = { + # If pam-any succeeds (fingerprint or password in parallel), auth is done. + # If it fails/crashes, fall through to normal password prompt as safety net. pam-any = { order = cfg.order; - control = "required"; + control = "[success=done default=ignore]"; modulePath = "${pam-any}/lib/security/pam_any.so"; args = [ "${pamAnyConfigFile}" ]; }; - # Disable the default unix password auth since pam-any - # handles it via the pam-any-password helper service. - unix.enable = lib.mkForce false; - # Keep deny as a safety net (it won't be reached if - # pam-any is required and returns success/failure). + # Fallback: keep normal password auth but without nullok + # so empty passwords are never accepted. + unix = { + order = 11700; + control = "sufficient"; + modulePath = "${pkgs.linux-pam}/lib/security/pam_unix.so"; + args = lib.mkForce [ "likeauth" "try_first_pass" ]; + }; }; }); }; |
