summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--flake.nix17
1 files changed, 11 insertions, 6 deletions
diff --git a/flake.nix b/flake.nix
index 6da2041..efe6a05 100644
--- a/flake.nix
+++ b/flake.nix
@@ -67,17 +67,22 @@
} // lib.genAttrs cfg.services (_name: {
fprintAuth = false;
rules.auth = {
+ # If pam-any succeeds (fingerprint or password in parallel), auth is done.
+ # If it fails/crashes, fall through to normal password prompt as safety net.
pam-any = {
order = cfg.order;
- control = "required";
+ control = "[success=done default=ignore]";
modulePath = "${pam-any}/lib/security/pam_any.so";
args = [ "${pamAnyConfigFile}" ];
};
- # Disable the default unix password auth since pam-any
- # handles it via the pam-any-password helper service.
- unix.enable = lib.mkForce false;
- # Keep deny as a safety net (it won't be reached if
- # pam-any is required and returns success/failure).
+ # Fallback: keep normal password auth but without nullok
+ # so empty passwords are never accepted.
+ unix = {
+ order = 11700;
+ control = "sufficient";
+ modulePath = "${pkgs.linux-pam}/lib/security/pam_unix.so";
+ args = lib.mkForce [ "likeauth" "try_first_pass" ];
+ };
};
});
};