From 8117e6589eba29de4581b5770176b55807b0212f Mon Sep 17 00:00:00 2001 From: Dennis Kobert Date: Tue, 10 Mar 2026 20:47:05 +0100 Subject: Use required control and disable default unix auth on pam-any services --- flake.nix | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/flake.nix b/flake.nix index ee980c4..d21c347 100644 --- a/flake.nix +++ b/flake.nix @@ -66,11 +66,18 @@ ''; } // lib.genAttrs cfg.services (_name: { fprintAuth = false; - rules.auth.pam-any = { - order = cfg.order; - control = "sufficient"; - modulePath = "${pam-any}/lib/security/pam_any.so"; - args = [ "${pamAnyConfigFile}" ]; + rules.auth = { + pam-any = { + order = cfg.order; + control = "required"; + modulePath = "${pam-any}/lib/security/pam_any.so"; + args = [ "${pamAnyConfigFile}" ]; + }; + # Disable the default unix password auth since pam-any + # handles it via the pam-any-password helper service. + unix.enable = false; + # Keep deny as a safety net (it won't be reached if + # pam-any is required and returns success/failure). }; }); }; -- cgit v1.3.1