summaryrefslogtreecommitdiff
path: root/debian/pam-configs/unix
diff options
context:
space:
mode:
authorKees Cook <kees@ubuntu.com>2008-11-05 12:34:02 -0800
committerSteve Langasek <steve.langasek@ubuntu.com>2019-01-03 17:28:28 -0800
commit266b2533ab58c22309adf5bc31363d517298a732 (patch)
tree452fe47f1c06e00f6a8a24614a74a492666c17d5 /debian/pam-configs/unix
parent8fc424edae1212a89979b2cd9b5f66796ae9e7bc (diff)
Allow passwords to change on expired accounts, by passing new_authtok_reqd return codes immediately (LP: #291091).
Diffstat (limited to 'debian/pam-configs/unix')
-rw-r--r--debian/pam-configs/unix4
1 files changed, 2 insertions, 2 deletions
diff --git a/debian/pam-configs/unix b/debian/pam-configs/unix
index 3bc350e7..4bb6bab4 100644
--- a/debian/pam-configs/unix
+++ b/debian/pam-configs/unix
@@ -8,9 +8,9 @@ Auth-Initial:
[success=end default=ignore] pam_unix.so nullok_secure
Account-Type: Primary
Account:
- [success=end default=ignore] pam_unix.so
+ [success=end new_authtok_reqd=done default=ignore] pam_unix.so
Account-Initial:
- [success=end default=ignore] pam_unix.so
+ [success=end new_authtok_reqd=done default=ignore] pam_unix.so
Session-Type: Additional
Session:
required pam_unix.so