From 8f07ad0ead8e4ea7d6604d6b90b34c339b470f1b Mon Sep 17 00:00:00 2001 From: Gabor Solya Date: Thu, 9 Jan 2025 19:10:51 +0100 Subject: [PATCH] CB-27664 Remove nullok from /etc/pam.d/password-auth and /etc/pam.d/system-auth --- saltstack/final/salt/cis-controls/etc/pam.d/password-auth | 4 ++-- saltstack/final/salt/cis-controls/etc/pam.d/system-auth | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/saltstack/final/salt/cis-controls/etc/pam.d/password-auth b/saltstack/final/salt/cis-controls/etc/pam.d/password-auth index d358175b6..108e74a16 100644 --- a/saltstack/final/salt/cis-controls/etc/pam.d/password-auth +++ b/saltstack/final/salt/cis-controls/etc/pam.d/password-auth @@ -3,7 +3,7 @@ auth required pam_faillock.so preauth silent audit deny=3 unlock_tim auth required pam_faildelay.so delay=2000000 auth [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet auth [default=1 ignore=ignore success=ok] pam_localuser.so -auth sufficient pam_unix.so nullok try_first_pass +auth sufficient pam_unix.so try_first_pass auth [default=die] pam_faillock.so authfail audit deny=3 unlock_time=900 auth requisite pam_succeed_if.so uid >= 1000 quiet_success auth sufficient pam_sss.so forward_pass @@ -17,7 +17,7 @@ account [default=bad success=ok user_unknown=ignore] pam_sss.so account required pam_permit.so password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type= ucredit=-1 lcredit=-1 dcredit=-1 ocredit=-1 -password sufficient pam_unix.so sha512 shadow nullok try_first_pass remember=5 use_authtok +password sufficient pam_unix.so sha512 shadow try_first_pass remember=5 use_authtok password sufficient pam_sss.so use_authtok password required pam_deny.so diff --git a/saltstack/final/salt/cis-controls/etc/pam.d/system-auth b/saltstack/final/salt/cis-controls/etc/pam.d/system-auth index 817689d07..278b3f586 100644 --- a/saltstack/final/salt/cis-controls/etc/pam.d/system-auth +++ b/saltstack/final/salt/cis-controls/etc/pam.d/system-auth @@ -4,7 +4,7 @@ auth required pam_faildelay.so delay=2000000 auth sufficient pam_fprintd.so auth [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet auth [default=1 ignore=ignore success=ok] pam_localuser.so -auth sufficient pam_unix.so nullok try_first_pass +auth sufficient pam_unix.so try_first_pass auth [default=die] pam_faillock.so authfail audit deny=3 unlock_time=900 auth requisite pam_succeed_if.so uid >= 1000 quiet_success auth sufficient pam_sss.so forward_pass @@ -18,7 +18,7 @@ account [default=bad success=ok user_unknown=ignore] pam_sss.so account required pam_permit.so password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type= ucredit=-1 lcredit=-1 dcredit=-1 ocredit=-1 -password sufficient pam_unix.so sha512 shadow nullok try_first_pass remember=5 use_authtok +password sufficient pam_unix.so sha512 shadow try_first_pass remember=5 use_authtok password sufficient pam_sss.so use_authtok password required pam_deny.so