summaryrefslogtreecommitdiffstats
path: root/nixos
diff options
context:
space:
mode:
authorMilan Pässler <mil@nyantec.com>2021-01-03 15:30:08 +0100
committerFrederik Rietdijk <freddyrietdijk@fridh.nl>2021-01-03 15:54:23 +0100
commit018072ea221254a449d11e45acba0f4b1f688c9d (patch)
tree5eef7bae6ba77a50a16666b1958efa3dd5abb01e /nixos
parent499792889db010e29213963544b0de7f5af66fe0 (diff)
nixos/pam: use pam_faillock instead of pam_tally
Fixes #108313 \#107185 removed pam_tally, in favor of pam_faillock (see release notes).
Diffstat (limited to 'nixos')
-rw-r--r--nixos/modules/security/pam.nix2
1 files changed, 1 insertions, 1 deletions
diff --git a/nixos/modules/security/pam.nix b/nixos/modules/security/pam.nix
index a428103eaa96..1522111dbddf 100644
--- a/nixos/modules/security/pam.nix
+++ b/nixos/modules/security/pam.nix
@@ -394,7 +394,7 @@ let
${optionalString cfg.requireWheel
"auth required pam_wheel.so use_uid"}
${optionalString cfg.logFailures
- "auth required pam_tally.so"}
+ "auth required pam_faillock.so"}
${optionalString (config.security.pam.enableSSHAgentAuth && cfg.sshAgentAuth)
"auth sufficient ${pkgs.pam_ssh_agent_auth}/libexec/pam_ssh_agent_auth.so file=${lib.concatStringsSep ":" config.services.openssh.authorizedKeysFiles}"}
${optionalString cfg.fprintAuth