@@ -16,6 +16,10 @@ auth sufficient pam_unix.so nullok try_first_pass
16
16
auth [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet
17
17
auth sufficient pam_sss.so forward_pass
18
18
{% endif %}
19
+ {% if (os_auth_pam_winbind_enable | bool ) %}
20
+ auth [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet
21
+ auth sufficient pam_winbind.so use_first_pass
22
+ {% endif %}
19
23
{% if os_auth_retries > 0 %}
20
24
auth required pam_faillock.so authfail audit even_deny_root deny={{ os_auth_retries }} unlock_time={{ os_auth_lockout_time }}
21
25
{% endif %}
@@ -30,6 +34,9 @@ account sufficient pam_succeed_if.so uid < 1000 quiet
30
34
{% if (os_auth_pam_sssd_enable | bool ) %}
31
35
account [default=bad success=ok user_unknown=ignore] pam_sss.so
32
36
{% endif %}
37
+ {% if (os_auth_pam_winbind_enable | bool ) %}
38
+ account [default=bad success=ok user_unknown=ignore] pam_winbind.so
39
+ {% endif %}
33
40
account required pam_permit.so
34
41
35
42
{% if (os_auth_pam_passwdqc_enable | bool ) %}
@@ -42,6 +49,9 @@ password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_au
42
49
{% if (os_auth_pam_sssd_enable | bool ) %}
43
50
password sufficient pam_sss.so use_authtok
44
51
{% endif %}
52
+ {% if (os_auth_pam_winbind_enable | bool ) %}
53
+ password sufficient pam_winbind.so use_authtok
54
+ {% endif %}
45
55
password required pam_deny.so
46
56
47
57
session optional pam_keyinit.so revoke
@@ -52,3 +62,6 @@ session required pam_unix.so
52
62
{% if (os_auth_pam_sssd_enable | bool ) %}
53
63
session optional pam_sss.so
54
64
{% endif %}
65
+ {% if (os_auth_pam_winbind_enable | bool ) %}
66
+ session optional pam_winbind.so
67
+ {% endif %}
0 commit comments