Page MenuHomeDevCentral

D975.id2508.diff
No OneTemporary

D975.id2508.diff

diff --git a/roles/core/sshd/init.sls b/roles/core/sshd/init.sls
--- a/roles/core/sshd/init.sls
+++ b/roles/core/sshd/init.sls
@@ -6,6 +6,25 @@
# License: Trivial work, not eligible to copyright
# -------------------------------------------------------------
+# -------------------------------------------------------------
+# OpenSSH
+# -------------------------------------------------------------
+
/etc/ssh/sshd_config:
file.managed:
- source: salt://roles/core/sshd/files/sshd_config
+
+# -------------------------------------------------------------
+# PAM
+# -------------------------------------------------------------
+
+# T1194 - Debian offers a nologin pam module avoiding people
+# to log in when /run/nologin exists. OS can pop this file,
+# for example at shutdown time or when systemd boot hasn't
+# finished.
+
+pam_disable_nologin:
+ file.comment:
+ - name: /etc/pam.d/sshd
+ - regex: ^account.*pam_nologin\.so
+ - backup: None

File Metadata

Mime Type
text/plain
Expires
Fri, Nov 15, 06:45 (13 h, 8 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
2246157
Default Alt Text
D975.id2508.diff (993 B)

Event Timeline