summaryrefslogtreecommitdiff
path: root/data/pam-redhat/gdm-smartcard.pam
diff options
context:
space:
mode:
Diffstat (limited to 'data/pam-redhat/gdm-smartcard.pam')
-rw-r--r--data/pam-redhat/gdm-smartcard.pam18
1 files changed, 18 insertions, 0 deletions
diff --git a/data/pam-redhat/gdm-smartcard.pam b/data/pam-redhat/gdm-smartcard.pam
new file mode 100644
index 00000000..d5ac1fab
--- /dev/null
+++ b/data/pam-redhat/gdm-smartcard.pam
@@ -0,0 +1,18 @@
+# Sample PAM file for doing smartcard authentication.
+# Distros should replace this with what makes sense for them.
+auth required pam_env.so
+auth [success=done ignore=ignore default=die] pam_pkcs11.so wait_for_card card_only
+auth requisite pam_succeed_if.so uid >= 500 quiet
+auth required pam_deny.so
+
+account required pam_unix.so
+account sufficient pam_localuser.so
+account sufficient pam_succeed_if.so uid < 500 quiet
+account required pam_permit.so
+
+password optional pam_pkcs11.so
+password requisite pam_cracklib.so try_first_pass retry=3 type=
+
+session optional pam_keyinit.so revoke
+session required pam_limits.so
+session required pam_unix.so