user cont...@itopie.ch
usertags 618722 + itopie.ch-installation
user i...@codha.ch
usertags 618722 + codha.ch-installation
thanks

Hi there,

On Sun, 04 May 2014 00:39:15 +0200, Raymond Pettersen wrote:
> I ended up with the following solution, which doesn't break pam-auth-update.
> 
> Change the common-account file in /usr/share/pam, and replace "requisite" with
> "optional". Run pam-auth-update and make sure that the /etc files are updated.
> 
> pam-ccreds should now work properly (tested on debian wheezy).

I can confirm that simply demoting pam_deny.so to optional in
common-account does the trick.

However, that should not be done in /usr/share/pam/common-account, since
such modification will be lost whenever the package will be upgraded (or
reinstalled).  Thus, it is better to modify /etc/pam.d/common-account
instead, which is preserved even after a pam-auth-update run.

To answer Guido's request for co-maintenance: I moved to sssd for a
while now, but I am currently testing a wider setup and evaluating again
pam-ccreds...

Thx, bye,
Gismo / Luca

Attachment: signature.asc
Description: Digital signature

Reply via email to