3: 2021-06-26 (Sat) 18:35:06 iseki |
4: 2021-06-27 (Sun) 21:48:43 iseki |
| | | |
| ****設定ファイル [#q45b6791] | | ****設定ファイル [#q45b6791] |
| + | - authconfig, authconfig-uti コマンドでデフォルトの設定ファイルを用意してくくれる |
| + | |
| - /etc/sssd/[[sssd.conf>./sssd.conf]] | | - /etc/sssd/[[sssd.conf>./sssd.conf]] |
| - /etc/nsswitch.conf | | - /etc/nsswitch.conf |
| -- sss を追加 | | -- sss を追加 |
- | - /etc/sysconfig/authconfig | + | - [[/etc/pam.d>PAM]]/* |
- | -- SSSD関連を yes, LDAP関連を no (いらんかも知れない.いらん気がする.参考程度に記す) | + | - /etc/sysconfig/authconfig |
| + | -- 手動:SSSD関連を yes, LDAP関連を no (手動は意味ないかも知れない.ない気がする.参考程度に記す) |
| #br | | #br |
| | | |
| | | |
| # sssctl domain-status default | | # sssctl domain-status default |
| + | #br |
| + | |
| + | *** [[PAM]] [#t20d7915] |
| + | |
| + | **** system-auth [#c33cbec0] |
| + | |
| + | auth required pam_env.so |
| + | auth required pam_faildelay.so delay=2000000 |
| + | auth [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet |
| + | auth [default=1 ignore=ignore success=ok] pam_localuser.so |
| + | auth sufficient pam_unix.so nullok try_first_pass |
| + | auth requisite pam_succeed_if.so uid >= 1000 quiet_success |
| + | auth sufficient pam_sss.so forward_pass |
| + | auth required pam_deny.so |
| + | |
| + | account required pam_unix.so broken_shadow |
| + | account sufficient pam_localuser.so |
| + | account sufficient pam_succeed_if.so uid < 1000 quiet |
| + | account [default=bad success=ok user_unknown=ignore] pam_sss.so |
| + | account required pam_permit.so |
| + | |
| + | password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type= |
| + | password sufficient pam_unix.so shadow nullok try_first_pass use_authtok |
| + | password sufficient pam_sss.so use_authtok |
| + | password required pam_deny.so |
| + | |
| + | session optional pam_keyinit.so revoke |
| + | session required pam_limits.so |
| + | -session optional pam_systemd.so |
| + | session optional pam_oddjob_mkhomedir.so umask=0077 |
| + | session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid |
| + | session required pam_unix.so |
| + | session optional pam_sss.so |
| + | **** password-auth [#x8b5ec4d] |
| + | auth required pam_env.so |
| + | auth required pam_faildelay.so delay=2000000 |
| + | auth [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet |
| + | auth [default=1 ignore=ignore success=ok] pam_localuser.so |
| + | auth sufficient pam_unix.so nullok try_first_pass |
| + | auth requisite pam_succeed_if.so uid >= 1000 quiet_success |
| + | auth sufficient pam_sss.so forward_pass |
| + | auth required pam_deny.so |
| + | |
| + | account required pam_unix.so broken_shadow |
| + | account sufficient pam_localuser.so |
| + | account sufficient pam_succeed_if.so uid < 1000 quiet |
| + | account [default=bad success=ok user_unknown=ignore] pam_sss.so |
| + | account required pam_permit.so |
| + | |
| + | password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type= |
| + | password sufficient pam_unix.so shadow nullok try_first_pass use_authtok |
| + | password sufficient pam_sss.so use_authtok |
| + | password required pam_deny.so |
| + | |
| + | session optional pam_keyinit.so revoke |
| + | session required pam_limits.so |
| + | -session optional pam_systemd.so |
| + | session optional pam_oddjob_mkhomedir.so umask=0077 |
| + | session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid |
| + | session required pam_unix.so |
| + | session optional pam_sss.so |