We would like to add groups, that are allowed to login to a system, to common-account. At the moment we initially template pam.d common-account file via Ansible. After that, the file gets changed by hand a lot and is not consisent accros the infrastructure.
Now we would like to add groups, also per ansible. Problem is the unkown state of the file and the incrementing succes=1 - success=... of pam_succeed_if.so. That leaves us with editing the file maunally to add groups, after initial templating.
#%PAM-1.0
#
# This file is autogenerated by pam-config. All changes
# will be overwritten.
#
# Account-related modules common to all services
#
# This file is included from other service-specific PAM config files,
# and should contain a list of the account modules that define
# the central access policy for use on the system. The default is to
# only deny service to users whose accounts are expired.
#
#account required pam_unix.so try_first_pass
account [success=2 new_authtok_reqd=done default=ignore] pam_unix.so
account [success=1 new_authtok_reqd=done default=ignore] pam_sss.so use_first_pass
account requisite pam_deny.so
account [default=ignore success=7] pam_succeed_if.so quiet uid < 10000
account [default=ignore success=6] pam_succeed_if.so user ingroup SGOps
account [default=ignore success=5] pam_succeed_if.so user ingroup SGDev
account [default=ignore success=4] pam_succeed_if.so user ingroup SGAnsible
account [default=ignore success=3] pam_succeed_if.so user ingroup SGDba
account [default=ignore success=2] pam_succeed_if.so user ingroup SGAdmin
account [default=ignore success=1] pam_succeed_if.so user ingroup SGTSAdmins
account [default=bad success=ignore] pam_succeed_if.so user ingroup doesnotexist
account required pam_permit.so
account required pam_tally2.so
Is there a more convenient way like
account [default=ignore success=1] pam_succeed_if.so quiet uid < 10000
account [default=ignore success=ok] pam_succeed_if.so user ingroup /etc/grouplist