PAM common-account pam_succeed_if.so list of groups without increment skip counter e.g. success=1 success=2 success=3

Viewed 165

We would like to add groups, that are allowed to login to a system, to common-account. At the moment we initially template pam.d common-account file via Ansible. After that, the file gets changed by hand a lot and is not consisent accros the infrastructure.

Now we would like to add groups, also per ansible. Problem is the unkown state of the file and the incrementing succes=1 - success=... of pam_succeed_if.so. That leaves us with editing the file maunally to add groups, after initial templating.

#%PAM-1.0
#
# This file is autogenerated by pam-config. All changes
# will be overwritten.
#
# Account-related modules common to all services
#
# This file is included from other service-specific PAM config files,
# and should contain a list of the account modules that define
# the central access policy for use on the system.  The default is to
# only deny service to users whose accounts are expired.
#
#account        required        pam_unix.so     try_first_pass

account [success=2 new_authtok_reqd=done default=ignore]        pam_unix.so
account [success=1 new_authtok_reqd=done default=ignore]        pam_sss.so      use_first_pass
account requisite pam_deny.so

account [default=ignore success=7] pam_succeed_if.so    quiet uid < 10000
account [default=ignore success=6] pam_succeed_if.so    user ingroup SGOps
account [default=ignore success=5] pam_succeed_if.so    user ingroup SGDev
account [default=ignore success=4] pam_succeed_if.so    user ingroup SGAnsible
account [default=ignore success=3] pam_succeed_if.so    user ingroup SGDba
account [default=ignore success=2] pam_succeed_if.so    user ingroup SGAdmin
account [default=ignore success=1] pam_succeed_if.so    user ingroup SGTSAdmins

account [default=bad success=ignore] pam_succeed_if.so  user ingroup doesnotexist

account required        pam_permit.so

account required        pam_tally2.so

Is there a more convenient way like

account [default=ignore success=1] pam_succeed_if.so    quiet uid < 10000
account [default=ignore success=ok] pam_succeed_if.so    user ingroup /etc/grouplist
0 Answers
Related