Subject: Re: PAM enabled on head
To: None <current-users@netbsd.org>
From: Klaus Klein <kleink@mibh.de>
List: current-users
Date: 03/08/2005 08:37:06
On Tuesday, 8. March 2005 07:28, Bernd Ernesti wrote:
> On Mon, Mar 07, 2005 at 11:17:29PM -0500, Christos Zoulas wrote:
> [..]
> 
> > We have changed PAM to fail closed. I.e. a missing PAM configuration will
> > default to fail authentication as opposed to allow it. We are still
> > thinking of adding even more strict checks in the authentication path, so
> > that incorrect configurations will not default to allow someone access.
> 
> So this means that you can no longer login if you don't have an /etc/pam.d
> or an empty one?

Precisely.


- Klaus