Skip to content

Conversation

@huckabeec
Copy link

This adds the option 'ignore_groups' where a comma separated list of groups of users who should not be considered by pam_krb5 can be provided.

This was added to work around the lack of advanced conditional syntax in macOS where OpenPAM is used vs Linux-PAM. Our specific use case is where pam_krb5 is used with FAST for OTP but there are non-OTP users present on the host.

minimum_uid doesn't help in these cases as these non-OTP users exist in a variety of uid ranges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant