On St, 2016-02-17 at 13:53 +0100, Matus UHLAR - fantomas wrote: > Hello, > > can I differ between nonexistent user and invalid password in > pam.conf? > > I want invalid user to be left for next authentication module, but > invalid > password to be rejected, so other people can not override password I > set for > local users. > > I currently have: > > auth [success=2 default=ignore] pam_unix.so nullok_secure > > I have tried to add "auth_err=die" but that caused remot logins to be > refused too... Unfortunately that does not work. You can use pam_localuser before pam_unix and jump over it for non-local users. -- Tomas Mraz No matter how far down the wrong road you've gone, turn back. Turkish proverb (You'll never know whether the road is wrong though.) _______________________________________________ Pam-list mailing list Pam-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/pam-list