enable pam-plugin-faillock when it's installed with custom settings #724
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary of Changes
ni-authis installedJustification
This change simplifies Secured, Network-Attached Controller (SNAC) configuration, AB#2816939. faillock is required to be enabled on a SNAC. The faillock settings were chosen to comply with SNAC requirements. The conflict with
ni-authwas added because from testing it appears that the faillock plugin is incompatible with the ni-auth plugin.Testing
I tested that opkg returns a clear error message when installing
pam-plugin-faillockdescribing the conflict ifni-authis installed. I confirmed thatlibpam-runtimecontains the customized/etc/security/faillock.conf. After removingni-auth, I installedpam-plugin-faillockand confirmed that the configuration files changed as I expected.I confirmed that
common-authwas reverted after removingpam-plugin-faillock.bitbake packagefeed-ni-core)Procedure
@ni/rtos @amstewart