|
Bugzilla – Full Text Bug Listing |
| Summary: | sudo can unlock pam_faillock | ||
|---|---|---|---|
| Product: | Sudo | Reporter: | nbztx |
| Component: | Sudo | Assignee: | Todd C. Miller <Todd.Miller> |
| Status: | RESOLVED WONTFIX | ||
| Severity: | normal | ||
| Priority: | low | ||
| Version: | 1.8.23 | ||
| Hardware: | PC | ||
| OS: | Linux | ||
|
Description
nbztx
2020-07-06 07:58:31 MDT
*** Bug 933 has been marked as a duplicate of this bug. *** This is really a PAM configuration issue. Sudo must call into PAM even when not validating a password to properly setup the session. As you;ve seen, this may cause pam_faillock to release the lock. I don't see a way around that other than removing pam_faillock from sudo's PAM configuration. Since sudo runs after the user has already validated, pam_faillock is less useful and is better left out of sudo's PAM configuration entirely. Unfortunately, this is not always simple due to the way modern PAM configurations have been structured using large include files. |