--- /dev/null
+##
+## THIS FILE IS UNDER PUPPET CONTROL. DON'T EDIT IT HERE.
+## USE: git clone git+ssh://$USER@puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet.git
+##
+#%PAM-1.0
+
+auth [authinfo_unavail=ignore success=done ignore=ignore default=die] pam_pwdfile.so pwdfile=/var/lib/misc/thishost/sudo-passwd
+auth required pam_unix.so nullok_secure try_first_pass
+@include common-account
+
+session required pam_permit.so
+session required pam_limits.so
mode => 440,
source => [ "puppet:///sudo/per-host/$fqdn/sudoers",
"puppet:///sudo/common/sudoers" ],
- require => Package["sudo"],
+ require => Package["sudo"]
+ ;
+ "/etc/pam.d/sudo":
+ source => [ "puppet:///sudo/per-host/$fqdn/pam",
+ "puppet:///sudo/common/pam" ],
+ require => Package["sudo"]
+ ;
+
}
}