1# Test deferring handling of expired passwords. -*- conf -*- 2# 3# Written by Russ Allbery <eagle@eyrie.org> 4# Copyright 2014, 2020 Russ Allbery <eagle@eyrie.org> 5# Copyright 2010-2011 6# The Board of Trustees of the Leland Stanford Junior University 7# 8# SPDX-License-Identifier: BSD-3-clause or GPL-1+ 9 10[options] 11 auth = defer_pwchange use_first_pass 12 account = ignore_k5login 13 password = ignore_k5login use_first_pass 14 15[run] 16 authenticate = PAM_SUCCESS 17 acct_mgmt = PAM_NEW_AUTHTOK_REQD 18 chauthtok(PRELIM_CHECK) = PAM_SUCCESS 19 chauthtok(UPDATE_AUTHTOK) = PAM_SUCCESS 20 acct_mgmt = PAM_SUCCESS 21 open_session = PAM_SUCCESS 22 close_session = PAM_SUCCESS 23 24[prompts] 25 echo_off = Current Kerberos password: |%p 26 echo_off = Enter new Kerberos password: |%n 27 echo_off = Retype new Kerberos password: |%n 28 29[output] 30 INFO user %u authenticated as %0 (expired) 31 INFO user %u account password is expired 32 INFO user %u changed Kerberos password 33 INFO user %u authenticated as %0 34