xref: /freebsd/contrib/pam-krb5/tests/data/scripts/expired/defer-mit (revision bf6873c5786e333d679a7838d28812febf479a8a)
1# Test deferring handling of expired passwords.  -*- conf -*-
2#
3# Written by Russ Allbery <eagle@eyrie.org>
4# Copyright 2014, 2020 Russ Allbery <eagle@eyrie.org>
5# Copyright 2010-2011
6#     The Board of Trustees of the Leland Stanford Junior University
7#
8# SPDX-License-Identifier: BSD-3-clause or GPL-1+
9
10[options]
11    auth     = defer_pwchange use_first_pass
12    account  = ignore_k5login
13    password = ignore_k5login use_first_pass
14
15[run]
16    authenticate              = PAM_SUCCESS
17    acct_mgmt                 = PAM_NEW_AUTHTOK_REQD
18    chauthtok(PRELIM_CHECK)   = PAM_SUCCESS
19    chauthtok(UPDATE_AUTHTOK) = PAM_SUCCESS
20    acct_mgmt                 = PAM_SUCCESS
21    open_session              = PAM_SUCCESS
22    close_session             = PAM_SUCCESS
23
24[prompts]
25    echo_off = Current Kerberos password: |%p
26    echo_off = Enter new Kerberos password: |%n
27    echo_off = Retype new Kerberos password: |%n
28
29[output]
30    INFO user %u authenticated as %0 (expired)
31    INFO user %u account password is expired
32    INFO user %u changed Kerberos password
33    INFO user %u authenticated as %0
34