On ma, 18 maalis 2019, Jelle de Jong via FreeIPA-users wrote:
Hello everybody,


I am looking for a way to have different authentication policy for a freeia-client logout and screenlock on linux workstations.

When a user logs in I want to use my password+otp (this is working)!

When a user locks it screen I want to be able unlock it with only the password.

When a user logs out and back in then it needs to use the password+otp again.

I am aware of the security implications for this.

How can I configure this policy?
I don't think there is a way to deploy such policy through SSSD at all.

Jakub, do you have an idea how to make that possible?

--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to