https://bugs.kde.org/show_bug.cgi?id=481808
--- Comment #37 from nyanpasu64 <[email protected]> --- Created attachment 195054 --> https://bugs.kde.org/attachment.cgi?id=195054&action=edit /etc/pam.d/kde modified to not trigger faillock on sleep-wake According to https://wpollock.com/AUnix2/PAM-Help.htm#advanced, we can recognize specific return codes (like AUTHTOK_ERR) and take specific actions, like "die" to avoid running subsequent faillock. I've prototyped an alternative /etc/pam.d/kde that appears to *work*! (no entries in faillock CLI after sleep and wake, and no "Unlocking failed" message): auth [success=1 authtok_err=die default=bad] pam_unix.so try_first_pass nullok Note that authtok_err needs to be lowercase (unlike the above site), or else even the right password doesn't succeed. I've attached my full modified kde file (made by inlining system-login and system-auth into the file, and editing the innermost system-auth commands). I'm not sure if these files could change in PAM updates or between distros/versions, and our KDE authentication chain would no longer work properly in that context. Does anyone know if *not* triggering faillock upon the authtok_err return code could have any security implications? When I entered the wrong password on purpose, I still found an entry when running faillock in a terminal. -- You are receiving this mail because: You are watching all bug changes.
