{"id":15227827,"url":"https://github.com/simp/pupmod-simp-pam","last_synced_at":"2026-02-03T21:13:41.827Z","repository":{"id":32298712,"uuid":"35873673","full_name":"simp/pupmod-simp-pam","owner":"simp","description":"The SIMP pam Puppet Module","archived":false,"fork":false,"pushed_at":"2026-01-13T05:06:55.000Z","size":577,"stargazers_count":2,"open_issues_count":6,"forks_count":22,"subscribers_count":15,"default_branch":"master","last_synced_at":"2026-01-13T08:34:45.223Z","etag":null,"topics":["hacktoberfest","pam","puppet","simp"],"latest_commit_sha":null,"homepage":"","language":"Ruby","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/simp.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2015-05-19T09:49:39.000Z","updated_at":"2025-11-25T17:39:04.000Z","dependencies_parsed_at":"2023-01-14T20:55:51.889Z","dependency_job_id":"1957b786-b939-40a0-bf3b-e69c93539932","html_url":"https://github.com/simp/pupmod-simp-pam","commit_stats":{"total_commits":115,"total_committers":22,"mean_commits":"5.2272727272727275","dds":0.7217391304347827,"last_synced_commit":"addaefca3ae572e3c96eed0e0f5fb5a80ba30e61"},"previous_names":[],"tags_count":39,"template":false,"template_full_name":null,"purl":"pkg:github/simp/pupmod-simp-pam","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/simp%2Fpupmod-simp-pam","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/simp%2Fpupmod-simp-pam/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/simp%2Fpupmod-simp-pam/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/simp%2Fpupmod-simp-pam/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/simp","download_url":"https://codeload.github.com/simp/pupmod-simp-pam/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/simp%2Fpupmod-simp-pam/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29057256,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-03T20:13:53.544Z","status":"ssl_error","status_checked_at":"2026-02-03T20:13:40.507Z","response_time":96,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["hacktoberfest","pam","puppet","simp"],"created_at":"2024-09-28T23:06:12.802Z","updated_at":"2026-02-03T21:13:41.793Z","avatar_url":"https://github.com/simp.png","language":"Ruby","funding_links":[],"categories":[],"sub_categories":[],"readme":"[![License](https://img.shields.io/:license-apache-blue.svg)](http://www.apache.org/licenses/LICENSE-2.0.html)\n[![CII Best Practices](https://bestpractices.coreinfrastructure.org/projects/73/badge)](https://bestpractices.coreinfrastructure.org/projects/73)\n[![Puppet Forge](https://img.shields.io/puppetforge/v/simp/pam.svg)](https://forge.puppetlabs.com/simp/pam)\n[![Puppet Forge Downloads](https://img.shields.io/puppetforge/dt/simp/pam.svg)](https://forge.puppetlabs.com/simp/pam)\n[![Build Status](https://travis-ci.org/simp/pupmod-simp-pam.svg)](https://travis-ci.org/simp/pupmod-simp-pam)\n\n#### Table of Contents\n\n\u003c!-- vim-markdown-toc GFM --\u003e\n\n* [Overview](#overview)\n* [This is a SIMP module](#this-is-a-simp-module)\n* [Module Description](#module-description)\n* [Setup](#setup)\n  * [Setup Requirements](#setup-requirements)\n  * [What ``pam`` Affects](#what-pam-affects)\n* [Usage](#usage)\n  * [Basic Usage](#basic-usage)\n  * [Restricting System Logins (pam_access)](#restricting-system-logins-pam_access)\n    * [Managing System Access](#managing-system-access)\n  * [Restricting Resource Usage (pam_limits)](#restricting-resource-usage-pam_limits)\n  * [Restricting ``su`` to the ``wheel`` Group](#restricting-su-to-the-wheel-group)\n  * [Managing /etc/security/faillock.conf](#managing-etcsecurityfaillockconf)\n    * [/etc/security/faillock.conf Example With All Parameters](#etcsecurityfaillockconf-hieradata-example-with-all-parameters)\n  * [Managing /etc/security/pwhistory.conf](#managing-etcsecuritypwhistoryconf)\n    * [/etc/security/pwhistory.conf Example With All Parameters](#etcsecuritypwhistoryconf-hieradata-example-with-all-parameters)\n* [Development](#development)\n  * [Acceptance tests](#acceptance-tests)\n\n\u003c!-- vim-markdown-toc --\u003e\n\n## Overview\n\nThis module configures PAM in an authoritative, but flexible, manner.\n\nSee [REFERENCE.md](./REFERENCE.md) for API details.\n\n## This is a SIMP module\n\nThis module is a component of the [System Integrity Management Platform](https://simp-project.com),\na compliance-management framework built on Puppet.\n\nIf you find any issues, they can be submitted to our [JIRA](https://simp-project.atlassian.net/).\n\nThis module is optimally designed for use within a larger SIMP ecosystem, but it can be used independently:\n* When included within the SIMP ecosystem, security compliance settings will be\n  managed from the Puppet server.\n* If used independently, all SIMP-managed security subsystems will be disabled by\n  default and must be explicitly opted into by administrators.  Please review\n  [simp_options](https://github.com/simp/pupmod-simp-simp_options) for details.\n\n## Module Description\n\nThis module provides a reasonably safe configuration of the main PAM stack\nfocused on common security and compliance settings. Care has been taken to\nprovide a significant set of switches and override mechanisms in order to\nprovide for user flexibility.\n\n## Setup\n\n### Setup Requirements\n\nNo special dependencies are required for core functionality of this module.\n\nYou will need to download the\n[simp/oath](https://github.com/simp/pupmod-simp-simp_oath) if you want to use\nthe **EXPERIMENTAL** OATH (TOTP/HOTP) support.\n\n### What ``pam`` Affects\n\nThe ``pam`` module modifies various settings in the ``/etc/pam.d/`` and\n``/etc/security`` directories related to user logins via various authentication\nmethods.\n\n## Usage\n\n### Basic Usage\n\nTo set up PAM using a sane set of defaults, you can simply ``include`` the\nclass as follows:\n\n```puppet\ninclude 'pam'\n```\n\nThis will set up PAM with the following capabilities:\n\n* ``pwquality`` settings\n* ``faillock`` support with auto-unlocking\n* Password hash algorithm strengthening\n* Password history management\n* Automatic home directory creation\n* User TTY auditing (only ``root`` by default)\n* Overall default deny\n\n### Restricting System Logins (pam_access)\n\nTo set up a 'default deny' policy for your system (local ``root`` logins are\nalways allowed):\n\n```puppet\ninclude 'pam::access'\n```\n\n#### Managing System Access\n\nThere are two methods for allowing users/groups into the system. The first is\nto use the ``pam::access::rule`` defined type.\n\nThe parameters are named after their counterparts as defined in\n``access.conf(5)``.\n\n```puppet\npam::access::rule { 'Allow Security Group from Anywhere':\n  users   =\u003e ['(security)'],\n  origins =\u003e ['ALL']\n}\n\npam::access::rule { 'Allow Alice from Home':\n  users   =\u003e ['alice'],\n  origins =\u003e ['alice.home.net']\n}\n\npam::access::rule { 'Allow Bob from Local':\n  users   =\u003e ['bob'],\n  origins =\u003e ['LOCAL'],\n  order   =\u003e 2000\n}\n\npam::access::rule { 'Deny Bob from Remote':\n  users      =\u003e ['bob'],\n  origins    =\u003e ['ALL'],\n  permission =\u003e '-',\n  order      =\u003e 2001\n}\n```\n\nThe second method is to define the access list as a ``Hash`` directly in Hiera:\n\n```yaml\n---\npam::access::users:\n  defaults:\n    origins:\n      - ALL\n    permission: \"+\"\n    \"(security)\":\n    alice:\n      origins:\n        - 'alice.home.net'\n    # Note, the hiera method is not as flexible so we needed to use the 'bob'\n    # group so that we could properly restrict the 'bob' user.\n    \"(bob)\":\n      origins:\n        - 'LOCAL'\n      order: 2000\n    'bob':\n      permission: \"-\"\n      order: 2001\n```\n\n### Restricting Resource Usage (pam_limits)\n\nTo activate management of various PAM resource limits via\n``/etc/security/limits.conf``:\n\n```puppet\ninclude 'pam::limits'\n```\n\nYou can then use the module to restrict resource limits for logged in\naccordance with the ``pam_limits(8)`` documentation.\n\n```puppet\npam::limits::rule { 'Limit Number of Processes for all Users':\n  domains =\u003e ['*'],\n  type    =\u003e 'soft',\n  item    =\u003e 'nproc',\n  value   =\u003e 50\n}\n```\n\nThe second method is to define the rule list as a ``Hash`` directly in Hiera:\n\n```yaml\n---\npam::limits::rules:\n  disable_core_for_all:\n    domains:\n      - '*'\n    type: 'hard'\n    item: 'core'\n    value: 0\n    order: 100\n```\n\n### Restricting ``su`` to the ``wheel`` Group\n\nTo restrict the use of ``su`` to the ``wheel`` group:\n\n```puppet\ninclude 'pam::wheel'\n```\n\nYou can change the target group by updating the value of\n``pam::wheel::wheel_group`` via Hiera.\n\n### Managing /etc/security/faillock.conf\n\nTo manage faillock with ``/etc/security/faillock.conf`` set the following in hieradata:\n\n```yaml\npam::manage_faillock_conf: true\n```\n\nA couple of things to note here are:\n\n- This feature will only work on systems running EL 8 (or equivalent) and above.\n- ``pam::faillock`` must still be true for faillock to work appropriately\n- By default, /etc/security/faillock.conf will be empty except for a comment saying the file is managed by puppet. To set content in the file, the following parameters are available:\n\n  - ``pam::faillock_log_dir``\n  - ``pam::faillock_audit``\n  - ``pam::display_account_lock``\n  - ``pam::faillock_no_log_info``\n  - ``pam::faillock_local_users_only``\n  - ``pam::faillock_nodelay``\n  - ``pam::deny``\n  - ``pam::fail_interval``\n  - ``pam::unlock_time``\n  - ``pam::even_deny_root``\n  - ``pam::root_unlock_time``\n  - ``pam::faillock_admin_group``\n\n#### /etc/security/faillock.conf Hieradata Example With All Parameters\n\n```yaml\npam::faillock: true\npam::manage_faillock_conf: true\npam::faillock_log_dir: '/var/log/faillock'\npam::faillock_audit: true\npam::display_account_lock: true\npam::faillock_no_log_info: false\npam::faillock_local_users_only: false\npam::faillock_nodelay: false\npam::deny: 5\npam::fail_interval: 900\npam::unlock_time: 900\npam::even_deny_root: true\npam::root_unlock_time: 60\npam::faillock_admin_group: 'wheel'\n```\n\n### Managing /etc/security/pwhistory.conf\n\nTo manage pwhistory with ``/etc/security/pwhistory.conf`` set the following in hieradata:\n\n```yaml\npam::manage_pwhistory_conf: true\n```\n\nA couple of things to note here are:\n\n- This feature will only work on systems running EL 8 (or equivalent) and above.\n- This feature replaced management of /etc/security/opasswd in the SIMP Useradd module as of version 7.0.0 and will conflict with any version of useradd older than 1.0.0.\n  - The parameter to control where password history is set is ``pam::remember_file``\n\n#### /etc/security/pwhistory.conf Hieradata Example With All Parameters\n\n```yaml\npam::manage_pwhistory_conf: true\npam::remember: 32\npam::remember_retry: 3\npam::remember_file: '/etc/security/opasswd'\npam::remember_debug: true\npam::remember_for_root: true\n```\n\n## Development\n\nPlease read our [Contribution Guide](https://simp.readthedocs.io/en/stable/contributors_guide/Contribution_Procedure.html)\n\n### Acceptance tests\n\nThis module includes [Beaker](https://github.com/puppetlabs/beaker) acceptance\ntests using the SIMP [Beaker Helpers](https://github.com/simp/rubygem-simp-beaker-helpers).\nBy default the tests use [Vagrant](https://www.vagrantup.com/) with\n[VirtualBox](https://www.virtualbox.org) as a back-end; Vagrant and VirtualBox\nmust both be installed to run these tests without modification. To execute the\ntests run the following:\n\n```shell\nbundle exec rake beaker:suites\n```\n\nSome environment variables may be useful:\n\n```shell\nBEAKER_debug=true\nBEAKER_provision=no\nBEAKER_destroy=no\nBEAKER_use_fixtures_dir_for_modules=yes\nBEAKER_fips=yes\n```\n\n* `BEAKER_debug`: show the commands being run on the STU and their output.\n* `BEAKER_destroy=no`: prevent the machine destruction after the tests finish so you can inspect the state.\n* `BEAKER_provision=no`: prevent the machine from being recreated. This can save a lot of time while you're writing the tests.\n* `BEAKER_use_fixtures_dir_for_modules=yes`: cause all module dependencies to be loaded from the `spec/fixtures/modules` directory, based on the contents of `.fixtures.yml`.  The contents of this directory are usually populated by `bundle exec rake spec_prep`.  This can be used to run acceptance tests to run on isolated networks.\n* `BEAKER_fips=yes`: enable FIPS-mode on the virtual instances. This can\n  take a very long time, because it must enable FIPS in the kernel\n  command-line, rebuild the initramfs, then reboot.\n\nPlease refer to the [SIMP Beaker Helpers documentation](https://github.com/simp/rubygem-simp-beaker-helpers/blob/master/README.md)\nfor more information.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsimp%2Fpupmod-simp-pam","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsimp%2Fpupmod-simp-pam","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsimp%2Fpupmod-simp-pam/lists"}