diff options
| author | Fuwn <[email protected]> | 2024-09-22 15:23:35 -0700 |
|---|---|---|
| committer | Fuwn <[email protected]> | 2024-09-22 15:23:35 -0700 |
| commit | 5658bb7f8bf3522c501864ea73024f544b14de3a (patch) | |
| tree | 0436b387e6e815997da89cea46f2deb6984fb8ab /modules/desktop/security/pam.nix | |
| parent | core: move kansai networking to desktop (diff) | |
| download | nixos-config-5658bb7f8bf3522c501864ea73024f544b14de3a.tar.xz nixos-config-5658bb7f8bf3522c501864ea73024f544b14de3a.zip | |
core: move kansai security to desktop
Diffstat (limited to 'modules/desktop/security/pam.nix')
| -rw-r--r-- | modules/desktop/security/pam.nix | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/modules/desktop/security/pam.nix b/modules/desktop/security/pam.nix new file mode 100644 index 0000000..b7eb426 --- /dev/null +++ b/modules/desktop/security/pam.nix @@ -0,0 +1,50 @@ +{ + security = { + pam = { + loginLimits = [ + { + domain = "@wheel"; + item = "nofile"; + type = "soft"; + value = "524288"; + } + { + domain = "@wheel"; + item = "nofile"; + type = "hard"; + value = "1048576"; + } + ]; + + services = + let + ttyAudit = { + enable = true; + enablePattern = "*"; + }; + in + { + swaylock.text = "auth include login"; + gtklock.text = "auth include login"; + + login = { + inherit ttyAudit; + + setLoginUid = true; + }; + + sshd = { + inherit ttyAudit; + + setLoginUid = true; + }; + + sudo = { + inherit ttyAudit; + + setLoginUid = true; + }; + }; + }; + }; +} |