pam-ussh
pam-ussh copied to clipboard
Improve principal restriction logic
Make optional requiring that certs contain a principal matching the local username.
For backward compatibility, disabling the check of a local-username-principal is opt-in, as doing the opposite would make existing configurations more open on upgrade.
Resolves #15.