diff --git a/debian/authforge.config b/debian/authforge.config new file mode 100755 index 0000000..df57bdc --- /dev/null +++ b/debian/authforge.config @@ -0,0 +1,14 @@ +#!/bin/sh +# Asks the admin for an initial policy. Postinst (Task 6) reads the +# answer and writes /etc/authforge/policy.d/00-debconf.conf on first +# install only. Re-runs (e.g. `dpkg-reconfigure authforge`) re-prompt +# but do not overwrite an existing seed file unless the admin chose to. +set -e + +# shellcheck source=/dev/null +. /usr/share/debconf/confmodule + +db_input medium authforge/initial-policy || true +db_go || true + +exit 0 diff --git a/debian/authforge.templates b/debian/authforge.templates new file mode 100644 index 0000000..6c8c1ea --- /dev/null +++ b/debian/authforge.templates @@ -0,0 +1,12 @@ +Template: authforge/initial-policy +Type: select +Default: None +Choices: None, Optional everywhere, Required for sudo +Description: Initial AuthForge policy: + AuthForge can write a starter policy at install time. Choose: + . + None — install only, no MFA enforcement (admins configure later). + Optional everywhere — every PAM stack offers FIDO2/TOTP but doesn't require it. + Required for sudo — sudo prompts for FIDO2 or recovery code in addition to the password. + . + You can change this any time later via the AuthForge GUI or `authforgectl policy set`. diff --git a/debian/control b/debian/control index 305b77d..8eda021 100644 --- a/debian/control +++ b/debian/control @@ -18,6 +18,7 @@ Vcs-Git: https://github.com/dangerousthings/authforge.git Package: authforge Architecture: any +Pre-Depends: debconf (>= 0.5) | debconf-2.0 Depends: authforge-daemon (= ${binary:Version}), authforge-pam (= ${binary:Version}), authforge-cli (= ${binary:Version}),