13 lines
559 B
Plaintext
13 lines
559 B
Plaintext
Template: authforge/initial-policy
|
|
Type: select
|
|
Default: None
|
|
Choices: None, Optional everywhere, Required for sudo
|
|
Description: Initial AuthForge policy:
|
|
AuthForge can write a starter policy at install time. Choose:
|
|
.
|
|
None — install only, no MFA enforcement (admins configure later).
|
|
Optional everywhere — every PAM stack offers FIDO2/TOTP but doesn't require it.
|
|
Required for sudo — sudo prompts for FIDO2 or recovery code in addition to the password.
|
|
.
|
|
You can change this any time later via the AuthForge GUI or `authforgectl policy set`.
|