source: postlfs/security/linux-pam.xml@ f22f1ef3

10.0 10.1 11.0 11.1 11.2 11.3 12.0 12.1 7.10 7.5 7.6 7.6-blfs 7.6-systemd 7.7 7.8 7.9 8.0 8.1 8.2 8.3 8.4 9.0 9.1 basic bdubbs/svn elogind gnome kde5-13430 kde5-14269 kde5-14686 kea ken/TL2024 ken/inkscape-core-mods ken/tuningfonts krejzi/svn lazarus lxqt nosym perl-modules plabs/newcss plabs/python-mods python3.11 qt5new rahul/power-profiles-daemon renodr/vulkan-addition systemd-11177 systemd-13485 trunk upgradedb xry111/intltool xry111/llvm18 xry111/soup3 xry111/test-20220226 xry111/xf86-video-removal
Last change on this file since f22f1ef3 was f22f1ef3, checked in by Igor Živković <igor@…>, 10 years ago

applied Denis Mugnier's patch updating some incorrect URLs.

git-svn-id: svn://svn.linuxfromscratch.org/BLFS/trunk/BOOK@12370 af4574ff-66df-0310-9fd7-8a98e5e911e0

  • Property mode set to 100644
File size: 11.6 KB
Line 
1<?xml version="1.0" encoding="ISO-8859-1"?>
2<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4 <!ENTITY % general-entities SYSTEM "../../general.ent">
5 %general-entities;
6
7 <!ENTITY linux-pam-download-http "http://linux-pam.org/library/Linux-PAM-&linux-pam-version;.tar.bz2">
8 <!ENTITY linux-pam-download-ftp " ">
9 <!ENTITY linux-pam-md5sum "35b6091af95981b1b2cd60d813b5e4ee">
10 <!ENTITY linux-pam-size "1.1 MB">
11 <!ENTITY linux-pam-buildsize "22 MB">
12 <!ENTITY linux-pam-time "0.3 SBU">
13
14 <!ENTITY linux-pam-docs-download "http://linux-pam.org/documentation/Linux-PAM-&linux-pam-version;-docs.tar.bz2">
15 <!ENTITY linux-pam-docs-md5sum "730895d1c6e1c706dc5ffe2419f9b3f5">
16 <!ENTITY linux-pam-docs-size "148 KB">
17 <!ENTITY debian-pam-docs "http://debian.securedservers.com/kernel/pub/linux/libs/pam">
18]>
19
20<sect1 id="linux-pam" xreflabel="Linux-PAM-&linux-pam-version;">
21 <?dbhtml filename="linux-pam.html"?>
22
23 <sect1info>
24 <othername>$LastChangedBy$</othername>
25 <date>$Date$</date>
26 </sect1info>
27
28 <title>Linux-PAM-&linux-pam-version;</title>
29
30 <indexterm zone="linux-pam">
31 <primary sortas="a-Linux-PAM">Linux-PAM</primary>
32 </indexterm>
33
34 <sect2 role="package">
35 <title>Introduction to Linux PAM</title>
36
37 <para>
38 The <application>Linux PAM</application> package contains
39 Pluggable Authentication Modules used to enable the local
40 system administrator to choose how applications authenticate
41 users.
42 </para>
43
44 &lfs74_checked;
45
46 <bridgehead renderas="sect3">Package Information</bridgehead>
47 <itemizedlist spacing="compact">
48 <listitem>
49 <para>
50 Download (HTTP): <ulink url="&linux-pam-download-http;"/>
51 </para>
52 </listitem>
53 <listitem>
54 <para>
55 Download (FTP): <ulink url="&linux-pam-download-ftp;"/>
56 </para>
57 </listitem>
58 <listitem>
59 <para>
60 Download MD5 sum: &linux-pam-md5sum;
61 </para>
62 </listitem>
63 <listitem>
64 <para>
65 Download size: &linux-pam-size;
66 </para>
67 </listitem>
68 <listitem>
69 <para>
70 Estimated disk space required: &linux-pam-buildsize;
71 </para>
72 </listitem>
73 <listitem>
74 <para>
75 Estimated build time: &linux-pam-time;
76 </para>
77 </listitem>
78 </itemizedlist>
79
80 <bridgehead renderas="sect3">Additional Downloads</bridgehead>
81 <itemizedlist spacing="compact">
82 <title>Optional Documentation</title>
83 <listitem>
84 <para>
85 Download (HTTP): <ulink url="&linux-pam-docs-download;"/>
86 </para>
87 </listitem>
88 <listitem>
89 <para>
90 Download MD5 sum: &linux-pam-docs-md5sum;
91 </para>
92 </listitem>
93 <listitem>
94 <para>
95 Download size &linux-pam-docs-size;
96 </para>
97 </listitem>
98 </itemizedlist>
99
100 <bridgehead renderas="sect3">Linux PAM Dependencies</bridgehead>
101
102 <bridgehead renderas="sect4">Optional</bridgehead>
103 <para role="optional">
104 <xref linkend="db"/>,
105 <xref linkend="cracklib"/>,
106 <xref linkend="libtirpc"/> and
107 <ulink url="http://www.prelude-ids.org/">Prelude</ulink>
108 </para>
109
110 <bridgehead renderas="sect4">Optional (To Rebuild the Documentation)</bridgehead>
111 <para role="optional">
112 <xref linkend="DocBook"/>,
113 <xref linkend="docbook-xsl"/>,
114 <xref linkend="fop"/>,
115 <xref linkend="libxslt"/> and
116 <xref linkend="w3m"/>
117 </para>
118
119 <para condition="html" role="usernotes">User Notes:
120 <ulink url="&blfs-wiki;/linux-pam"/>
121 </para>
122 </sect2>
123
124 <sect2 role="installation">
125 <title>Installation of Linux PAM</title>
126
127 <para>
128 If you downloaded the documentation, unpack the tarball by issuing
129 the following command.
130 </para>
131
132<screen><userinput>tar -xf ../Linux-PAM-&linux-pam-version;-docs.tar.bz2 --strip-components=1</userinput></screen>
133
134 <para>
135 Install <application>Linux PAM</application> by
136 running the following commands:
137 </para>
138
139<screen><userinput>./configure --prefix=/usr \
140 --sysconfdir=/etc \
141 --docdir=/usr/share/doc/Linux-PAM-&linux-pam-version; \
142 --disable-nis &amp;&amp;
143make</userinput></screen>
144
145 <para>
146 To test the results, a configuration file must be created. This file
147 will be removed after the tests have completed. Ensure there are no errors
148 produced by the tests before continuing the installation. First create the
149 configuration file by issuing the following commands as the
150 <systemitem class="username">root</systemitem> user:
151 </para>
152
153<screen role="root"><userinput>install -v -m755 -d /etc/pam.d &amp;&amp;
154
155cat &gt; /etc/pam.d/other &lt;&lt; "EOF"
156auth required pam_deny.so
157account required pam_deny.so
158password required pam_deny.so
159session required pam_deny.so
160EOF</userinput></screen>
161
162 <para>
163 Now run the tests by issuing <command>make check</command>.
164 </para>
165
166 <para>
167 Remove the configuration file created earlier by issuing the
168 following command as the
169 <systemitem class="username">root</systemitem> user:
170 </para>
171
172<screen role="root"><userinput>rm -rfv /etc/pam.d</userinput></screen>
173
174 <para>
175 Now, as the <systemitem class="username">root</systemitem>
176 user:
177 </para>
178
179<screen role="root"><userinput>make install &amp;&amp;
180chmod -v 4755 /sbin/unix_chkpwd</userinput></screen>
181 </sect2>
182
183 <sect2 role="commands">
184 <title>Command Explanations</title>
185
186 <para>
187 <option>--disable-nis</option>: This switch disables building
188 of the Network Information Service/Yellow Pages support in
189 pam_unix and pam_access modules. Remove it if you have installed
190 <xref linkend="libtirpc"/>.
191 </para>
192
193 <para>
194 <command>chmod -v 4755 /sbin/unix_chkpwd</command>:
195 The <command>unix_chkpwd</command> helper program must be setuid
196 so that non-<systemitem class="username">root</systemitem>
197 processes can access the shadow file.
198 </para>
199
200 </sect2>
201
202 <sect2 role="configuration">
203 <title>Configuring Linux-PAM</title>
204
205 <sect3 id="pam-config">
206 <title>Config Files</title>
207
208 <para>
209 <filename>/etc/security/*</filename> and
210 <filename>/etc/pam.d/*</filename>
211 </para>
212
213 <indexterm zone="linux-pam pam-config">
214 <primary sortas="e-etc-security">/etc/security/*</primary>
215 </indexterm>
216
217 <indexterm zone="linux-pam pam-config">
218 <primary sortas="e-etc-pam.d">/etc/pam.d/*</primary>
219 </indexterm>
220
221 </sect3>
222
223 <sect3>
224 <title>Configuration Information</title>
225
226 <para>
227 Configuration information is placed in
228 <filename class="directory">/etc/pam.d/</filename>.
229 Below is an example file:
230 </para>
231
232<screen><literal># Begin /etc/pam.d/other
233
234auth required pam_unix.so nullok
235account required pam_unix.so
236session required pam_unix.so
237password required pam_unix.so nullok
238
239# End /etc/pam.d/other</literal></screen>
240
241 <para>
242 The <application>PAM</application> man page (<command>man
243 pam</command>) provides a good starting point for descriptions
244 of fields and allowable entries. The <ulink
245 url="http://www.linux-pam.org/Linux-PAM-html/Linux-PAM_SAG.html">Linux-PAM
246 System Administrators' Guide</ulink> is recommended for additional
247 information.
248 </para>
249
250 <para>
251 Refer to <ulink url="&debian-pam-docs;/modules.html"/> for a list
252 of various third-party modules available.
253 </para>
254
255 <important>
256 <para>
257 You should now reinstall the <xref linkend="shadow"/>
258 package.
259 </para>
260 </important>
261
262 </sect3>
263
264 </sect2>
265
266 <sect2 role="content">
267 <title>Contents</title>
268
269 <segmentedlist>
270 <segtitle>Installed Program</segtitle>
271 <segtitle>Installed Libraries</segtitle>
272 <segtitle>Installed Directories</segtitle>
273
274 <seglistitem>
275 <seg>
276 mkhomedir_helper, pam_tally, pam_tally2,
277 pam_timestamp_check, unix_chkpwd and
278 unix_update
279 </seg>
280 <seg>
281 libpam.so, libpamc.so and libpam_misc.so
282 </seg>
283 <seg>
284 /etc/security,
285 /lib/security,
286 /usr/include/security and
287 /usr/share/doc/Linux-PAM-&linux-pam-version;
288 </seg>
289 </seglistitem>
290 </segmentedlist>
291
292 <variablelist>
293 <bridgehead renderas="sect3">Short Descriptions</bridgehead>
294 <?dbfo list-presentation="list"?>
295 <?dbhtml list-presentation="table"?>
296
297 <varlistentry id="mkhomedir_helper">
298 <term><command>mkhomedir_helper</command></term>
299 <listitem>
300 <para>
301 is a helper binary that creates home directories.
302 </para>
303 <indexterm zone="linux-pam mkhomedir_helper">
304 <primary sortas="b-mkhomedir_helper">mkhomedir_helper</primary>
305 </indexterm>
306 </listitem>
307 </varlistentry>
308
309 <varlistentry id="pam_tally">
310 <term><command>pam_tally</command></term>
311 <listitem>
312 <para>
313 is used to interrogate and manipulate the login counter file.
314 </para>
315 <indexterm zone="linux-pam pam_tally">
316 <primary sortas="b-pam_tally">pam_tally</primary>
317 </indexterm>
318 </listitem>
319 </varlistentry>
320
321 <varlistentry id="pam_tally2">
322 <term><command>pam_tally2</command></term>
323 <listitem>
324 <para>
325 is used to interrogate and manipulate the login counter file, but
326 does not have some limitations that <command>pam_tally</command>
327 does.
328 </para>
329 <indexterm zone="linux-pam pam_tally2">
330 <primary sortas="b-pam_tally2">pam_tally2</primary>
331 </indexterm>
332 </listitem>
333 </varlistentry>
334
335 <varlistentry id="pam_timestamp_check">
336 <term><command>pam_timestamp_check</command></term>
337 <listitem>
338 <para>
339 is used to check if the default timestamp is valid
340 </para>
341 <indexterm zone="linux-pam pam_timestamp_check">
342 <primary sortas="b-pam_timestamp_check">pam_timestamp_check</primary>
343 </indexterm>
344 </listitem>
345 </varlistentry>
346
347 <varlistentry id="unix_chkpwd">
348 <term><command>unix_chkpwd</command></term>
349 <listitem>
350 <para>
351 is a helper binary that verifies the password of the current user.
352 </para>
353 <indexterm zone="linux-pam unix_chkpwd">
354 <primary sortas="b-unix_chkpwd">unix_chkpwd</primary>
355 </indexterm>
356 </listitem>
357 </varlistentry>
358
359 <varlistentry id="unix_update">
360 <term><command>unix_update</command></term>
361 <listitem>
362 <para>
363 is a helper binary that updates the password of a given user.
364 </para>
365 <indexterm zone="linux-pam unix_update">
366 <primary sortas="b-unix_update">unix_update</primary>
367 </indexterm>
368 </listitem>
369 </varlistentry>
370
371 <varlistentry id="libpam">
372 <term><filename class="libraryfile">libpam.so</filename></term>
373 <listitem>
374 <para>
375 provides the interfaces between applications and the
376 PAM modules.
377 </para>
378 <indexterm zone="linux-pam libpam">
379 <primary sortas="c-libpam">libpam.so</primary>
380 </indexterm>
381 </listitem>
382 </varlistentry>
383
384 </variablelist>
385
386 </sect2>
387
388</sect1>
Note: See TracBrowser for help on using the repository browser.