pam_list(7) 맨 페이지 - 윈디하나의 솔라나라

개요

섹션
맨 페이지 이름
검색(S)

pam_list(7)

pa...t(7)Standards, Environments, Macros, Character Sets, and miscellanpya...t(7)

NAME
       pam_list - PAM account management module for UNIX

SYNOPSIS
       pam_list.so.1 [allow=file | deny=file | compat] [debug] [user] [auser]
            [nouser] [group] [host] [nohost] [norole] [role] [user_host_exact]

DESCRIPTION
       The  pam_list  module implements pam_sm_acct_mgmt(3PAM), which provides
       functionality to the PAM account management stack. The module  provides
       functions  to  validate  that  the user's account is valid on this host
       based on a list of users and/or netgroups in the given file. The users,
       groups, and netgroups are separated by newline  character.  Groups  are
       specified  with  a  '%'  character as a prefix. Netgroups are specified
       with a '@' character as a  prefix.  A  line  containing  a  single  '*'
       matches  any user/group/netgroup. A line starting with a '#' is treated
       as a comment. The maximum line length is 1023 characters.


       The username is the value  of  PAM_USER.  The  host  is  the  value  of
       PAM_RHOST  or,  if  PAM_RHOST is not set, the name of the local host as
       returned by gethostname(3C) is used.


       If neither of the allow, deny, or compat  options  are  specified,  the
       module will look for +/- entries in the local /etc/passwd file. If this
       style  is used, nsswitch.conf(5) must not be configured with compat for
       the passwd database. If no relevant +/-  entry  exists  for  the  user,
       pam_list is not participating in the result.


       If compat option is specified then the module will look for +/- entries
       in  the  local  /etc/passwd  file.  Other  entries in this file will be
       counted as + entries. If no relevant entry exits for the user, pam_list
       will deny the access.


       When checking group membership both a users primary group  and  supple‐
       mentary groups are checked against the group name.


       The following options can be passed to the module:

       allow=file         The  full pathname to a file of allowed users and/or
                          netgroups. Only one of allow= or deny= can be speci‐
                          fied.


       compat             Activate compat mode.


       deny=file          The full pathname to a file of denied  users  and/or
                          netgroups. Only one of deny= or allow= can be speci‐
                          fied.


       debug              Provide  syslog(3C)  debugging  information  at  the
                          LOG_AUTH | LOG_DEBUG level.


       user               The module should only perform netgroup  matches  on
                          the username. This is the default option.


       auser              The  value of PAM_AUSER is used instead of PAM_USER.
                          This is useful when used to control access for su(8)
                          when it is desirable that check should apply to  the
                          current  user rather than the target user. Note that
                          initial system login services are unlikely  to  have
                          PAM_AUSER set.


       nouser             The  username  should  not  be  used in the netgroup
                          match.


       group              The allow/deny file contains group names rather than
                          usernames.


       host               Only the host should be used in netgroup matches.


       nohost             The hostname should not be used in netgroup matches.


       norole             Return PAM_IGNORE if the  account  (PAM_USER)  is  a
                          role. This is the default.


       role               Evaluate  the  rules  even if PAM_USER is a role ac‐
                          count.


       user_host_exact    The user and hostname must be in the same netgroup.


RETURN VALUES
       The following values are returned:

       PAM_SERVICE_ERR     An invalid set of module options was  specified  in
                           the  PAM  configuration  (see pam.conf(5)) for this
                           module, or the  user/netgroup  file  could  not  be
                           opened.


       PAM_BUF_ERR         A memory buffer error occurred.


       PAM_IGNORE          The  module  is ignored, as it is not participating
                           in the result.


       PAM_PERM_DENIED     The user is not on the allow list or is on the deny
                           list.


       PAM_SUCCESS         The account is valid for use at this time.


       PAM_USER_UNKNOWN    No account is present for the user


EXAMPLES
       Example 1 Using pam_list in default mode



       The changes to /etc/pam.conf would be:


         other   account requisite       pam_roles.so.1
         other   account required        pam_unix_account.so.1
         other   account required        pam_list.so.1




       The equivalent PAM configuration in /etc/pam.d/ would be the  following
       entries in /etc/pam.d/other:


         account requisite       pam_roles.so.1
         account required        pam_unix_account.so.1
         account required        pam_list.so.1




       In  the  case  of  default  mode or compat mode, the important lines in
       /etc/passwd appear as follows:


         +loginname     - user is approved
         -loginname     - user is disapproved
         +@netgroup     - netgroup members are approved
         -@netgroup     - netgroup members are disapproved


       Example 2 Using pam_list with allow file



       The changes to /etc/pam.conf would be:


         other   account requisite       pam_roles.so.1
         other   account required        pam_unix_account.so.1
         other   account required        pam_list.so.1 allow=/etc/users.allow




       The equivalent PAM configuration in /etc/pam.d/ would be the  following
       entries in /etc/pam.d/other:


         account requisite       pam_roles.so.1
         account required        pam_unix_account.so.1
         account required        pam_list.so.1 allow=/etc/users.allow



       /etc/users.allow contains:

         root
         localloginname
         remoteloginname
         @netgroup


ATTRIBUTES
       See attributes(7) for descriptions of the following attributes:

       tab()  box; cw(2.75i) |cw(2.75i) lw(2.75i) |lw(2.75i) ATTRIBUTE TYPEAT‐
       TRIBUTE VALUE _ Availabilitysystem/library/pam-core _ Interface Stabil‐
       ityCommitted


SEE ALSO
       syslog(3C),    libpam(3LIB),     pam_authenticate(3PAM),     pam(3PAM),
       pam_sm_acct_mgmt(3PAM), nsswitch.conf(5), pam.conf(5), attributes(7)

HISTORY
       The auser option was added in Oracle Solaris 11.4.35.


       Support for using '*' as a wildcard entry, and for '#' to start comment
       lines, was added in Oracle Solaris 11.3.31.


       The  group option, and support for using a '%' prefix to denote groups,
       was added in Oracle Solaris 11.3.24.


       The role and norole options were added in Oracle Solaris 11.0.0.


       The compat option was added in Oracle Solaris 10 9/10 (Update 9).


       The pam_list module was introduced in Solaris 10 8/08 (Update  6),  in‐
       cluding  support  for  the allow, deny, user, nouser, host, nohost, and
       user_host_exact options.

Oracle Solaris 11.4               12 Sep 2023                        pa...t(7)
맨 페이지 내용의 저작권은 맨 페이지 작성자에게 있습니다.
RSS ATOM XHTML 5 CSS3