pam_authtok_get(7) 맨 페이지 - 윈디하나의 솔라나라

개요

섹션
맨 페이지 이름
검색(S)

pam_authtok_get(7)

pa...t(7)Standards, Environments, Macros, Character Sets, and miscellanpya...t(7)

NAME
       pam_authtok_get - authentication and password management module

SYNOPSIS
       pam_authtok_get.so.1 [debug]

DESCRIPTION
       The  pam_authtok_get  service  module provides password prompting func‐
       tionality to the PAM stack. It implements pam_sm_authenticate(3PAM) and
       pam_sm_chauthtok(3PAM), providing functionality to both the Authentica‐
       tion stack and the Password Management stack.

   Authentication Service
       The implementation of pam_sm_authenticate(3PAM) prompts  for  the  user
       name if not set and then tries to get the authentication token from the
       pam  handle.  If  the  token is not set, it then prompts the user for a
       password and stores it in the PAM  item  PAM_AUTHTOK.  This  module  is
       meant to be the first module on an authentication stack where users are
       to authenticate using a keyboard.

   Password Management Service
       Due to the nature of the PAM Password Management stack traversal mecha‐
       nism,  the  pam_sm_chauthtok(3PAM)  function is called twice. Once with
       the PAM_PRELIM_CHECK flag, and once with the PAM_UPDATE_AUTHTOK flag.


       In the first (PRELIM) invocation, the implementation of  pam_sm_chauth‐
       tok(3PAM) moves the contents of the PAM_AUTHTOK (current authentication
       token) to PAM_OLDAUTHTOK, and then prompts the user for a new password.
       This new password is stored in PAM_AUTHTOK.


       If  a previous module has set PAM_OLDAUTHTOK prior to the invocation of
       pam_authtok_get, this module turns into a NO-OP and immediately returns
       PAM_SUCCESS.


       In the second (UPDATE) invocation, the user  is  prompted  to  re-enter
       password.  The pam_sm_chauthtok implementation verifies this re-entered
       password with the password stored  in  PAM_AUTHTOK.  If  the  passwords
       match, the module returns PAM_SUCCESS.


       The following option can be passed to the module:

       debug    syslog(3C) debugging information at the LOG_DEBUG level


RETURN VALUES
       The authentication service returns the following values:

       PAM_SUCCESS       Successfully obtains authentication token


       PAM_SYSTEM_ERR    Fails to retrieve username, username is NULL or empty



       The password management service returns the following values:

       PAM_SUCCESS        Successfully obtains authentication token


       PAM_AUTHTOK_ERR    Authentication token manipulation error


ATTRIBUTES
       See attributes(7) for descriptions of the following attributes:

       tab()  box; cw(2.75i) |cw(2.75i) lw(2.75i) |lw(2.75i) ATTRIBUTE TYPEAT‐
       TRIBUTE VALUE _ Availabilitysystem/library/pam-core _ Interface Stabil‐
       ityCommitted


SEE ALSO
       syslog(3C), libpam(3LIB), pam(3PAM), pam_authenticate(3PAM), pam_sm_au‐
       thenticate(3PAM), pam_sm_chauthtok(3PAM),  pam.conf(5),  attributes(7),
       pam_authtok_check(7),        pam_authtok_store(7),       pam_dhkeys(7),
       pam_passwd_auth(7),       pam_unix_account(7),        pam_unix_auth(7),
       pam_unix_session(7)

HISTORY
       The pam_authtok_get module was introduced in Solaris 9, and later back‐
       ported  to  patches  for Solaris 8. This included support for the debug
       option. Prior to that, this work was performed in the pam_unix module.

Oracle Solaris 11.4               12 Sep 2023                        pa...t(7)
맨 페이지 내용의 저작권은 맨 페이지 작성자에게 있습니다.
RSS ATOM XHTML 5 CSS3