pam_unix(5)
pam_unix - authentication, account, session, and password management PAM modules for UNIX
Showing IRIX 6.5.30 (default release). Added in IRIX 6.5.19.
NAME pam_unix - authentication, account, session, and password management PAM modules for UNIX SYNOPSIS /usr/lib/security/pam_unix.so DESCRIPTION The UNIX service module for PAM, /usr/lib/security/pam_unix.so, provides functionality for all four PAM modules: The authentication module, the ac- count management module, the session management module, and the password management module. The pam_unix.so module is a shared object that can be dynamically loaded to provide the necessary functionality upon demand. Its path is specified in the PAM configuration file. Unix Authentication Module The UNIX authentication component provides functions to verify the identity of a user, (pam_sm_authenticate()) and to set user specific credentials (pam_sm_setcred()). pam_sm_authenticate() compares the user entered pass- word with the password from UNIX password database. If the passwords match, the user is authenticated. The following options may be passed to the UNIX service module: debug syslog(3) debugging information at LOG_DEBUG level nowarn turn off warning messages use_first_pass It compares the password in the password database with the user's initial password (entered when the user authenticated to the first authentication module in the stack). If the passwords do not match, or if no password has been entered, quit and do not prompt the user for a password. This option should only be used if the authentication service is designated as optional in the pam.conf configuration file. try_first_pass It compares the password in the password database with the user's initial password (entered when the user authenticated to the first authentication module in the stack). If the passwords do not match, or if no password has been entered, prompt the user for a password. The pam_sm_setcred() function sets user specific credentials. For UNIX, this is a NULL function. Unix Account Management Module The UNIX account management component provides a function to perform ac- count management (pam_sm_acct_mgmt()). The pam_sm_acct_mgmt() function re- trieves the user's password entry from the UNIX password database and veri- fies that the user's account and password have not expired. The following option may be passed in to the UNIX service module: debug syslog(3) debugging information at LOG_DEBUG level nowarn turn off warning messages Unix Session Management Module The UNIX session management component provides functions to initiate (pam_sm_open_session()) and terminate (pam_sm_close_session()) UNIX ses- sions. Currently for UNIX, these functions are empty. The following op- tion may be passed in to the UNIX service module: debug syslog(3) debugging information at LOG_DEBUG level nowarn turn off warning messages Unix Password Management Module The UNIX password management component provides a function to change pass- words (pam_sm_chauthtok()) in the UNIX password database. This module must be required in pam.conf. It can not be optional or suffi- cient. The following option may be passed in to the UNIX service module: debug syslog(3) debugging information at LOG_DEBUG level nowarn turn off warning messages use_first_pass It compares the password in the password database with the user's old password (entered to the first password module in the stack). If the passwords do not match, or if no password has been entered, quit and do not prompt the user for the old password. It also attempts to use the new password (entered to the first password module in the stack) as the new pass- word for this module. If the new password fails, quit and do not prompt the user for a new password. try_first_pass It compares the password in the password database with the user's old password (entered to the first password module in the stack). If the passwords do not match, or if no password has been entered, prompt the user for the old password. It also attempts to use the new password (entered to the first password module in the stack) as the new password for this module. If the new password fails, prompt the user for a new password. SEE ALSO pam(3), pam_authenticate(3), pam_setcred(3), syslog(3), pam.conf(4)