pam_chauthtok(3)

pam_chauthtok - perform passord related functions within the PAM framework

As shipped in IRIX 6.5.22. Added in IRIX 6.5.19.

NAME
     pam_chauthtok - perform passord related functions within the PAM framework

SYNOPSIS
     cc [ flag ... ] file ...  -lpam [ library ... ]

     #include <security/pam_appl.h>

     int pam_chauthtok(pam_handle_t *pamh, const int flags);


DESCRIPTION
     pam_chauthtok()  is  called  to  change the authentication token associated
     with a particular user referenced by the authentication handle, pamh.

     The following flag may be passed in to pam_chauthtok():

            PAM_SILENT                    The password service should not gener-
                                          ate any messages

            PAM_CHANGE_EXPIRED_AUTHTOK    The password service should  only  up-
                                          date  those  passwords that have aged.
                                          If this flag is not passed, all  pass-
                                          word   services  should  update  their
                                          passwords.


NOTES
     The flag PAM_CHANGE_EXPIRED_AUTHTOK is typically used by a  login  applica-
     tion  which  has  determined  that the user's password has aged or expired.
     Before allowing the  user  to  login,  the  login  application  may  invoke
     pam_chauthtok()  with  this  flag to allow the user to update the password.
     Typically applications such as passwd(1) should not use this flag.

     Upon successful completion of the call, the  authentication  token  of  the
     user  will be changed in accordance with the password service configured in
     the system through pam.conf(4).

RETURN VALUES
     Upon successful completion, PAM_SUCCESS is returned.  In  addition  to  the
     error  return  values  described in pam(3), the following values may be re-
     turned:

            PAM_PERM_DENIED                   No permission

            PAM_AUTHTOK_ERR                   Authentication token  manipulation
                                              error

            PAM_AUTHTOK_RECOVERY_ERR          Old authentication token cannot be
                                              recovered

            PAM_AUTHTOK_LOCK_BUSY             Authentication token lock busy

            PAM_AUTHTOK_DISABLE_AGING         Authentication  token  aging  dis-
                                              abled

            PAM_USER_UNKNOWN                  User unknown to password service

            PAM_TRY_AGAIN                     Preliminary check by password ser-
                                              vice failed

SEE ALSO
     pam(3), pam_start(3), pam_authenticate(3)