Skip Navigation Links | |
Exit Print View | |
man pages section 5: Standards, Environments, and Macros Oracle Solaris 11.1 Information Library |
- PAM authentication, account, session and password management PAM module to deny operations
pam_deny.so.1
The pam_deny module implements all the PAM service module functions and returns the module type default failure return code for all calls.
The following options are interpreted:
syslog(3C) debugging information at the LOG_AUTH|LOG_DEBUG levels
The following error codes are returned:
If pam_sm_acct_mgmt is called.
If pam_sm_authenticate is called.
If pam_sm_chauthtok is called.
If pam_sm_setcred is called.
If pam_sm_open_session or pam_sm_close_session is called.
Example 1 Disallowing ssh none authentication
The following example is a pam.conf fragment that illustrates how to deny the SSHv2 userauth of “none”:
sshd-none auth requisite pam_deny.so.1 sshd-none account requisite pam_deny.so.1 sshd-none session requisite pam_deny.so.1 sshd-none password requisite pam_deny.so.1
The equivalent configuration in /etc/pam.d/ would be the following entries in /etc/pam.d/sshd-none:
auth requisite pam_deny.so.1 account requisite pam_deny.so.1 session requisite pam_deny.so.1 password requisite pam_deny.so.1
Example 2 Disallowing any service not explicitly defined
The following example is a pam.conf fragment that illustrates how to deny any PAM service which is not explicitly defined in the PAM configuration:
other auth requisite pam_deny.so.1 other account requisite pam_deny.so.1 other session requisite pam_deny.so.1 other password requisite pam_deny.so.1
The equivalent configuration in /etc/pam.d/ would be the following entries in /etc/pam.d/other:
auth requisite pam_deny.so.1 account requisite pam_deny.so.1 session requisite pam_deny.so.1 password requisite pam_deny.so.1
See attributes(5) for a description of the following attributes:
|
su(1M), libpam(3LIB), pam(3PAM), pam_sm_authenticate(3PAM), syslog(3C), pam.conf(4), nsswitch.conf(4), attributes(5), pam_authtok_check(5), pam_authtok_get(5), pam_authtok_store(5), pam_dhkeys(5), pam_passwd_auth(5), pam_unix_account(5), pam_unix_auth(5), pam_unix_session(5), privileges(5)
The interfaces in libpam(3LIB) are MT-Safe only if each thread within the multi-threaded application uses its own PAM handle.
The pam_deny module is intended to deny access to a specified service. The other service name may be used to deny access to services not explicitly specified.