pam issues - was Re: [OpenAFS] Is OpenAFS appropriate?

Stephen Bosch posting@vodacomm.ca
Wed, 21 Jan 2004 12:03:48 -0700


Derrick J Brashear wrote:
> So what's in /etc/pam.d/system-auth?

Oops. I think I've just exposed my general ignorance of how pam works.

sfbosch@wopr users $ cat /etc/pam.d/system-auth
#%PAM-1.0

auth       required     /lib/security/pam_env.so
auth       sufficient   /lib/security/pam_unix.so likeauth nullok
auth       required     /lib/security/pam_deny.so

account    required     /lib/security/pam_unix.so

password   required     /lib/security/pam_cracklib.so retry=3
password   sufficient   /lib/security/pam_unix.so nullok md5 shadow 
use_authtok
password   required     /lib/security/pam_deny.so

session    required     /lib/security/pam_limits.so
session    required     /lib/security/pam_unix.so
sfbosch@wopr users $

I have to have a line for pam_afs.so in here, too -- is that it?

-Stephen-