ubuntu:pam_pluggable_authentication_module

This is an old revision of the document!


PAM (Pluggable authentication module)

PAM is a suite of shared libraries that enable the local system administrator to choose how applications authenticate users.

In other words, without (rewriting and) recompiling a PAM-aware application, it is possible to switch between the authentication mechanism(s) it uses. One may entirely upgrade the local authentication system without touching the applications themselves.

This PAM library is configured locally with a system file, /etc/pam.conf (or a series of configuration files located in /etc/pam.d/) to authenticate a user request via the locally available authentication modules.

The modules themselves will usually be located in the directory /lib/security or /lib64/security and take the form of dynamically loadable object files. See dlopen(3)).

PAM deals with four separate types of (management) task:

  • authentication management
  • account management
  • session management
  • password management

These are handled in the relevant Linux-PAM configuration file.

The actual management functions are performed by modules specified in the configuration file.


pam_passwdqc

ubuntu/pam_pluggable_authentication_module.1575203132.txt.gz · Last modified: 2020/07/15 09:30 (external edit)

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki