| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
| |
Notes:
svn path=/head/; revision=91884
|
| |
|
|
| |
Notes:
svn path=/head/; revision=90146
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Chain caching is a feature of Linux-PAM, where pam_authenticate() and
pam_open_session() "freeze" the chain so that their companion
primitive (pam_setcred() and pam_close_session() respectively) will
call the exact same modules, skipping those that failed in the
previous call.
There are several reasons not to do this, the most prominent of which
is that it makes it impossible to call pam_setcred() without first
calling pam_authenticate() - which is perfectly valid according to
DCE/RFC 86.0 and XSSO, and is necessary to make 'login -f' work.
Instead of chain caching, implement something similar to the way
Solaris' libpam behaves: pam_setcred treats "sufficient" modules as if
they were "required", i.e. does not break the chain when they succeed.
PAM modules whose pam_sm_setcred() should not be called unless their
pam_sm_authenticate() succeeded can simply set a state variable using
pam_set_data() in pam_sm_authenticate(), and use pam_get_data() to
check it in pam_sm_setcred().
Sponsored by: DARPA, NAI Labs
Notes:
svn path=/head/; revision=89738
|
| |
|
|
|
|
|
| |
OK'ed by: des
Notes:
svn path=/head/; revision=89587
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
problem, it still didn't DTRT for services that did not have a service-
specific policy if /etc/pam.d existed but did not contain an "other"
policy. This fixes the problems some people have experienced with sudo.
And I almost didn't have to use goto.
The current configuration sequence is:
1) Look for /etc/pam.d/foo
2) If PAM_READ_BOTH_CONFS is defined, or step 1) failed, look for
foo in /etc/pam.conf
3) Look for /etc/pam.d/other (to fill in the gaps)
4) If PAM_READ_BOTH_CONFS is defined, or step 3) failed, look for
other in /etc/pam.conf
I believe this is the intended behaviour of the original code. The least
surprising behaviour seems to be when PAM_READ_BOTH_CONFS is not defined -
/etc/pam.d/foo will be preferred over /etc/pam.conf, but the latter will
serve as a backup if the former does not exist.
Sponsored by: DARPA, NAI Labs
Notes:
svn path=/head/; revision=87469
|
| |
|
|
|
|
|
| |
Sponsored by: DARPA, NAI Labs
Notes:
svn path=/head/; revision=87407
|
| |
|
|
|
|
|
|
|
| |
function prototypes (or, in a few cases, removing argument names altogether).
Sponsored by: DARPA, NAI Labs
Notes:
svn path=/head/; revision=87405
|
| |
|
|
|
|
|
| |
Sponsored by: DARPA, NAI Labs
Notes:
svn path=/head/; revision=87401
|
| |
|
|
|
|
|
| |
Reported by: bde
Notes:
svn path=/head/; revision=87175
|
| |
|
|
|
|
|
|
|
|
|
| |
RTLD_NOW got incorrectly defined to 1 (which is RTLD_LAZY in FreeBSD).
In addition, the comment about FreeBSD requiring SHLIB_SYM_PREFIX to
be "_" is incorrect.
Submitted by: tobez (except for the bit about the incorrect comment)
Notes:
svn path=/head/; revision=86981
|
| |
|
|
|
|
|
| |
PAM_BUF_ERR is much closer to the truth.
Notes:
svn path=/head/; revision=86980
|
| |
|
|
|
|
|
| |
rid of gensetdefs from here as well.
Notes:
svn path=/head/; revision=78194
|
| |
|
|
|
|
|
|
|
|
| |
SIGINTR (^C) and SIGSTP (^Z) masked.
Reported by: bde, sobomax
Submitted by: sobomax
Notes:
svn path=/head/; revision=77867
|
| |
|
|
|
|
|
| |
actually reading the line.
Notes:
svn path=/head/; revision=77725
|
| |
|
|
| |
Notes:
svn path=/head/; revision=77723
|
| |
|
|
| |
Notes:
svn path=/head/; revision=77411
|
| |
|
|
|
|
|
|
|
|
|
| |
> Script started on Sat May 12 22:18:47 2001
> ttyp1:bde@gamplex:/usr/src/libexec/rshd> rsh localhost ls
> rcmd: localhost: Undefined error: 0
Reported by: bde
Notes:
svn path=/head/; revision=76677
|
| |
|
|
| |
Notes:
svn path=/head/; revision=76467
|
| |
|
|
| |
Notes:
svn path=/head/; revision=76241
|
| |\
| |
| |
| |
| |
| |
| | |
which included commits to RCS files with non-trunk default branches.
Notes:
svn path=/head/; revision=76239
|
| | |
| |
| |
| | |
Notes:
svn path=/vendor/libpam/dist/; revision=76238
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
simple enough to be trusted.
Add account management functionality to the pam_unix module.
These changes should make it possible to use PAM in some ports.
Submitted by: Max Khon <fjoe@iclub.nsu.ru>
Notes:
svn path=/head/; revision=46665
|
| | |
| |
| |
| | |
Notes:
svn path=/head/; revision=42917
|
| | |
| |
| |
| |
| |
| |
| |
| | |
still get them with "cvs upd -r pam_unpruned" if you want to look at
them.
Notes:
svn path=/head/; revision=41336
|
| | |
| |
| |
| |
| |
| |
| |
| | |
We don't use this module, but still I don't want to leave this call
in the code.
Notes:
svn path=/head/; revision=41226
|
| | |
| |
| |
| | |
Notes:
svn path=/head/; revision=41225
|
| | |
| |
| |
| |
| |
| |
| | |
takes care of that.
Notes:
svn path=/head/; revision=41224
|
| | |
| |
| |
| | |
Notes:
svn path=/head/; revision=41223
|
| |\|
| |
| |
| |
| |
| |
| | |
which included commits to RCS files with non-trunk default branches.
Notes:
svn path=/head/; revision=41221
|
| |
|
|
|
| |
Notes:
svn path=/vendor/libpam/dist/; revision=41220
svn path=/vendor/libpam/0.65/; revision=41222; tag=vendor/libpam/0.65
|
|
|
Notes:
svn path=/head/; revision=41219
|