[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [leafnode-list] PAM Support does not work!!!

Jim Gifford schrieb am 2004-03-28:

> I am using a shadow passwd file.

That's what I thought. :-/

Security issues aside (make sure you don't authenticate outside your
LAN, NNTP passwords are sent in clear), I have double checked the PAM
code and seen no bugs, Hynek's code was and is in good shape AFAICS.

PAM is supposed to use a set-group-id helper program, /sbin/unix2_chkpwd
on my machine, to check the data against /etc/shadow. For some reason,
it doesn't try that but insists on reading /etc/shadow directly, which
must fail because it has not the proper privileges to do so.

If anyone knows the magic dance to perform at moonlight so that PAM uses
the setgid helper, please let me know. URL/pointer suffices.

Matthias Andree

Encrypt your mail: my GnuPG key ID is 0x052E7D95
leafnode-list mailing list