diff options
author | Daniel Baumann <daniel.baumann@progress-linux.org> | 2024-04-27 12:01:37 +0000 |
---|---|---|
committer | Daniel Baumann <daniel.baumann@progress-linux.org> | 2024-04-27 12:01:37 +0000 |
commit | de848d9e9146434817c65d74d1d0313e9d729462 (patch) | |
tree | dcbd0efb229b17f696f7195671f05b354b4f70fc /modules/pam_sepermit/README | |
parent | Initial commit. (diff) | |
download | pam-de848d9e9146434817c65d74d1d0313e9d729462.tar.xz pam-de848d9e9146434817c65d74d1d0313e9d729462.zip |
Adding upstream version 1.4.0.upstream/1.4.0upstream
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to 'modules/pam_sepermit/README')
-rw-r--r-- | modules/pam_sepermit/README | 48 |
1 files changed, 48 insertions, 0 deletions
diff --git a/modules/pam_sepermit/README b/modules/pam_sepermit/README new file mode 100644 index 0000000..cd697bb --- /dev/null +++ b/modules/pam_sepermit/README @@ -0,0 +1,48 @@ +pam_sepermit — PAM module to allow/deny login depending on SELinux enforcement +state + +━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ + +DESCRIPTION + +The pam_sepermit module allows or denies login depending on SELinux enforcement +state. + +When the user which is logging in matches an entry in the config file he is +allowed access only when the SELinux is in enforcing mode. Otherwise he is +denied access. For users not matching any entry in the config file the +pam_sepermit module returns PAM_IGNORE return value. + +The config file contains a list of user names one per line with optional +arguments. If the name is prefixed with @ character it means that all users in +the group name match. If it is prefixed with a % character the SELinux user is +used to match against the name instead of the account name. Note that when +SELinux is disabled the SELinux user assigned to the account cannot be +determined. This means that such entries are never matched when SELinux is +disabled and pam_sepermit will return PAM_IGNORE. + +See sepermit.conf(5) for details. + +OPTIONS + +debug + + Turns on debugging via syslog(3). + +conf=/path/to/config/file + + Path to alternative config file overriding the default. + +EXAMPLES + +auth [success=done ignore=ignore default=bad] pam_sepermit.so +auth required pam_unix.so +account required pam_unix.so +session required pam_permit.so + + +AUTHOR + +pam_sepermit and this manual page were written by Tomas Mraz +<tmraz@redhat.com>. + |