ºìÁªLinuxÃÅ»§
Linux°ïÖú

RHEL5 ²åÈëÈÏ֤ģ¿é(PAM)Ïê½â

·¢²¼Ê±¼ä:2008-02-08 00:02:21À´Ô´:ºìÁª×÷Õß:Commands
»ùÓÚPluggable Authentication Modules(¿É²åÈëÑé֤ģ¿é£¬¼ò³ÆPAM)µÄÑéÖ¤»úÖÆ£¬¿ÉÒÔÏµÍ³ÌØ¶¨Ó¦ÓóÌÐòµÄʹÓÃÏÞÖÆÓÚrootÕË»§¡£²»Í¬µÄModule¿ÉÒÔʵÏÖϵͳ¹ÜÀíÔ±°´ÕÕÓû§¡¢ÃÜÂë»òÕßµÇÈëλÖÃÉèÖ÷ÃÎÊ¿ØÖƲßÂÔ¡£

PAM ËùÓеÄÈÏÖ¤º¯Êý¿â´æ·ÅÓÚ/lib/security/pam_*.so£¬²¢ÓÉ/etc/pam.d/Ŀ¼Ï¶ÔÓ¦µÄÎļþ½øÐе÷Óá£ÔÚÑéÖ¤ÇëÇóʱ£¬Ó¦ÓóÌÐòͨ¹ýlibpamº¯Êý¿âÀ´Ìṩ·þÎñ¡£¾ßÌåʹÓÃÄÄЩPAMº¯Êý¿â½øÐÐÑéÖ¤£¬ÔòÓÉ/etc/pam.d/Ŀ¼Ï¶ÔÓ¦µÄÉèÖÃÎļþ¾ö¶¨¡£libpam Ìṩº¯Êý¹²Ïí·þÎñ£¬¶øÇÒ¿ÉÒÔ¶¯Ì¬ÔØÈë¡£

1 PAM¹¤×÷»úÖÆ

/lib/security Ŀ¼ÏµÄÿһ¸öÈÏ֤ģ¿é¶¼»á·µ»Øpass»òÕßfail½á¹û£¬²¿·Ö³ÌÐòʹÓÃ/etc/securityĿ¼ÏµÄÉèÖÃÎļþ¾ö¶¨ÈÏÖ¤·½Ê½¡£Ó¦ÓóÌÐòµ÷ÓÃPAMÄ£¿éÈÏÖ¤µÄÅäÖ㬴æ·ÅÓÚ/etc/pam.d£¬ÎļþÃûÓëÓ¦ÓóÌÐòÃû¶ÔÓ¦£¬ÎļþÖеÄÿһÐж¼»á·µ»ØÒ»¸ö³ÉÑéÖ¤¹¦»¹ÊÇʧ°ÜµÄ¿ØÖƱêÖ¾£¬ÒÔ¾ö¶¨Óû§ÊÇ·ñÓµÓзÃÎÊȨÏÞ¡£

2 PAMÑéÖ¤ÀàÐÍ

* auth Ñé֤ʹÓÃÕßÉí·Ý£¬ÌáʾÊäÈëÕ˺źÍÃÜÂë
* account »ùÓÚÓû§±í¡¢Ê±¼ä»òÕßÃÜÂëÓÐЧÆÚÀ´¾ö¶¨ÊÇ·ñÔÊÐí·ÃÎÊ
* password ½ûÖ¹Óû§·´¸´³¢ÊԵǼ£¬ÔÚ±ä¸üÃÜÂëʱ½øÐÐÃÜÂ븴ÔÓÐÔ¿ØÖÆ
* session ½øÐÐÈÕÖ¾¼Ç¼£¬»òÕßÏÞÖÆÓû§µÇ¼µÄ´ÎÊý

libpamº¯Êý¿â»á¿ÉÒÔµ÷ÓÃÒÔÉÏÒ»ÖÖ·þÎñ»òÕßÈ«²¿¡£

3 PAMÑéÖ¤¿ØÖÆÀàÐÍ(Control Values)

ÑéÖ¤¿ØÖÆÀàÐÍÒ²¿ÉÒÔ³Æ×öControl Flags£¬ÓÃÓÚPAMÑéÖ¤ÀàÐ͵ķµ»Ø½á¹û¡£

* required Ñé֤ʧ°ÜʱÈÔÈ»¼ÌÐø£¬µ«·µ»ØFail(Óû§²»»áÖªµÀÄÄÀïʧ°Ü)
* requisite Ñé֤ʧ°ÜÔòÁ¢¼´½áÊøÕû¸öÑéÖ¤¹ý³Ì£¬·µ»ØFail
* sufficient ÑéÖ¤³É¹¦ÔòÁ¢¼´·µ»Ø£¬²»ÔÙ¼ÌÐø£¬·ñÔòºöÂÔ½á¹û²¢¼ÌÐø
* optional ÎÞÂÛÑéÖ¤½á¹ûÈçºÎ£¬¾ù²»»áÓ°Ïì(ͨ³£ÓÃÓÚsessionÀàÐÍ)

ÑéÖ¤½á¹û¶ÔÕÕ±í
©°©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©´
©¦ ©¦Result©¦Keep testing?©¦ Affect ©¦
©À©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©È
©¦ ©¦Pass ©¦ Y ©¦Define by system©¦
©¦Required ©¦Fail ©¦ Y ©¦Fail ©¦
©À©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©È
©¦Requisite ©¦Pass ©¦ Y ©¦Define by system©¦
©¦ ©¦Fail ©¦ N ©¦Fail ©¦
©À©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©È
©¦Sufficient©¦Pass ©¦ N ©¦Define by system©¦
©¦ ©¦Fail ©¦ Y ©¦Ignore ©¦
©¸©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¼

Ñé֤ʾÀý1
©°©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©´
©¦ ©¦ ©¦ ©¦user1©¦user2©¦user3©¦
©À©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©È
©¦Auth ©¦Required©¦Module1©¦Pass ©¦Fail ©¦Pass ©¦
©À©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©È
©¦Auth ©¦Required©¦Module2©¦Pass ©¦Pass ©¦Fail ©¦
©À©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©È
©¦Auth ©¦Required©¦Module3©¦Pass ©¦Pass ©¦Fail ©¦
©À©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©È
©¦ Result ©¦Pass ©¦Fail ©¦Fail ©¦
©¸©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¼

Ñé֤ʾÀý2
©°©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©Ð©¤©¤©¤©¤©¤©´
©¦ ©¦ ©¦ ©¦user1©¦user2©¦user3©¦
©À©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©È
©¦Auth ©¦Required ©¦Module1©¦Pass ©¦Fail ©¦Pass ©¦
©À©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©È
©¦Auth ©¦Sufficient©¦Module2©¦Pass ©¦Pass ©¦Fail ©¦
©À©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©È
©¦Auth ©¦Required ©¦Module3©¦ N/A ©¦ N/A ©¦Pass ©¦
©À©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©à©¤©¤©¤©¤©¤©È
©¦ Result ©¦ T ©¦ F ©¦ T ©¦
©¸©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©Ø©¤©¤©¤©¤©¤©¼

4 /etc/pam.dĿ¼ÖеÄÅäÖÃÎļþ

ÿһ¸öÅäÖÃÎļþ¾ùÓÐËÄÀ¸£ºµÚÒ»À¸ÑéÖ¤ÀàÐÍ£¬µÚ¶þÀ¸ÑéÖ¤¿ØÖƱê×¼£¬µÚÈýÀ¸µ÷ÓõÄPAMÄ£¿é£¬µÚËÄÀ¸ÎªÊ¹ÓõIJÎÊý¡£

module_type control_flag module_location arguments

ÿһÐмǼ¾ùÊÇÒ»¸ö½×¶ÎÐԵIJâÊÔ¡£

[root@wardking ~]# cat /etc/pam.d/system-auth
#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth required pam_env.so
auth sufficient pam_unix.so nullok try_first_pass
auth requisite pam_succeed_if.so uid >= 500 quiet
auth required pam_deny.so

account required pam_unix.so
account sufficient pam_succeed_if.so uid < 500 quiet
account required pam_permit.so

password requisite pam_cracklib.so try_first_pass retry=3
password sufficient pam_unix.so md5 shadow nullok try_first_pass use_authtok
password required pam_deny.so

session optional pam_keyinit.so revoke
session required pam_limits.so
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session required pam_unix.so

authÓëaccountµ÷ÓõÄÄ£¿éÖ±½ÓÓ°Ïìµ½Óû§ÊÇ·ñ¿ÉÒÔÖ´ÐгÌÐò¡£

passwordÊÇÔÚÓû§¸ü¸ÄÃÜÂëʱʹÓá£

sessionÓÃÓڼǼÓû§ÑéÖ¤³É¹¦ÒÔºóµÄ²Ù×÷¼Ç¼¡£

5 pam_stackÌØÊâÄ£¿é

µ±Óжà¸öÓ¦ÓóÌÐòÐèҪʹÓÃÏàͬµÄÑé֤ģ¿éʱ£¬¿ÉÒԱ༭һ¸öpamÉèÖÃÎļþ£¬¶¨Ò干ͬµ÷ÓõÄÄ£¿é£¬´æ´¢ÓÚ/etc/pam.dĿ¼ÖУ¬¹©Ó¦ÓóÌÐòµ÷Óá£ÀýÈçsystem-authÉèÖÃÎļþ£¬¿ÉÒÔ¹©²»Í¬µÄÓ¦ÓóÌÐòµ÷Óã¬Èç¹û¶ÔÆä½øÐÐÐ޸ģ¬¿ÉÒÔ±ä¸üϵͳÑéÖ¤²ßÂÔ¡£

6 pam_unixÄ£¿é

¿ÉÒÔµ÷Óô«Í³µÄNSSϵͳ£¬¼´libnssº¯Êý¿â¡£¿ÉÒÔÓÃÓÚPAMµÄËÄÖÖÑéÖ¤·½Ê½£¬Ê¹ÓÃauth·½Ê½¿ÉÒÔÈ¡µÃÓû§µÄÃÜÂ룬ʹÓÃaccont·½Ê½¼ì²éÓû§µÄÃÜÂëÊÇ·ñÒѾ­¹ýÆÚ£¬£¬Ê¹ÓÃpassword·½Ê½¿ÉÒÔ¼ì²éÓû§ÔÚÐÞ¸ÄÃÜÂëʱ½øÐпØÖÆ£¬Ê¹ÓÃsession·½Ê½¼Ç¼Óû§µÇ¼µÇ³öÈÕÖ¾¡£

7 ÍøÂçÑéÖ¤

¿ÉÒÔͨ¹ýÍøÂçµÇ¼·½Ê½À´ÑéÖ¤Óû§

* pam_krb5(Kerberos V tickets)
* pam_ldap(LDAP binds)
* pam_smb_auth(old SMB authentication)
* pam_winbind(SMB throuth winbind)

ijЩÃû³Æ·þÎñÒ²¿ÉÒÔͨ¹ýpam_unixµ÷ÓÃlibnssº¯Êý¿âÖеÄÄ£¿é½øÐÐÑéÖ¤(NIS, Some LDAP configurations)£¬¶ø²»Ò»¶¨Ê¹ÓÃÒÔÉϵÄËĸöÄ£¿é

8 ÈÏ֤ģ¿é

pam_securityÄ£¿éÖ»»á¶ÔrootÓÐÓ°Ïì¡£µ±rootÕË»§µÇ¼ʱ£¬pam_security»á²Î¿¼/etc/securettyĿ¼ÖеÄconsoleÁÐ±í£¬ÒÔ¾ö¶¨rootÊÇ·ñ¿ÉÒԵǼ£¬±ÜÃâÓû§´Ó²»°²È«µÄÖն˵Ǽ¡£

pam_nologinÄ£¿é»áÈ·ÈÏ/etc/nologinÎļþÊÇ·ñ´æÔÚ£¬Èç¹û´æÔÚ£¬ÆÕͨÓû§Ôò»áÑé֤ʧ°Ü£¬Ö»ÔÊÐírootÓû§µÇ¼¡£

pam_listfileÄ£¿é»áÈ·ÈÏÒªÇóµÇ¼µÄÓû§Õ˺ÅÓëÔÊÐíµÄÕ˺ÅÃûµ¥ÊÇ·ñ³åÍ»£¬±ØÐ뽨Á¢Ò»¸öÔÊÐíµÇ¼»òÕ߾ܾøµÇ¼µÄÃûµ¥¡£

auth required pam_listfile item=user sense=deny file=/etc/vsftpd/ftpusers onerr=succeed

9 ÔöÇ¿Óû§ÃÜÂ밲ȫÐÔ

pam_unixÓÐÁ½¸ö²ÎÊý£¬¿ÉÒÔÔöÇ¿Óû§ÃÜÂ밲ȫÐÔ

* pam_unix MD5 passwords ʹÓÃMD5±àÂë½øÐмÓÃÜ
* pam_unix shadow passwords ½«¼ÓÃܺóµÄÃÜÂë´æ·ÅÓÚ/etc/shadowÎļþÖУ¬²¢ÇÒÏÞÖÆÆÕͨÓû§·ÃÎÊ£¬¶øÇÒÏÞÖÆÓû§ÃÜÂëÓÐЧÆÚ

»¹ÓÐÆäËüµÄÄ£¿é¿ÉÒÔÆðµ½ÀàËÆ×÷Ó㬱ÈÈçpam_krb5

10 ÃÜÂ밲ȫÐÔÔ­Ôò

¿ÉÒÔ¶¨ÒåÆÕͨÓû§ÉèÖÃÃÜÂëʱ±ØÐë×ñÐÐÒ»¶¨µÄ²ßÂÔ¡£

* password history¼Ç¼Óû§Ôø¾­Ê¹ÓùýµÄÃÜÂë
pam_unix with remember=N (¼Ç¼Óû§Ê¹ÓùýµÄǰN¸öÃÜÂ룬²¢ÇÒ½ûÖ¹ÔÙ´ÎʹÓÃÕâЩÃÜÂë)

* pasword length ÃÜÂ볤¶È¼°¸´ÔÓÐÔ
pam_cracklibÄ£¿é¹æ¶¨Óû§±ØÐëʹÓôóСд×Öĸ¡¢Êý×Ö¡¢ÌØÊâ·ûºÅ×öΪÃÜÂ룬¶øÇÒ²»ÄÜÊÇ×ÖµäÖеĵ¥´Ê
pam_passwdqcÄ£¿éÓëcracklibÀàËÆ£¬Ö»ÊDz»¼ì²é×ÖµäÖеĵ¥´Ê

* failed login monitoring ¼à¿ØÓû§µÇ¼ʧ°ÜµÄ´ÎÊý
pam_tailyµÇ¼ʧ°Ü´ÎÊý¹ý¶à£¬ÔòËø¶¨Õ˺Å

11 pam_limit

pam_limit ÏÞÖÆÓû§¿ÉÒÔʹÓõÄϵͳ×ÊÔ´£¬µ÷Óà /etc/security/limits.confÎļþ£¬ÏÞÖÆÓû§Ê¹ÓõÄÄÚ´æ¡¢¿ÉÒÔÆôÓöàÉÙÏß³Ì

#* soft core 0
#* hard rss 10000
#@student hard nproc 20
#@faculty soft nproc 20
#@faculty hard nproc 50
#ftp hard nproc 0
#@student - maxlogins 4

¿ÉÒÔʹÓÃulimit¸²¸ÇsoftÉèÖÃÏµ«ÊÇÈÔÈ»ÊÜÏÞÓÚhard

12 pam_console

pam_consoleÄ£¿é£ºµ±Óû§µÇ¼µ½consoleºó£¬½«ÓµÓв¿·ÖÌØ±ðȨÏÞ¡£ÕâЩȨÏÞÔÚ/etc/security/console.appsĿ¼Öж¨Òå¡£

ÀýÈ磺Óû§µÇ¼ºóÓµÓÐÖØÐÂÆô¶¯¼ÆËã»úµÄȨÏÞ

[root@wardking ~]# cat /etc/security/console.apps/reboot
FALLBACK=true

Ò²¿ÉÒÔÓÃÔÚauthÑéÖ¤ÀàÐÍÖУ¬Óû§ÔÚ±¾µØ³É¹¦µÇ¼ºó£¬¾Í»á¾Ü¾øÆäËüÔ¶³ÌµÇ¼ÇëÇó¡£

13 ÆäËü³ÌÐòµ÷ÓÃPAM

³ýÓû§µÇ¼ÑéÖ¤ÒÔÍ⣬ÔÚÆÕͨÓû§Ê¹ÓÃϵͳ¹ÜÀí¹¤¾ßʱ£¬Ò²ÐèÒªÌṩÑéÖ¤£¬ÀýÈçsu, reboot, system-*¹¤¾ßµÈ¡£

pam_rootokÄ£¿éÓÃÀ´È·ÈÏÓû§ÊÇ·ñÊÇrootÉí·Ý

pam_timestampÄ£¿éÓÃÓڼǼÓû§Ö´ÐÐsudoµÄʱ¼ä¼ä¸ô£¬Èç¹ûÔÚ5·ÖÖÓÖ®ÄÚÑéÖ¤³É¹¦£¬ÔòÖ±½Óͨ¹ýÑéÖ¤£¬¶ø²»ÔÙÐèÒªÊäÈëÃÜÂë

pam_xauthÄ£¿éÓÃÓÚ½«ÑéÖ¤µÄÁÙʱÎļþת·¢¸øÆäËü³ÌÐò

14 ʵÀý·ÖÎö

[root@wardking ~]# cd /etc/pam.d
[root@wardking pam.d]# cat config-util
#%PAM-1.0
auth sufficient pam_rootok.so
auth sufficient pam_timestamp.so
auth include system-auth
account required pam_permit.so
session required pam_permit.so
session optional pam_xauth.so
session optional pam_timestamp.so

/etc/pam.d/config-utilÊÇÒ»¸öpam_stackÀàÐ͵ÄÌØÊâÄ£¿é£¬Ìṩ¸øsystem-config-*µÈ¶à¸öÓ¦ÓóÌÐò¹²Í¬µ÷Óá£

auth sufficient pam_rootok.so

ÕâÒ»ÌõÃüÁ¼ì²éÓû§µÄÉí·Ý£¬µ÷ÓÃpam_rootok.soÄ£¿é£¬Èç¹û±»ÑéÖ¤µÄÓû§ÊÇroot£¬Ôò·µ»ØPass¡£Èç¹û²»ÊÇrootÓû§£¬Ôò·µ»ØFail¡£ÓÉÓÚ´ËÌõÃüÁîʹÓÃsufficient¿ØÖƱêÖ¾£¬¼´Ê¹Ñé֤ʧ°ÜÒ²½«Ö´ÐкóÐøÃüÁî¡£

auth sufficient pam_timestamp.so

Èç¹ûµÚÒ»ÌõÃüÁîÑé֤ʧ°Ü£¬Ôò¿ÉÒԶ϶¨µ±Ç°±»ÑéÖ¤Óû§ÊÇÆÕͨÓû§¡£Òò´ËÔÚµÚ¶þÌõÃüÁîÖÐʹÓÃpam_timestamp.soÄ£¿é£¬¼ì²é¸ÃÓû§ÊÇ·ñÔÚ5 ·ÖÖÓÖ®Äڳɹ¦ÔËÐÐÁËsudoÃüÁÈç¹ûÊÇ·µ»ØPass£¬·ñÔò·µ»ØFail¡£ÕâÌõÃüÁîͬÑùʹÓÃÁËsufficient¿ØÖƱêÖ¾£¬Òò´ËÔÚÑé֤ʧ°ÜʱÈÔ½«Ö´ÐкóÐøÃüÁî¡£

auth include system-auth

µÚÈýÌõÃüÁîʹÓÃpam_stack.soÄ£¿é£¬µ÷Óõ±Ç°Ä¿Â¼ÏµÄsystem-authÅäÖÃÎļþ¡£system-auth¶¨ÒåÁ˽϶àµÄPAMÃüÁîÓï¾ä£¬ÆäÖ÷Òª×÷ÓÃÊÇÌáʾÆÕͨÓû§ÊäÈërootÕ˺ŵÄÃÜÂë¡£

account required pam_permit.so

µÚËÄÌõÃüÁîÒÔaccountÀàÐ͵÷ÓÃpam_permit.soÄ£¿é£¬»ùÓÚµ±Ç°ÕË»§µÄÓÐЧÐÔ£¨ÕË»§ÊÇ·ñ½ûÓûòÕß¹ýÆÚ£©À´ÔÊÐí»òÕ߾ܾø·ÃÎÊ¡£ÓÉÓÚ¸ÃÌõÃüÁîÒÔrequired¿ØÖƱêÖ¾Ö´ÐУ¬Èç¹ûÑéÖ¤½á¹ûÈÔÈ»Fail£¬ÔòÕû¸ö¹ý³ÌÑé֤ʧ°Ü¡£

×îºóÈýÌõsessionÃüÁ½«¶ÔÕû¸öÑéÖ¤¹ý³Ì½øÐÐÈÕÖ¾¼Ç¼£¬Ð´Èëµ½/var/log/secureÖС£

15 ¹ÊÕϼì²â

µ±ÏµÍ³ÑéÖ¤³öÏÖÎÊÌâʱ£¬Ê×ÏÈÓ¦µ±¼ì²é/var/log/messages»òÕß/var/log/secureÖеÄÊä³öÐÅÏ¢£¬¸ù¾ÝÕâЩÐÅÏ¢ÅжÏÓû§Õ˺ŵÄÓÐЧÐÔ¡£Èç¹ûÊÇÒòΪPAMÑéÖ¤¹ÊÕÏ£¬¶øÒýÆðrootÒ²ÎÞ·¨µÇ¼£¬Ö»ÄÜʹÓÃsingle user»òÕßrescueģʽ½øÐÐÅÅ´í¡£
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 1 ÌõÆÀÂÛ

  1. ssslkj123 ÓÚ 2010-12-08 00:57:07·¢±í:

    Õâ¸ö½²PAMÄ£¿é½²µÄ»¹ÊÇ ±È½ÏÏêϸµÄµ«ÊÇ control values µ±ÖÐµÄ ÎªÊ²Ã´Ã»ÓйØÓÚ include µÄ ½éÉÜ Ö»ËµÁË£ºrequired requisite sunfficient ºÍoptional £¿