ºìÁªLinuxÃÅ»§
Linux°ïÖú

¸öÈËÔÚRedhat linux϶ÔPAMµÄÒ»µãÁ˽â

·¢²¼Ê±¼ä:2008-07-19 16:50:11À´Ô´:ºìÁª×÷Õß:Hbhmycg
PAM:»ùÓÚPluggable Authentication Modules(¿É²åÈëÑé֤ģ¿é£¬¼ò³ÆPAM)µÄÑéÖ¤»úÖÆ.Ö÷ÒªÓÃÓÚÓ¦ÓóÌÐòµÄͳһÉí·ÝÑéÖ¤·½Ê½.

/etc/pam.d/Ŀ¼°üÀ¨ËùÓÐÖ§³ÖPAMÓ¦ÓóÌÐòµÄPAMÅäÖÃÎļþ¡£Ã¿¸öÖ§³ÖPAMµÄÓ¦ÓóÌÐò»ò·þÎñ¶¼ÔÚ/etc/pam.d/Ŀ¼ÖÐÓÐÒ»¸öÏàÓ¦µÄÎļþ¡£¶øÕâ¸öĿ¼ÖеÄÿ¸öÎļþµÄÃû³ÆÓëËûÃÇËù¿ØÖÆ·ÃÎʵķþÎñÃû³ÆÏàͬ¡£Õâ¸öÎļþÃû·ÅÖõľÍÊÇËüÃÇ×Ô¼ºµÄPAMÅäÖÃÎļþ,ÔÚÑéÖ¤ÇëÇóʱ£¬Ó¦ÓóÌÐòͨ¹ý libpamº¯Êý¿âÀ´Ìṩ·þÎñ¡£¾ßÌåʹÓÃÄÄЩPAMº¯Êý¿â½øÐÐÑéÖ¤£¬ÔòÓÉ/etc/pam.d/Ŀ¼Ï¶ÔÓ¦µÄÅäÖÃÎļþ¾ö¶¨¡£libpam Ìṩº¯Êý¹²Ïí·þÎñ£¬¶øÇÒ¿ÉÒÔ¶¯Ì¬ÔØÈë¡£ÀýÈç²é¿´Ó¦ÓóÌÐòsuÊÇ·ñÖ§³Öpam£¬¿ÉÓÃldd /bin/suÀ´²é¿´ËüÊÇÖ§³Ölibpamº¯Êý.(±§Ç¸£ºÓÐЩ³ÌÐò²»Ö§³Ölibpamº¯Êýµ«Ò²»á±»PAMËùÑéÖ¤£¬Ä¿Ç°»¹Ã»ÍêÈ«¸ãÇå³þ£©

PAMÅäÖÃÎļþµÄ¸ñʽ


1¡¢service type:
auth:ÓÃÀ´ÑéÖ¤Óû§Éí·Ý£¬ÌáʾÊäÈëÓû§ÃûºÍÃÜÂë¡£

account:ÓÃÀ´ÑéÖ¤ÕʺÅ״̬:Óû§µÄÃÜÂëÊÇ·ñ¹ýÆÚ£¬Óû§ÊÇ·ñÓÐȨÏÞ·ÃÎÊijЩ×ÊÔ´¡£

password:½ûÖ¹Óû§·´¸´³¢ÊԵǼ£¬ÔÚ±ä¸üÃÜÂëʱ½øÐÐÃÜÂ븴ÔÓÐÔ¿ØÖÆ

session:ÓÃÀ´ÅäÖò¢¹ÜÀíÓû§»á»°¡¢½øÐÐÈÕÖ¾¼Ç¼»òÏÞÖÆÓû§µÇ½µÄ´ÎÊý¡£

×¢:Ò»¸öµ¥¶ÀµÄÄ£¿é¿ÉÒÔ°üÀ¨Ò»¸ö»ò¶à¸öÄ£¿é½Ó¿Ú£¬ÀýÈ磬pam_unix.so°üÀ¨ÁËËùÓÐËĸöÄ£¿é½Ó¿Ú

2¡¢control flag
required:ҪʹÑéÖ¤¹ý³Ì¼ÌÐø£¬Õâ¸öÄ£¿éµÄ½á¹û±ØÐëÊdzɹ¦¡£Èç¹ûʧ°Ü£¬Óû§ÒªµÈËùÓÐÄ£¿é¶¼Íê³Éºó²Å»á±»Í¨Öª¡£

requisite:¸úrequired²»Í¬µÄÊÇ£¬Èç¹ûʧ°Ü£¬Óû§»áÂíÉϱ»Í¨Öª¡£

sufficient:Èç¹ûÄ£¿éÑé֤ʧ°Ü£¬ÔòºöÂԴ˽á¹û.Èç¹ûÒ»¸ö´ËÄ£¿é³É¹¦£¬ÇÒÇ°ÃæÃ»ÓÐÈκαêʶΪrequiredµÄÄ£¿éÑé֤ʧ°Ü£¬ÄÇôÎÞÐèÆäËüÈκνá¹û£¬ÔòÕâ¸ö·þÎñ¾Í¿É±»Ê¹Óá£

optional:Ä£¿é½á¹û²»±»Àí»á¡£±»±êʶΪoptionalµÄÄ£¿éÖ»ÔÚÕâ¸ö½çÃæÖÐûÓÐÒýÓÃÆäËüÄ£¿éʱ²Å³ÉΪÑéÖ¤³É¹¦Ëù±ØÐëµÄ¡£

include:°üº¬¸ø³ö·þÎñÀàÐ͵ÄÖ¸¶¨²ÎÊý¡£

×¢£ºrequiredÄ£¿é±»µ÷ÓõÄ˳Ðò²¢²»ÖØÒª¡£Ö»ÓбêʶΪsufficientºÍrequisiteµÄÄ£¿éµÄµ÷ÓÃ˳Ðò²ÅÖØÒª¡£

3¡¢module name
µ÷ÓõÄÄ£¿éÃû¡£Æä¾ø¶ÔPATHÈçÏ£º

32λOS:/lib/security/
64λOS:/lib64/security/

4¡¢module arguments
ÎÞЧµÄ²ÎÊýͨ³£»á±»ºöÂÔ£¬Ëü²»»áÓ°Ïìµ½PAMÑéÖ¤µÄ½á¹û¡£µ«ÔÚһЩģ¿éÖУ¬ÎÞЧµÄ²ÎÊý¿ÉÄܻᵼÖÂÑé֤ʧ°Ü¡£Ò»°ã°ÑerrorдÈë/var/log/secureÎļþ¡£
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 2 ÌõÆÀÂÛ

  1. hantu ÓÚ 2009-07-18 03:25:19·¢±í:

    ºÜºÃµÄ×ÊÁÏ

  2. forlinux0518 ÓÚ 2009-07-17 19:50:56·¢±í:

    ¶÷ £¬¶ÔÓÚѧPAMµÄÈË £¬¶ÔÕâЩÊDZØÐëÕÆÎյģ¬Ð»Ð»Â¥Ö÷