AlterPath ACS Command Reference Guide
87
Authentication
pam_securetty
Provides standard UNIX securetty checking.
pam_time
Running a well-regulated system occasionally involves restricting
access to certain services in a selective manner. This module offers
some time control for access to services offered by a system. Its actions
are determined with a configuration file. This module can be configured
to deny access to (individual) users based on their name, the time of day,
the day of week, the service they are applying for and their terminal
from which they are making their request.
pam_tacplus
Provides TacacsPlus Server authentication, authorization (account
management), and accounting (session management).
pam_unix
This is the standard UNIX authentication module. It uses standard calls
from the system’s libraries to retrieve and set account information as
well as authentication. Usually this is obtained from the
/etc/passwd
and
the
/etc/shadow
file as well when shadow is enabled.
pam_warn
This module is principally for logging information about a proposed
authentication or application to update a password.
pam_krb5
The Kerberos module currently used is pam_krb5. This PAM module
requires the MIT 1.1+ release of Kerberos, or the Cygnus CNS
distribution. It has not been tested against heimdal or any other Kerberos
distributions. Important file: /etc/krb5.conf. The krb5.conf file contains
Kerberos configuration information, including the locations of KDCs
and admin servers for the Kerberos realms of interest, defaults for the
current realm and for Kerberos applications, and mappings of
hostnames onto Kerberos realms. Normally, you should install your
krb5.conf file in the directory/etc. You can override the default location
by setting the environment variable KRB5_CONFIG.
pam_ldap
Pam_ldap looks for the ldap client configuration file “ldap.conf” in
/etc/. Here's an example of the
ldap.conf
file (partial):
# file name: ldap.conf
# This is the configuration file for the LDAP
# nameservice
# switch library and the LDAP PAM module.
# Your LDAP server. Must be resolvable without using
# LDAP.
host 127.0.0.1
# The distinguished name of the search base.
base dc=padl,dc=com
Module Name
Description
Table 3.7: Available PAM modules in the ACS
Содержание AlterPath ACS
Страница 16: ...xvi Table of Contents...
Страница 29: ...13 This page has been left intentionally blank...
Страница 30: ...14 Preface...
Страница 68: ...52 Device Access...
Страница 86: ...70 Authentication Step 5 Saving changes To save the configuration run the command saveconf...
Страница 96: ...80 Authentication Save the configuration to flash 2 cli config savetoflash...
Страница 114: ...98 Authentication...
Страница 204: ...188 Administration To exit the CLI mode and return to ACS s shell issue the command cli quit...
Страница 268: ...252 Power Management with AlterPath PM Integration...
Страница 304: ...288 PCMCIA Cards Integration...
Страница 338: ...322 Profile Configuration...
Страница 364: ...348 Additional Features and Applications...
Страница 376: ...360 Appendix A New User Background Information...
Страница 406: ...390 Appendix C Cabling and Hardware Information This page has been left intentionally blank...
Страница 418: ...402 List of Tables...
Страница 420: ...404 List of Figures...