
2.3.1 pam_env.conf
This file can be used to define a standardized environment for users that is set whenever
the
pam_env
module is called. With it, preset environment variables using the following
syntax:
VARIABLE
[DEFAULT=[value]]
[OVERRIDE=[value]]
VARIABLE
Name of the environment variable to set.
[DEFAULT=[value]]
Default value the administrator wants set.
[OVERRIDE=[value]]
Values that may be queried and set by
pam_env
, overriding the default value.
A typical example of how
pam_env
can be used is the adaptation of the
DISPLAY
variable, which is changed whenever a remote login takes place. This is shown in
Ex-
ample 2.6, “pam_env.conf”
(page 23).
Example 2.6
pam_env.conf
REMOTEHOST
DEFAULT=localhost OVERRIDE=@{PAM_RHOST}
DISPLAY
DEFAULT=${REMOTEHOST}:0.0 OVERRIDE=${DISPLAY}
The first line sets the value of the
REMOTEHOST
variable to
localhost
, which is
used whenever
pam_env
cannot determine any other value. The
DISPLAY
variable
in turn contains the value of
REMOTEHOST
. Find more information in the comments
in the file
/etc/security/pam_env.conf
.
2.3.2 pam_mount.conf
The purpose of pam_mount is to mount user home directories during the login process,
and to unmount them during logout in an environment where a central file server keeps
all the home directories of users. With this method, it is not necessary to mount a
complete
/home
directory where all user home directories would be accessible. Instead,
only the home directory of the respective user is mounted.
Authentication with PAM
23
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......