PAM_GROUP - Online Linux Manual PageSection : 8
Updated : 09/03/2021
Source : Linux-PAM Manual
Note : Linux-PAM Manual

NAMEpam_group − PAM module for group access

SYNOPSISpam_group​.so

DESCRIPTIONThe pam_group PAM module does not authenticate the user, but instead it grants group memberships (in the credential setting phase of the authentication module) to the user​. Such memberships are based on the service they are applying for​. By default rules for group memberships are taken from config file /etc/security/group​.conf​. This module's usefulness relies on the file−systems accessible to the user​. The point being that once granted the membership of a group, the user may attempt to create a setgid binary with a restricted group ownership​. Later, when the user is not given membership to this group, they can recover group membership with the precompiled binary​. The reason that the file−systems that the user has access to are so significant, is the fact that when a system is mounted nosuid the user is unable to create or execute such a binary file​. For this module to provide any level of security, all file−systems that the user has write access to should be mounted nosuid​. The pam_group module functions in parallel with the /etc/group file​. If the user is granted any groups based on the behavior of this module, they are granted in addition to those entries /etc/group (or equivalent)​.

OPTIONSThis module does not recognise any options​.

MODULE TYPES PROVIDEDOnly the auth module type is provided​.

RETURN VALUESPAM_SUCCESS group membership was granted​. PAM_ABORT Not all relevant data could be gotten​. PAM_BUF_ERR Memory buffer error​. PAM_CRED_ERR Group membership was not granted​. PAM_IGNORE pam_sm_authenticate was called which does nothing​. PAM_USER_UNKNOWN The user is not known to the system​.

FILES/etc/security/group​.conf Default configuration file

SEE ALSOgroup.conf(5), pam.d(5), pam(8)​.

AUTHORSpam_group was written by Andrew G​. Morgan <morgan@kernel​.org>​.
0
Johanes Gumabo
Data Size   :   8,830 byte
man-pam_group.8Build   :   2024-12-29, 07:25   :  
Visitor Screen   :   x
Visitor Counter ( page / site )   :   4 / 258,886
Visitor ID   :     :  
Visitor IP   :   18.221.58.191   :  
Visitor Provider   :   AMAZON-02   :  
Provider Position ( lat x lon )   :   39.962500 x -83.006100   :   x
Provider Accuracy Radius ( km )   :   1000   :  
Provider City   :   Columbus   :  
Provider Province   :   Ohio ,   :   ,
Provider Country   :   United States   :  
Provider Continent   :   North America   :  
Visitor Recorder   :   Version   :  
Visitor Recorder   :   Library   :  
Online Linux Manual Page   :   Version   :   Online Linux Manual Page - Fedora.40 - march=x86-64 - mtune=generic - 24.12.29
Online Linux Manual Page   :   Library   :   lib_c - 24.10.03 - march=x86-64 - mtune=generic - Fedora.40
Online Linux Manual Page   :   Library   :   lib_m - 24.10.03 - march=x86-64 - mtune=generic - Fedora.40
Data Base   :   Version   :   Online Linux Manual Page Database - 24.04.13 - march=x86-64 - mtune=generic - fedora-38
Data Base   :   Library   :   lib_c - 23.02.07 - march=x86-64 - mtune=generic - fedora.36

Very long time ago, I have the best tutor, Wenzel Svojanovsky . If someone knows the email address of Wenzel Svojanovsky , please send an email to johanes_gumabo@yahoo.co.id .
If error, please print screen and send to johanes_gumabo@yahoo.co.id
Under development. Support me via PayPal.