pam_access man page on CentOS

Man page or keyword search:  
man Server   8420 pages
apropos Keyword Search (all sections)
Output format
CentOS logo
[printable version]

PAM_ACCESS(8)		       Linux-PAM Manual			 PAM_ACCESS(8)

NAME
       pam_access - PAM module for logdaemon style login access control

SYNOPSIS
       pam_access.so [debug] [nodefgroup] [noaudit] [accessfile=file]
		     [fieldsep=sep] [listsep=sep]

DESCRIPTION
       The pam_access PAM module is mainly for access management. It provides
       logdaemon style login access control based on login names, host or
       domain names, internet addresses or network numbers, or on terminal
       line names in case of non-networked logins.

       By default rules for access management are taken from config file
       /etc/security/access.conf if you don't specify another file.

OPTIONS
       accessfile=/path/to/access.conf
	      Indicate an alternative access.conf style configuration file to
	      override the default. This can be useful when different services
	      need different access lists.

       debug  A lot of debug informations are printed with syslog(3).

       noaudit
	      Do not report logins from disallowed hosts and ttys to the audit
	      subsystem.

       fieldsep=separators
	      This option modifies the field separator character that
	      pam_access will recognize when parsing the access configuration
	      file. For example: fieldsep=| will cause the default `:'
	      character to be treated as part of a field value and `|' becomes
	      the field separator. Doing this may be useful in conjuction with
	      a system that wants to use pam_access with X based applications,
	      since the PAM_TTY item is likely to be of the form "hostname:0"
	      which includes a `:' character in its value. But you should not
	      need this.

       listsep=separators
	      This option modifies the list separator character that
	      pam_access will recognize when parsing the access configuration
	      file. For example: listsep=, will cause the default ` ' (space)
	      and `\t' (tab) characters to be treated as part of a list
	      element value and `,' becomes the only list element separator.
	      Doing this may be useful on a system with group information
	      obtained from a Windows domain, where the default built-in
	      groups "Domain Users", "Domain Admins" contain a space.

       nodefgroup
	      User tokens which are not enclosed in parentheses will not be
	      matched against the group database. The backwards compatible
	      default is to try the group database match for all tokens.
	      Without the option the parentheses do not have any special
	      meaning which means that matching user accounts and/or groups
	      with parentheses in name is still possible.

MODULE SERVICES PROVIDED
       All services are supported.

RETURN VALUES
       PAM_SUCCESS
	      Access was granted.

       PAM_PERM_DENIED
	      Access was not granted.

       PAM_IGNORE
	      pam_setcred was called which does nothing.

       PAM_ABORT
	      Not all relevant data or options could be gotten.

       PAM_USER_UNKNOWN
	      The user is not known to the system.

FILES
       /etc/security/access.conf
	      Default configuration file

SEE ALSO
       access.conf(5), pam.d(8), pam(8).

AUTHORS
       The logdaemon style login access control scheme was designed and
       implemented by Wietse Venema. The pam_access PAM module was developed
       by Alexei Nogin <alexei@nogin.dnttm.ru>. The IPv6 support and the
       network(address) / netmask feature was developed and provided by Mike
       Becher <mike.becher@lrz-muenchen.de>.

Linux-PAM Manual		  01/09/2013			 PAM_ACCESS(8)
[top]

List of man pages available for CentOS

Copyright (c) for man pages and the logo by the respective OS vendor.

For those who want to learn more, the polarhome community provides shell access and support.

[legal] [privacy] [GNU] [policy] [cookies] [netiquette] [sponsors] [FAQ]
Tweet
Polarhome, production since 1999.
Member of Polarhome portal.
Based on Fawad Halim's script.
....................................................................
Vote for polarhome
Free Shell Accounts :: the biggest list on the net