Re: 7.4.3 and PAM authentication failures - Mailing list pgsql-admin

From Tom Lane
Subject Re: 7.4.3 and PAM authentication failures
Date
Msg-id 18655.1092699344@sss.pgh.pa.us
Whole thread Raw
In response to 7.4.3 and PAM authentication failures  (Dallas N Antley <dna+pgsql@clas.ufl.edu>)
Responses Re: 7.4.3 and PAM authentication failures  (Dallas N Antley <dna+pgsql@clas.ufl.edu>)
List pgsql-admin
Dallas N Antley <dna+pgsql@clas.ufl.edu> writes:
> I think I know why pam authentication fails with the pam_unix*
> modules, but would appreciate your opinion.

I think you've proven that the particular PAM modules you are testing
with are useless for programs executing as non-root, but that doesn't
mean the entire concept is broken.  Look around ... there are lots of
PAM modules (or at least that's the theory).

BTW, what are those "door_info()" and "door_call()" calls shown in the
truss output?  Could it be that those are supposed to get the PAM code
into a higher authorization level?

            regards, tom lane

pgsql-admin by date:

Previous
From: Dallas N Antley
Date:
Subject: 7.4.3 and PAM authentication failures
Next
From: Dallas N Antley
Date:
Subject: Re: 7.4.3 and PAM authentication failures