summaryrefslogtreecommitdiffstats
path: root/lib/libpam/modules
Commit message (Collapse)AuthorAgeFilesLines
* Add a __DECONST() to unbreak the build.des2003-07-151-1/+1
|
* Fix the master yppasswd routines, so they really workmbr2003-06-151-0/+26
| | | | | | | | for root on ypmaster. yppasswd_local() did use YPPASSWDPROG instead of MASTER_YPPASSWDPROG, and the domain was not set, resulting in a coredump during xdr-encode. Reviewed by: des
* Retire pam_wheel(8) (which has been disconnected for quite a while) anddes2003-06-016-657/+0
| | | | pam_ftp(8).
* Update copyright dates.des2003-05-315-5/+5
|
* Remove all instances of pam_std_option()des2003-05-315-167/+58
|
* Introduce pam_guest(8) which will replace pam_ftp(8).des2003-05-314-1/+220
|
* mdoc(7) fixes.ru2003-05-241-4/+4
| | | | Approved by: re (blanket)
* Retire the useless NOSECURE knob.des2003-05-191-2/+1
| | | | Approved by: re (scottl)
* Turn MAKE_KERBEROS5 into NO_KERBEROS by negating the logic. Some extramarkm2003-05-051-1/+1
| | | | | cleanups were necessary in release/Makefile, and the tinderbox code was syntax checked, not run checked.
* Make sure rhostip is always initialized.des2003-04-301-1/+1
| | | | | PR: bin/51508 Submitted by: Peter Grimshaw <peter@tesseract.demon.co.uk>
* Treat an empty PAM_RHOST the same as a NULL one.des2003-04-304-5/+5
| | | | PR: bin/51508
* Set $HOME to the correct directory (within the chroot tree).des2003-04-301-0/+1
|
* Remove a bogus null password check which assumed that a user with an emptydes2003-04-241-2/+8
| | | | | | password must necessarily have an empty pwd->pw_passwd. Also add a check that prevents users from setting a blank password unless the nullok option was specified. Root is still allowed to give anyone a blank password.
* Connect the pam_chroot(8) module to the build.des2003-04-081-0/+1
|
* Add a cwd option which specifies where to chdir(2) after the chroot(2).des2003-04-082-6/+22
| | | | | When using the /home/./foo scheme, this defaults to the rhs (/foo); otherwise it defaults to /.
* Experimental pam_chroot module (not connected to the build)des2003-03-303-0/+193
|
* This module is not WARNS-clean, due to brokenness in OpenSSL headers.des2003-03-101-0/+1
|
* Somewhat better wording.des2003-03-101-8/+6
|
* Silence warning caused by OPIE brokenness.des2003-03-101-2/+3
|
* style.Makefile(5) policeobrien2003-03-0925-109/+119
| | | | | | (I've tried to keep to the spirit of the original formatting) Reviewed by: des
* KerberosIV de-orbit burn continues. Remove the KerberosIV PAM module.markm2003-03-086-451/+0
|
* Comment-only assistance to lint to kill warnings.markm2003-03-081-0/+4
|
* mdoc(7) police: Nits.ru2003-03-032-4/+4
|
* mdoc(7) police: markup laundry.ru2003-02-232-2/+2
|
* Add an "allow_local" option which forces historical behaviour.des2003-02-162-2/+20
|
* Assume "localhost" if no remote host was specified. This is safe from ades2003-02-151-3/+4
| | | | POLA point of view since the stock /etc/opieaccess now allows localhost.
* Use pam_get_user(3) instead of pam_get_item(3) where appropriate.des2003-02-102-4/+4
|
* Complete rewrite of pam_ssh(8). The previous version was becoming harddes2003-02-094-557/+307
| | | | | | | | | | | to maintain, and had security issues which would have required a major rewrite to address anyway. This implementation currently starts a separate agent for each session instead of connecting each new session to the agent started by the first one. While this would be a Good Thing (and the old pam_ssh(8) tried to do it), it's hard to get right. I'll revisit this issue when I've had a chance to test some modifications to ssh-agent(1).
* Maybe I was a little too fast? Remove debugging code, and commit thedes2003-02-063-2/+90
| | | | | | Makefile and man page which I'd forgotten to 'cvs add'. Sponsored by: DARPA, NAI Labs
* Replace pam_wheel(8) with pam_group(8) which has a cleaner interface. Thedes2003-02-062-1/+119
| | | | | | | | | | pam_wheel(8) module was written to work in spite of a broken libpam, and has grown organically since its inception, which is reflected in both its functionality and implementation. Rather than clean up pam_wheel(8) and break backward compatibility, I've chosen to reimplement it under a new, more generic name. Sponsored by: DARPA, NAI Labs
* Make sure the message is only printed once.des2003-02-061-3/+5
|
* Don't blame markm for what he didn't do - writing these man pages, fordes2003-02-062-6/+2
| | | | | instance. Also bump the date since I made substantial modifications earlier today.
* Update copyright.des2003-02-061-1/+1
|
* Add support for escape sequences in the arguments (e.g. %u for user name)des2003-02-062-24/+82
| | | | Sponsored by: DARPA, NAI Labs
* Export the PAM environment to the child process instead of the "normal"des2003-02-062-3/+12
| | | | | | environment list, which may be unsafe and / or sensitive. Sponsored by: DARPA, NAI Labs
* Minimal manual page for pam_kerberosIV(8).des2003-02-062-0/+66
| | | | Sponsored by: DARPA, NAI Labs
* In pam_sm_acct_mgmt(), retrieve the cached credentials before trying todes2003-02-031-3/+6
| | | | | | initialize the context. This way, a failure to initialize the context is not fatal unless we actually have work to do - because if we don't, we return PAM_SUCCESS without even trying to initialize the context.
* Whitespace cleanupdes2003-02-031-3/+3
|
* OpenPAMify.des2003-02-021-33/+10
|
* Do not return inappropriate error codes in pam_sm_setcred.nectar2003-01-291-1/+4
|
* About September 2001, I consulted with all the previous authors ofnectar2003-01-101-163/+13
| | | | | | pam_krb5 to consolidate the copyright texts. The semi-official pam_krb5 module has been distributed with this new license text ever since, but I'm just now getting around to updating the text here.
* english(4) police.schweikh2002-12-273-3/+3
|
* mdoc(7) police: removed gratuitous .Pp call.ru2002-12-231-1/+0
|
* Merge in most non-style differences from Andrew Korty's pam_ssh 1.7.des2002-12-163-51/+70
|
* mdoc(7) police: .Dt is ALL UPPERCASE.ru2002-12-121-1/+1
| | | | Approved by: re
* mdoc(7) police: formatting nits.ru2002-11-292-3/+6
| | | | Approved by: re
* Whitespace nits.des2002-11-281-2/+2
| | | | Approved by: re (bmah)
* Add a PAM_MODULE_ENTRY to this module so it'll actually do something.des2002-11-281-0/+2
| | | | Approved by: re (bmah)
* utmp.ut_time and lastlog.ll_time are explicitly int32_t rather thanpeter2002-11-151-4/+6
| | | | | | | | | | | | time_t. Deal with the possibility that time_t != int32_t. This boils down to this sort of thing: - time(&ut.ut_time); + ut.ut_time = time(NULL); and similar for ctime(3) etc. I've kept it minimal for the stuff that may need to be portable (or 3rd party code), but used Matt's time32 stuff for cases where that isn't as much of a concern. Approved by: re (jhb)
* Make dynamic PAM modules depend on dynamic PAM library.ru2002-11-141-4/+7
| | | | Requested by: des, markm
OpenPOWER on IntegriCloud