Anybody using PAM? Feedback appreciated
Posted in 2007
Topics: Server Administration
Hi, anybody here uses PAM? If so, what do you like and dislike about it? If not, whay not? Simply don't need it or found any show stopper? In other words, any comments are welcome if you ever considered it. Regards, -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
>From: Fernando Nunes <spam@domus.online.pt> >Hi, >anybody here uses PAM? If so, what do you like and dislike about it? >If not, whay not? Simply don't need it or found any show stopper? > >In other words, any comments are welcome if you ever considered it. > >Regards, > >-- >Fernando Nunes >Portugal This is a bit of a loaded question... If you're running most of the Linux distros then you're "using" PAM. If you meant implementing PAM with IDS, yes and no. Yes I set it up, but not using it on my current implementation. If you are using LDAP authentication, then you're using PAM. What I didn't try to implement is my own PAM module that would allow to authenticate virtual users, but it could be done. What turned me off was that there were some issues in 10.0 and I was working on a 64 bit system. I guess when Cheetah goes GA, I'll try it again. The pain is in trying to write and test your own PAM module. If you're using the regular PAM modules, then it should be ok. _________________________________________________________________ Don't get caught with egg on your face. Play Chicktionary!' http://club.live.com/chicktionary.aspx?icid=chick_hotmailtextlink2
Ian Michael Gumby wrote: > > > >> From: Fernando Nunes <spam@domus.online.pt> >> Hi, >> anybody here uses PAM? If so, what do you like and dislike about it? >> If not, whay not? Simply don't need it or found any show stopper? >> >> In other words, any comments are welcome if you ever considered it. >> >> Regards, >> >> -- >> Fernando Nunes >> Portugal > > This is a bit of a loaded question... > > If you're running most of the Linux distros then you're "using" PAM. I meant explicitly with IDS... Not because the underlying OS uses it.. > > If you meant implementing PAM with IDS, yes and no. > Yes I set it up, but not using it on my current implementation. > > If you are using LDAP authentication, then you're using PAM. Once again, if it's the underlying OS that was not what I had in mind... > What I didn't try to implement is my own PAM module that would allow to > authenticate virtual users, but it could be done. With some restrictions, for now... > What turned me off was that there were some issues in 10.0 and I was > working on a 64 bit system. I believe 10.00.FC6 should have most of the bugs cleared... That doesn't mean it doesn't have some issues... Currently PAM is supported in every 32 or 64 bit platforms (HP-UX, Linux, AIX, Solaris...) > I guess when Cheetah goes GA, I'll try it again. The pain is in trying > to write and test your own PAM module. If you're using the regular PAM > modules, then it should be ok. There shouldn't be too much pain... There are some issues which are being considered (not for Cheetah first release), but there are very simple examples of how to write a module... Nevertheless, there are so many modules out there that I'd be curious to know what other needs are not covered by those. I?m particularly interested in finding why anybody is using it, and also why not. There is no need, tried and it didn't work, could find good documentation, other limitations etc. Thanks for your answer. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
>From: Fernando Nunes <spam@domus.online.pt> Ok, Yes, we're in synch. I have a client where they have a high level of turnover. Since IDS verifies against the user ID, I had to settle for creating a small authentication database and then having an admin application maintain their users. I would have liked to create a virtual user database at the OS level and then have IDS check that via PAM. This way I can have better / more natural user control and authentication. So I guess when the IIUG version becomes available, I'll have to check it out again.... -Mike >Ian Michael Gumby wrote: > > > > > > > >> From: Fernando Nunes <spam@domus.online.pt> > >> Hi, > >> anybody here uses PAM? If so, what do you like and dislike about it? > >> If not, whay not? Simply don't need it or found any show stopper? > >> > >> In other words, any comments are welcome if you ever considered it. > >> > >> Regards, > >> > >> -- > >> Fernando Nunes > >> Portugal > > > > This is a bit of a loaded question... > > > > If you're running most of the Linux distros then you're "using" PAM. > >I meant explicitly with IDS... Not because the underlying OS uses it.. > > > > > If you meant implementing PAM with IDS, yes and no. > > Yes I set it up, but not using it on my current implementation. > > > > If you are using LDAP authentication, then you're using PAM. > >Once again, if it's the underlying OS that was not what I had in mind... > > > > What I didn't try to implement is my own PAM module that would allow to > > authenticate virtual users, but it could be done. > >With some restrictions, for now... > > > > What turned me off was that there were some issues in 10.0 and I was > > working on a 64 bit system. > >I believe 10.00.FC6 should have most of the bugs cleared... That doesn't >mean >it doesn't have some issues... Currently PAM is supported in every 32 or 64 >bit >platforms (HP-UX, Linux, AIX, Solaris...) > > > I guess when Cheetah goes GA, I'll try it again. The pain is in trying > > to write and test your own PAM module. If you're using the regular PAM > > modules, then it should be ok. > >There shouldn't be too much pain... There are some issues which are being >considered (not for Cheetah first release), but there are very simple >examples >of how to write a module... Nevertheless, there are so many modules out >there >that I'd be curious to know what other needs are not covered by those. > > >I?m particularly interested in finding why anybody is using it, and also >why >not. There is no need, tried and it didn't work, could find good >documentation, >other limitations etc. > >Thanks for your answer. > >-- >Fernando Nunes >Portugal > >http://informix-technology.blogspot.com >My email works... but I don't check it frequently... >_______________________________________________ >Informix-list mailing list >Informix-list@iiug.org >http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Don't get caught with egg on your face. Play Chicktionary!' http://club.live.com/chicktionary.aspx?icid=chick_hotmailtextlink2