Introduction to the Kerberos Products and GSS-API

PAM Kerberos

On HP-UX 11.0 and 11iv1

#

#PAM configuration

#Authentication management

login

auth sufficient

/usr/lib/security/libpam_krb5.1

login

auth required

/usr/lib/security/libpam_unix.1

try_first_pass

 

su

auth sufficient

/usr/lib/security/libpam_krb5.1

su

auth required

/usr/lib/security/libpam_unix.1

try_first_pass

 

dtlogin

auth sufficient

/usr/lib/security/libpam_krb5.1

dtlogin

auth required

/usr/lib/security/libpam_unix.1

try_first_pass

 

dtaction

auth sufficient

/usr/lib/security/libpam_krb5.1

dtaction

auth required

/usr/lib/security/libpam_unix.1

try_first_pass

 

ftp

auth sufficient

/usr/lib/security/libpam_krb5.1

ftp

auth required

/usr/lib/security/libpam_unix.1

try_first_pass

 

OTHER

auth sufficient

/usr/lib/security/libpam_unix.1

#

 

 

#Account management

login

account required /usr/lib/security/libpam_krb5.1

login

account required /usr/lib/security/libpam_unix.1

su

account required /usr/lib/security/libpam_krb5.1

su

account required /usr/lib/security/libpam_unix.1

dtlogin

account required /usr/lib/security/libpam_krb5.1

dtlogin

account required /usr/lib/security/libpam_unix.1

dtaction

account required /usr/lib/security/libpam_krb5.1

dtaction

account required /usr/lib/security/libpam_unix.1

ftp

account required /usr/lib/security/libpam_krb5.1

ftp

account required /usr/lib/security/libpam_unix.1

OTHER

account sufficient /usr/lib/security/libpam_unix.1

#

 

#Session management

login

session required /usr/lib/security/libpam_krb5.1

login

session required /usr/lib/security/libpam_unix.1

dtlogin

session required /usr/lib/security/libpam_krb5.1

dtlogin

session required /usr/lib/security/libpam_unix.1

dtaction

session required /usr/lib/security/libpam_krb5.1

dtaction

session required /usr/lib/security/libpam_unix.1

Chapter 2

43