Administering LDAP-UX Client Services

PAM_AUTHZ Login Authorization Enhancement

How Login Authorization Works

The system administrator can define the access rules and store them in

the policy file, /etc/opt/ldapux/pam_authz.policy. PAM_AUTHZ

uses these access rules defined in the policy file to control the login authorization.

Figure 4-1

PAM_AUTHZ Environment

1

7

pam enabled application

5

pam_authz

6

authentication modules, for examples: pam_kerberos pam_ldap

policy configuration file

2

ldap-ux

3 client daemon

ldapclientd

4

LDAP

/etc/groupdirectory server

/etc/netgroup

The following describes the policy validation processed by PAM_AUTHZ for the user login authorization shown in figure 4-1:.

1.The administrator defines a local policy file and saves all the defined access rules in the policy configuration file,

/etc/opt/ldapux/pam_authz.policy.

110

Chapter 4

Page 124
Image 124
HP UX LDAP-UX Integration Software manual How Login Authorization Works, Pamauthz Environment