path: root/modules/pam_ftp/README
diff options
Diffstat (limited to 'modules/pam_ftp/README')
1 files changed, 47 insertions, 13 deletions
diff --git a/modules/pam_ftp/README b/modules/pam_ftp/README
index 6d03330c..15f4130e 100644
--- a/modules/pam_ftp/README
+++ b/modules/pam_ftp/README
@@ -1,18 +1,52 @@
-This is the README for pam_ftp
+pam_ftp — PAM module for anonymous access module
-This module is an authentication module that does simple ftp
-Recognized arguments:
- "debug" print debug messages
- "users=" comma separated list of users which
- could login only with email adress
- "ignore" allow invalid email adresses
+pam_ftp is a PAM module which provides a pluggable anonymous ftp mode of
-Options for:
-auth: for authentication it provides pam_authenticate() and
- pam_setcred() hooks.
+This module intercepts the user's name and password. If the name is ftp or
+anonymous, the user's password is broken up at the @ delimiter into a PAM_RUSER
+and a PAM_RHOST part; these pam-items being set accordingly. The username (
+PAM_USER) is set to ftp. In this case the module succeeds. Alternatively, the
+module sets the PAM_AUTHTOK item with the entered password and fails.
+This module is not safe and easily spoofable.
+ Print debug information.
+ Pay no attention to the email address of the user (if supplied).
+ Instead of ftp or anonymous, provide anonymous login to the comma separated
+ list of users: XXX,YYY,.... Should the applicant enter one of these
+ usernames the returned username is set to the first in the list: XXX.
+Add the following line to /etc/pam.d/ftpd to handle ftp style anonymous login:
+# ftpd; add ftp-specifics. These lines enable anonymous ftp over
+# standard UN*X access (the listfile entry blocks access to
+# users listed in /etc/ftpusers)
+auth sufficient
+auth required use_first_pass
+auth required \
+ onerr=succeed item=user sense=deny file=/etc/ftpusers
+pam_ftp was written by Andrew G. Morgan <>.
-Thorsten Kukuk <>, 17. June 1999