summaryrefslogtreecommitdiff
path: root/doc/modules/pam_chroot.sgml
blob: ec739c188b2d4efa10c2894c54cb80069d05981a (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
<!--
   $Id$
   
   This file was written by Bruce Campbell <brucec@humbug.org.au>
-->

<sect1>Chroot

<sect2>Synopsis

<p>
<descrip>

<tag><bf>Module Name:</bf></tag>
<tt/pam_chroot/

<tag><bf>Author:</bf></tag>
Bruce Campbell &lt;brucec@humbug.org.au&gt;

<tag><bf>Maintainer:</bf></tag>
Author; proposed on 20/11/96 - email for status

<tag><bf>Management groups provided:</bf></tag>
account; session; authentication

<tag><bf>Cryptographically sensitive:</bf></tag>
	
<tag><bf>Security rating:</bf></tag>

<tag><bf>Clean code base:</bf></tag>
Unwritten.

<tag><bf>System dependencies:</bf></tag>

<tag><bf>Network aware:</bf></tag>
Expects localhost.

</descrip>

<sect2>Overview of module

<p>
This module is intended to provide a transparent wrapper around the
average user, one that puts them in a fake file-system (eg, their
'<tt>/</tt>' is really <tt>/some/where/else</tt>).

<p>
Useful if you have several classes of users, and are slightly paranoid
about security.  Can be used to limit who else users can see on the
system, and to limit the selection of programs they can run.

<sect2>Account component:

<p>
<em/Need more info here./

<sect2>Authentication component:

<p>
<em/Need more info here./

<sect2>Session component:

<p>
<em/Need more info here./

<p>
<descrip>

<tag><bf>Recognized arguments:</bf></tag>
Arguments and logging levels for the PAM version are being worked on.

<tag><bf>Description:</bf></tag>

<tag><bf>Examples/suggested usage:</bf></tag>
Do provide a reasonable list of programs - just tossing 'cat', 'ls', 'rm',
'cp' and 'ed' in there is a bit... 
<p>
Don't take it to extremes (eg, you can set up a separate environment for
each user, but its a big waste of your disk space.)

</descrip>

<!--
End of sgml insert for this module.
-->