summaryrefslogtreecommitdiff
path: root/modules/pam_debug/pam_debug.8
blob: 5bce51e35f2e9a0c04a78365b86459152b879da5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
.\"     Title: pam_debug
.\"    Author: 
.\" Generator: DocBook XSL Stylesheets v1.70.1 <http://docbook.sf.net/>
.\"      Date: 06/17/2006
.\"    Manual: Linux\-PAM Manual
.\"    Source: Linux\-PAM Manual
.\"
.TH "PAM_DEBUG" "8" "06/17/2006" "Linux\-PAM Manual" "Linux\-PAM Manual"
.\" disable hyphenation
.nh
.\" disable justification (adjust text to left margin only)
.ad l
.SH "NAME"
pam_debug \- PAM module to debug the PAM stack
.SH "SYNOPSIS"
.HP 13
\fBpam_debug.so\fR [auth=\fIvalue\fR] [cred=\fIvalue\fR] [acct=\fIvalue\fR] [prechauthtok=\fIvalue\fR] [chauthtok=\fIvalue\fR] [auth=\fIvalue\fR] [open_session=\fIvalue\fR] [close_session=\fIvalue\fR]
.SH "DESCRIPTION"
.PP
The pam_debug PAM module is intended as a debugging aide for determining how the PAM stack is operating. This module returns what its module arguments tell it to return.
.SH "OPTIONS"
.TP 3n
\fBauth=\fR\fB\fIvalue\fR\fR
The
\fBpam_sm_authenticate\fR(3)
function will return
\fIvalue\fR.
.TP 3n
\fBcred=\fR\fB\fIvalue\fR\fR
The
\fBpam_sm_setcred\fR(3)
function will return
\fIvalue\fR.
.TP 3n
\fBacct=\fR\fB\fIvalue\fR\fR
The
\fBpam_sm_acct_mgmt\fR(3)
function will return
\fIvalue\fR.
.TP 3n
\fBprechauthtok=\fR\fB\fIvalue\fR\fR
The
\fBpam_sm_chauthtok\fR(3)
function will return
\fIvalue\fR
if the
\fIPAM_PRELIM_CHECK\fR
flag is set.
.TP 3n
\fBchauthtok=\fR\fB\fIvalue\fR\fR
The
\fBpam_sm_chauthtok\fR(3)
function will return
\fIvalue\fR
if the
\fIPAM_PRELIM_CHECK\fR
flag is
\fBnot\fR
set.
.TP 3n
\fBopen_session=\fR\fB\fIvalue\fR\fR
The
\fBpam_sm_open_session\fR(3)
function will return
\fIvalue\fR.
.TP 3n
\fBclose_session=\fR\fB\fIvalue\fR\fR
The
\fBpam_sm_close_session\fR(3)
function will return
\fIvalue\fR.
.PP
Where
\fIvalue\fR
can be one of: success, open_err, symbol_err, service_err, system_err, buf_err, perm_denied, auth_err, cred_insufficient, authinfo_unavail, user_unknown, maxtries, new_authtok_reqd, acct_expired, session_err, cred_unavail, cred_expired, cred_err, no_module_data, conv_err, authtok_err, authtok_recover_err, authtok_lock_busy, authtok_disable_aging, try_again, ignore, abort, authtok_expired, module_unknown, bad_item, conv_again, incomplete.
.SH "MODULE SERVICES PROVIDED"
.PP
The services
\fBauth\fR,
\fBaccount\fR,
\fBpassword\fR
and
\fBsession\fR
are supported.
.SH "RETURN VALUES"
.TP 3n
PAM_SUCCESS
Default return code if no other value was specified, else specified return value.
.SH "EXAMPLES"
.sp
.RS 3n
.nf
auth    requisite       pam_permit.so
auth    [success=2 default=ok]  pam_debug.so auth=perm_denied cred=success
auth    [default=reset]         pam_debug.so auth=success cred=perm_denied
auth    [success=done default=die] pam_debug.so
auth    optional        pam_debug.so auth=perm_denied cred=perm_denied
auth    sufficient      pam_debug.so auth=success cred=success
    
.fi
.RE
.SH "SEE ALSO"
.PP

\fBpam.conf\fR(5),
\fBpam.d\fR(8),
\fBpam\fR(8)
.SH "AUTHOR"
.PP
pam_debug was written by Andrew G. Morgan <morgan@kernel.org>.