Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 17 Oct 2003 14:28:57 -0400
From:      Adil Katchi <AdilK@sandvine.com>
To:        "'freebsd-hackers@freebsd.org'" <freebsd-hackers@freebsd.org>
Subject:   sshd, PAM and template_user
Message-ID:  <FE045D4D9F7AED4CBFF1B3B813C8533702912027@mail.sandvine.com>

next in thread | raw e-mail | index | archive | help
While I realize that freeBSD has PAM`ified SSH, I was wondering if anyone
was planning to extend this in the manner that telnet/rlogin have been.
>From /etc/pam.d/login: auth sufficient pam_tacplus.so try_first_pass
template_user=staffer
Basically this`ll grab the "staffer" account and use it as the basis for
other arbitrary users who have been authenticated by TACACS. Very handy at
an ISP where you may wish to allow or disallow access to many servers to a
large number of individuals who tend to come and go. The people who don`t
_really_ need to access the machines on a daily basis just get a TACACS
login and they get to live with the "template" user`s dotfiles etc.
Unfortunately, sshd does some explicit checks with getpwnam() that cause ssh
connectins to fail if the user is not in /etc/passwd.
Any ssh hackers looking at this, by any chance? 
Thanks,
Adil



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?FE045D4D9F7AED4CBFF1B3B813C8533702912027>