From owner-freebsd-isp@FreeBSD.ORG Tue Feb 8 05:05:02 2005 Return-Path: Delivered-To: freebsd-isp@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C7E6D16A4CE for ; Tue, 8 Feb 2005 05:05:02 +0000 (GMT) Received: from bsd3.nyct.net (bsd3.nyct.net [216.139.128.7]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5D7D043D1F for ; Tue, 8 Feb 2005 05:05:02 +0000 (GMT) (envelope-from myj@bsd3.nyct.net) Received: from bsd3.nyct.net (localhost [127.0.0.1]) by bsd3.nyct.net (8.12.11/8.12.11) with ESMTP id j18551Ym065102 for ; Tue, 8 Feb 2005 00:05:01 -0500 (EST) (envelope-from myj@bsd3.nyct.net) Received: (from myj@localhost) by bsd3.nyct.net (8.12.11/8.12.11/Submit) id j18551SP065101; Tue, 8 Feb 2005 00:05:01 -0500 (EST) (envelope-from myj) Date: Tue, 8 Feb 2005 00:05:01 -0500 (EST) From: Paul Sandys To: freebsd-isp@freebsd.org Message-ID: <20050208000000.D64811@bsd3.nyct.net> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Subject: PAM and login.conf + SSH and IMAP X-BeenThere: freebsd-isp@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Internet Services Providers List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 08 Feb 2005 05:05:02 -0000 I need to block ssh access to wheel only and at the same time allow IMAP access to any user. When I put following in /etc/login.access, the ssh behaves the way I want: +:wheel:ALL -:ALL:ALL However, it also denies imap access. I'm trying different options in /etc/pam.d/imap without any success. Is there a PAM module that would authenticate using system password file and disregarded /etc/login.access ? Any suggestions ? Thanks, Paul Paul Sandys network operations manager http://www.nyct.net/ 212.293.2620