pam_deny.8.xml 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135
  1. <?xml version="1.0" encoding='UTF-8'?>
  2. <!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.3//EN"
  3. "http://www.oasis-open.org/docbook/xml/4.3/docbookx.dtd">
  4. <refentry id="pam_deny">
  5. <refmeta>
  6. <refentrytitle>pam_deny</refentrytitle>
  7. <manvolnum>8</manvolnum>
  8. <refmiscinfo class="sectdesc">Linux-PAM Manual</refmiscinfo>
  9. </refmeta>
  10. <refnamediv id="pam_deny-name">
  11. <refname>pam_deny</refname>
  12. <refpurpose>The locking-out PAM module</refpurpose>
  13. </refnamediv>
  14. <refsynopsisdiv>
  15. <cmdsynopsis id="pam_deny-cmdsynopsis">
  16. <command>pam_deny.so</command>
  17. </cmdsynopsis>
  18. </refsynopsisdiv>
  19. <refsect1 id="pam_deny-description">
  20. <title>DESCRIPTION</title>
  21. <para>
  22. This module can be used to deny access. It always indicates a failure
  23. to the application through the PAM framework. It might be suitable
  24. for using for default (the <emphasis>OTHER</emphasis>) entries.
  25. </para>
  26. </refsect1>
  27. <refsect1 id="pam_deny-options">
  28. <title>OPTIONS</title>
  29. <para>This module does not recognise any options.</para>
  30. </refsect1>
  31. <refsect1 id="pam_deny-types">
  32. <title>MODULE TYPES PROVIDED</title>
  33. <para>
  34. All module types (<option>account</option>, <option>auth</option>,
  35. <option>password</option> and <option>session</option>) are provided.
  36. </para>
  37. </refsect1>
  38. <refsect1 id='pam_deny-return_values'>
  39. <title>RETURN VALUES</title>
  40. <para>
  41. <variablelist>
  42. <varlistentry>
  43. <term>PAM_AUTH_ERR</term>
  44. <listitem>
  45. <para>
  46. This is returned by the account and auth services.
  47. </para>
  48. </listitem>
  49. </varlistentry>
  50. <varlistentry>
  51. <term>PAM_CRED_ERR</term>
  52. <listitem>
  53. <para>
  54. This is returned by the setcred function.
  55. </para>
  56. </listitem>
  57. </varlistentry>
  58. <varlistentry>
  59. <term>PAM_AUTHTOK_ERR</term>
  60. <listitem>
  61. <para>
  62. This is returned by the password service.
  63. </para>
  64. </listitem>
  65. </varlistentry>
  66. <varlistentry>
  67. <term>PAM_SESSION_ERR</term>
  68. <listitem>
  69. <para>
  70. This is returned by the session service.
  71. </para>
  72. </listitem>
  73. </varlistentry>
  74. </variablelist>
  75. </para>
  76. </refsect1>
  77. <refsect1 id='pam_deny-examples'>
  78. <title>EXAMPLES</title>
  79. <programlisting>
  80. #%PAM-1.0
  81. #
  82. # If we don't have config entries for a service, the
  83. # OTHER entries are used. To be secure, warn and deny
  84. # access to everything.
  85. other auth required pam_warn.so
  86. other auth required pam_deny.so
  87. other account required pam_warn.so
  88. other account required pam_deny.so
  89. other password required pam_warn.so
  90. other password required pam_deny.so
  91. other session required pam_warn.so
  92. other session required pam_deny.so
  93. </programlisting>
  94. </refsect1>
  95. <refsect1 id='pam_deny-see_also'>
  96. <title>SEE ALSO</title>
  97. <para>
  98. <citerefentry>
  99. <refentrytitle>pam.conf</refentrytitle><manvolnum>5</manvolnum>
  100. </citerefentry>,
  101. <citerefentry>
  102. <refentrytitle>pam.d</refentrytitle><manvolnum>5</manvolnum>
  103. </citerefentry>,
  104. <citerefentry>
  105. <refentrytitle>pam</refentrytitle><manvolnum>8</manvolnum>
  106. </citerefentry>
  107. </para>
  108. </refsect1>
  109. <refsect1 id='pam_deny-author'>
  110. <title>AUTHOR</title>
  111. <para>
  112. pam_deny was written by Andrew G. Morgan &lt;morgan@kernel.org&gt;
  113. </para>
  114. </refsect1>
  115. </refentry>