sepermit.conf.5 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117
  1. '\" t
  2. .\" Title: sepermit.conf
  3. .\" Author: [see the "AUTHOR" section]
  4. .\" Generator: DocBook XSL Stylesheets v1.79.1 <http://docbook.sf.net/>
  5. .\" Date: 09/03/2021
  6. .\" Manual: Linux-PAM Manual
  7. .\" Source: Linux-PAM Manual
  8. .\" Language: English
  9. .\"
  10. .TH "SEPERMIT\&.CONF" "5" "09/03/2021" "Linux-PAM Manual" "Linux\-PAM Manual"
  11. .\" -----------------------------------------------------------------
  12. .\" * Define some portability stuff
  13. .\" -----------------------------------------------------------------
  14. .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  15. .\" http://bugs.debian.org/507673
  16. .\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html
  17. .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  18. .ie \n(.g .ds Aq \(aq
  19. .el .ds Aq '
  20. .\" -----------------------------------------------------------------
  21. .\" * set default formatting
  22. .\" -----------------------------------------------------------------
  23. .\" disable hyphenation
  24. .nh
  25. .\" disable justification (adjust text to left margin only)
  26. .ad l
  27. .\" -----------------------------------------------------------------
  28. .\" * MAIN CONTENT STARTS HERE *
  29. .\" -----------------------------------------------------------------
  30. .SH "NAME"
  31. sepermit.conf \- configuration file for the pam_sepermit module
  32. .SH "DESCRIPTION"
  33. .PP
  34. The lines of the configuration file have the following syntax:
  35. .PP
  36. \fI<user>\fR[:\fI<option>\fR:\fI<option>\fR\&.\&.\&.]
  37. .PP
  38. The
  39. \fBuser\fR
  40. can be specified in the following manner:
  41. .sp
  42. .RS 4
  43. .ie n \{\
  44. \h'-04'\(bu\h'+03'\c
  45. .\}
  46. .el \{\
  47. .sp -1
  48. .IP \(bu 2.3
  49. .\}
  50. a username
  51. .RE
  52. .sp
  53. .RS 4
  54. .ie n \{\
  55. \h'-04'\(bu\h'+03'\c
  56. .\}
  57. .el \{\
  58. .sp -1
  59. .IP \(bu 2.3
  60. .\}
  61. a groupname, with
  62. \fB@group\fR
  63. syntax\&. This should not be confused with netgroups\&.
  64. .RE
  65. .sp
  66. .RS 4
  67. .ie n \{\
  68. \h'-04'\(bu\h'+03'\c
  69. .\}
  70. .el \{\
  71. .sp -1
  72. .IP \(bu 2.3
  73. .\}
  74. a SELinux user name with
  75. \fB%seuser\fR
  76. syntax\&.
  77. .RE
  78. .PP
  79. The recognized options are:
  80. .PP
  81. \fBexclusive\fR
  82. .RS 4
  83. Only single login session will be allowed for the user and the user\*(Aqs processes will be killed on logout\&.
  84. .RE
  85. .PP
  86. \fBignore\fR
  87. .RS 4
  88. The module will never return PAM_SUCCESS status for the user\&. It will return PAM_IGNORE if SELinux is in the enforcing mode, and PAM_AUTH_ERR otherwise\&. It is useful if you want to support passwordless guest users and other confined users with passwords simultaneously\&.
  89. .RE
  90. .PP
  91. The lines which start with # character are comments and are ignored\&.
  92. .SH "EXAMPLES"
  93. .PP
  94. These are some example lines which might be specified in
  95. /etc/security/sepermit\&.conf\&.
  96. .sp
  97. .if n \{\
  98. .RS 4
  99. .\}
  100. .nf
  101. %guest_u:exclusive
  102. %staff_u:ignore
  103. %user_u:ignore
  104. .fi
  105. .if n \{\
  106. .RE
  107. .\}
  108. .SH "SEE ALSO"
  109. .PP
  110. \fBpam_sepermit\fR(8),
  111. \fBpam.d\fR(5),
  112. \fBpam\fR(8),
  113. \fBselinux\fR(8),
  114. .SH "AUTHOR"
  115. .PP
  116. pam_sepermit and this manual page were written by Tomas Mraz <tmraz@redhat\&.com>