1*30332991Swiz.\" $NetBSD: pam_group.8,v 1.4 2005/02/02 14:34:25 wiz Exp $ 26f11bdf1Schristos.\" Copyright (c) 2003 Networks Associates Technology, Inc. 36f11bdf1Schristos.\" All rights reserved. 46f11bdf1Schristos.\" 56f11bdf1Schristos.\" Portions of this software were developed for the FreeBSD Project by 66f11bdf1Schristos.\" ThinkSec AS and NAI Labs, the Security Research Division of Network 76f11bdf1Schristos.\" Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 86f11bdf1Schristos.\" ("CBOSS"), as part of the DARPA CHATS research program. 96f11bdf1Schristos.\" 106f11bdf1Schristos.\" Redistribution and use in source and binary forms, with or without 116f11bdf1Schristos.\" modification, are permitted provided that the following conditions 126f11bdf1Schristos.\" are met: 136f11bdf1Schristos.\" 1. Redistributions of source code must retain the above copyright 146f11bdf1Schristos.\" notice, this list of conditions and the following disclaimer. 156f11bdf1Schristos.\" 2. Redistributions in binary form must reproduce the above copyright 166f11bdf1Schristos.\" notice, this list of conditions and the following disclaimer in the 176f11bdf1Schristos.\" documentation and/or other materials provided with the distribution. 186f11bdf1Schristos.\" 3. The name of the author may not be used to endorse or promote 196f11bdf1Schristos.\" products derived from this software without specific prior written 206f11bdf1Schristos.\" permission. 216f11bdf1Schristos.\" 226f11bdf1Schristos.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 236f11bdf1Schristos.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 246f11bdf1Schristos.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 256f11bdf1Schristos.\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 266f11bdf1Schristos.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 276f11bdf1Schristos.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 286f11bdf1Schristos.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 296f11bdf1Schristos.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 306f11bdf1Schristos.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 316f11bdf1Schristos.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 326f11bdf1Schristos.\" SUCH DAMAGE. 336f11bdf1Schristos.\" 346f11bdf1Schristos.\" $FreeBSD: src/lib/libpam/modules/pam_group/pam_group.8,v 1.3 2004/07/02 23:52:17 ru Exp $ 356f11bdf1Schristos.\" 36*30332991Swiz.Dd February 1, 2005 376f11bdf1Schristos.Dt PAM_GROUP 8 386f11bdf1Schristos.Os 396f11bdf1Schristos.Sh NAME 406f11bdf1Schristos.Nm pam_group 416f11bdf1Schristos.Nd Group PAM module 426f11bdf1Schristos.Sh SYNOPSIS 436f11bdf1Schristos.Op Ar service-name 446f11bdf1Schristos.Ar module-type 456f11bdf1Schristos.Ar control-flag 466f11bdf1Schristos.Pa pam_group 476f11bdf1Schristos.Op Ar arguments 486f11bdf1Schristos.Sh DESCRIPTION 496f11bdf1SchristosThe group service module for PAM accepts or rejects users based on 506f11bdf1Schristostheir membership in a particular file group. 516f11bdf1Schristos.Pp 526f11bdf1SchristosThe following options may be passed to the 536f11bdf1Schristos.Nm 546f11bdf1Schristosmodule: 556f11bdf1Schristos.Bl -tag -width ".Cm fail_safe" 566f11bdf1Schristos.It Cm deny 576f11bdf1SchristosReverse the meaning of the test, i.e., reject the applicant if and only 586f11bdf1Schristosif he or she is a member of the specified group. 596f11bdf1SchristosThis can be useful to exclude certain groups of users from certain 606f11bdf1Schristosservices. 616f11bdf1Schristos.It Cm fail_safe 626f11bdf1SchristosIf the specified group does not exist, or has no members, act as if 636f11bdf1Schristosit does exist and the applicant is a member. 646f11bdf1Schristos.It Cm group Ns = Ns Ar groupname 656f11bdf1SchristosSpecify the name of the group to check. 666f11bdf1SchristosThe default is 676f11bdf1Schristos.Dq Li wheel . 686f11bdf1Schristos.It Cm root_only 696f11bdf1SchristosSkip this module entirely if the target account is not the superuser 706f11bdf1Schristosaccount. 711d6e3b56Schristos.It Cm authenticate 721d6e3b56SchristosThe user is asked to authenticate using his own password. 736f11bdf1Schristos.El 746f11bdf1Schristos.Sh SEE ALSO 756f11bdf1Schristos.Xr pam.conf 5 , 766f11bdf1Schristos.Xr pam 8 776f11bdf1Schristos.Sh AUTHORS 786f11bdf1SchristosThe 796f11bdf1Schristos.Nm 806f11bdf1Schristosmodule and this manual page were developed for the 816f11bdf1Schristos.Fx 826f11bdf1SchristosProject by 836f11bdf1SchristosThinkSec AS and NAI Labs, the Security Research Division of Network 846f11bdf1SchristosAssociates, Inc.\& under DARPA/SPAWAR contract N66001-01-C-8035 856f11bdf1Schristos.Pq Dq CBOSS , 866f11bdf1Schristosas part of the DARPA CHATS research program. 87