The /etc/pam.conf file is the main PAM configuration file. You must edit the file to insert a line in the password service stack. On some Linux systems, the pam.conf file is replaced with /etc/pam.d, so you will need to edit the /etc/pam.d/system-auth file.
To configure the pam.conf file
passwd password required /usr/lib/security/pam_unix.so
passwd password optional /usr/lib/security/pam_CA_eta.so
Indicates the location of an alternate configuration file.
Sends error and informational messages to the local syslog service.
Generates a trace file for each password update operation. The trace files are named /tmp/pam_CA_eta-trace.<nnnn> where <nnnn> is the PID number of the password process.
For AIX systems, add the following lines at the bottom of the /etc/pam.conf file:
#
# CA IdentityMinder Unix Password Synchronization
#
login password optional /usr/lib/security/pam_CA_eta.so syslog passwd password optional /usr/lib/security/pam_CA_eta.so syslog rlogin password optional /usr/lib/security/pam_CA_eta.so syslog su password optional /usr/lib/security/pam_CA_eta.so syslog telnet password optional /usr/lib/security/pam_CA_eta.so syslog sshd password optional /usr/lib/security/pam_CA_eta.so syslog OTHER password optional /usr/lib/security/pam_CA_eta.so syslog
For HP-UX systems, add the following lines at the bottom of the /etc/pam.conf file:
#
# CA IdentityMinder Unix Password Synchronization
#
login password optional /usr/lib/security/libpam_CA_eta.1 syslog passwd password optional /usr/lib/security/libpam_CA_eta.1 syslog dtlogin password optional /usr/lib/security/libpam_CA_eta.1 syslog dtaction password optional /usr/lib/security/libpam_CA_eta.1 syslog OTHER password optional /usr/lib/security/libpam_CA_eta.1 syslog
For HP-UX Itanium2, add the following lines at the bottom of the /etc/pam.conf file:
#
# CA IdentityMinder Unix Password Synchronization
#
login password optional /usr/lib/security/$ISA/libpam_CA_eta.1 syslog passwd password optional /usr/lib/security/$ISA/libpam_CA_eta.1 syslog dtlogin password optional /usr/lib/security/$ISA/libpam_CA_eta.1 syslog dtaction password optional /usr/lib/security/$ISA/libpam_CA_eta.1 syslog OTHER password optional /usr/lib/security/$ISA/libpam_CA_eta.1 syslog
For Sun Solaris systems, add the pam_CA_eta line after the existing pam_unix line:
#
# Password management
#
other password required /usr/lib/security/pam_unix.so.1 other password optional /usr/lib/security/pam_CA_eta.so syslog
For Linux systems, add the pam_CA_eta line between the existing pam_cracklib and pam_unix lines:
password required /lib/security/pam_cracklib.so retry=3 type= password optional /lib/security/pam_CA_eta.so syslog password sufficient /lib/security/pam_unix.so nullok use_authtok md5 shadow password required /lib/security/pam_deny.so
Copyright © 2013 CA.
All rights reserved.
|
|