195ca4cb3SDag-Erling Smørgrav.\" Copyright (c) 2001 Mark R V Murray 295ca4cb3SDag-Erling Smørgrav.\" All rights reserved. 395ca4cb3SDag-Erling Smørgrav.\" Copyright (c) 2001 Networks Associates Technology, Inc. 495ca4cb3SDag-Erling Smørgrav.\" All rights reserved. 595ca4cb3SDag-Erling Smørgrav.\" 695ca4cb3SDag-Erling Smørgrav.\" Portions of this software were developed for the FreeBSD Project by 795ca4cb3SDag-Erling Smørgrav.\" ThinkSec AS and NAI Labs, the Security Research Division of Network 895ca4cb3SDag-Erling Smørgrav.\" Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 995ca4cb3SDag-Erling Smørgrav.\" ("CBOSS"), as part of the DARPA CHATS research program. 1095ca4cb3SDag-Erling Smørgrav.\" 1195ca4cb3SDag-Erling Smørgrav.\" Redistribution and use in source and binary forms, with or without 1295ca4cb3SDag-Erling Smørgrav.\" modification, are permitted provided that the following conditions 1395ca4cb3SDag-Erling Smørgrav.\" are met: 1495ca4cb3SDag-Erling Smørgrav.\" 1. Redistributions of source code must retain the above copyright 1595ca4cb3SDag-Erling Smørgrav.\" notice, this list of conditions and the following disclaimer. 1695ca4cb3SDag-Erling Smørgrav.\" 2. Redistributions in binary form must reproduce the above copyright 1795ca4cb3SDag-Erling Smørgrav.\" notice, this list of conditions and the following disclaimer in the 1895ca4cb3SDag-Erling Smørgrav.\" documentation and/or other materials provided with the distribution. 1995ca4cb3SDag-Erling Smørgrav.\" 3. The name of the author may not be used to endorse or promote 2095ca4cb3SDag-Erling Smørgrav.\" products derived from this software without specific prior written 2195ca4cb3SDag-Erling Smørgrav.\" permission. 2295ca4cb3SDag-Erling Smørgrav.\" 2395ca4cb3SDag-Erling Smørgrav.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 2495ca4cb3SDag-Erling Smørgrav.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 2595ca4cb3SDag-Erling Smørgrav.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 2695ca4cb3SDag-Erling Smørgrav.\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 2795ca4cb3SDag-Erling Smørgrav.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 2895ca4cb3SDag-Erling Smørgrav.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 2995ca4cb3SDag-Erling Smørgrav.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 3095ca4cb3SDag-Erling Smørgrav.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 3195ca4cb3SDag-Erling Smørgrav.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 3295ca4cb3SDag-Erling Smørgrav.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 3395ca4cb3SDag-Erling Smørgrav.\" SUCH DAMAGE. 3495ca4cb3SDag-Erling Smørgrav.\" 3595ca4cb3SDag-Erling Smørgrav.Dd December 5, 2001 3695ca4cb3SDag-Erling Smørgrav.Dt PAM_RHOSTS 8 3795ca4cb3SDag-Erling Smørgrav.Os 3895ca4cb3SDag-Erling Smørgrav.Sh NAME 3995ca4cb3SDag-Erling Smørgrav.Nm pam_rhosts 4095ca4cb3SDag-Erling Smørgrav.Nd Rhosts PAM module 4195ca4cb3SDag-Erling Smørgrav.Sh SYNOPSIS 4295ca4cb3SDag-Erling Smørgrav.Op Ar service-name 4395ca4cb3SDag-Erling Smørgrav.Ar module-type 4495ca4cb3SDag-Erling Smørgrav.Ar control-flag 4595ca4cb3SDag-Erling Smørgrav.Pa pam_rhosts 4695ca4cb3SDag-Erling Smørgrav.Op Ar options 4795ca4cb3SDag-Erling Smørgrav.Sh DESCRIPTION 4895ca4cb3SDag-Erling SmørgravThe rhosts authentication service module for PAM, 4995ca4cb3SDag-Erling Smørgrav.Nm 5095ca4cb3SDag-Erling Smørgravprovides functionality for only one PAM category: 5195ca4cb3SDag-Erling Smørgravauthentication. 5295ca4cb3SDag-Erling SmørgravIn terms of the 5395ca4cb3SDag-Erling Smørgrav.Ar module-type 5495ca4cb3SDag-Erling Smørgravparameter, this is the 5595ca4cb3SDag-Erling Smørgrav.Dq Li auth 5695ca4cb3SDag-Erling Smørgravfeature. 5795ca4cb3SDag-Erling Smørgrav.Ss Rhosts Authentication Module 5895ca4cb3SDag-Erling SmørgravThe Rhosts authentication component 5995ca4cb3SDag-Erling Smørgrav.Pq Fn pam_sm_authenticate , 6095ca4cb3SDag-Erling Smørgravreturns success if and only if the target user's UID is not 0 and the 6195ca4cb3SDag-Erling Smørgravremote host and user are listed in 6295ca4cb3SDag-Erling Smørgrav.Pa /etc/hosts.equiv 6395ca4cb3SDag-Erling Smørgravor in the target user's 6495ca4cb3SDag-Erling Smørgrav.Pa ~/.rhosts . 6595ca4cb3SDag-Erling Smørgrav.Pp 6695ca4cb3SDag-Erling SmørgravThe following options may be passed to the authentication module: 6795ca4cb3SDag-Erling Smørgrav.Bl -tag -width ".Cm allow_root" 6895ca4cb3SDag-Erling Smørgrav.It Cm debug 6995ca4cb3SDag-Erling Smørgrav.Xr syslog 3 7095ca4cb3SDag-Erling Smørgravdebugging information at 7195ca4cb3SDag-Erling Smørgrav.Dv LOG_DEBUG 7295ca4cb3SDag-Erling Smørgravlevel. 7395ca4cb3SDag-Erling Smørgrav.It Cm no_warn 7495ca4cb3SDag-Erling Smørgravsuppress warning messages to the user. 7595ca4cb3SDag-Erling SmørgravThese messages include reasons why the user's authentication attempt 7695ca4cb3SDag-Erling Smørgravwas declined. 7795ca4cb3SDag-Erling Smørgrav.It Cm allow_root 7895ca4cb3SDag-Erling Smørgravdo not automatically fail if the target user's UID is 0. 7995ca4cb3SDag-Erling Smørgrav.El 8095ca4cb3SDag-Erling Smørgrav.Sh SEE ALSO 81*6e1fc011SGraham Percival.Xr pam 3 , 8295ca4cb3SDag-Erling Smørgrav.Xr hosts.equiv 5 , 83*6e1fc011SGraham Percival.Xr pam.conf 5 8495ca4cb3SDag-Erling Smørgrav.Sh AUTHORS 8595ca4cb3SDag-Erling SmørgravThe 8695ca4cb3SDag-Erling Smørgrav.Nm 8795ca4cb3SDag-Erling Smørgravmodule and this manual page were developed for the 8895ca4cb3SDag-Erling Smørgrav.Fx 8995ca4cb3SDag-Erling SmørgravProject by 9095ca4cb3SDag-Erling SmørgravThinkSec AS and NAI Labs, the Security Research Division of Network 911a0a9345SRuslan ErmilovAssociates, Inc.\& under DARPA/SPAWAR contract N66001-01-C-8035 9295ca4cb3SDag-Erling Smørgrav.Pq Dq CBOSS , 9395ca4cb3SDag-Erling Smørgravas part of the DARPA CHATS research program. 94