?
Solved

How to use PAM to restrict user login for certain time

Posted on 2010-08-29
12
Medium Priority
?
950 Views
Last Modified: 2013-12-06
Hi guys,
I think PAM is used with NIS, by creating users on NIS server and enable client to login to their machines through users created on NIS server (just like windows active directory).

The question is can I use PAM to on local machine (without using NIS)  to restrict users login to linux system for certain time?
0
Comment
Question by:rawandnet
  • 6
  • 5
12 Comments
 
LVL 7

Expert Comment

by:mcuk_storm
ID: 33553479
There is a useful guide on this topic over at techrepublic: http://articles.techrepublic.com.com/5100-10878_11-1055269.html
0
 

Author Comment

by:rawandnet
ID: 33564886
I have followed all steps, but it has no affect, It is just like nothing been done!!
0
 
LVL 14

Expert Comment

by:cjl7
ID: 33584076
Make sure your system-auth-ac loads the correct sub-sections of pam. For example "session".

//jonas
0
Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

 

Author Comment

by:rawandnet
ID: 33584201
how to do that?
0
 
LVL 14

Expert Comment

by:cjl7
ID: 33588248
Could you post your /etc/pam.d/system-auth-ac ?

//jonas
0
 

Author Comment

by:rawandnet
ID: 33605697
content fo /etc/pam.d/system-auth-ac is:
#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth        required      pam_env.so
auth        sufficient    pam_unix.so nullok try_first_pass
auth        requisite     pam_succeed_if.so uid >= 500 quiet
auth        required      pam_deny.so

account     required      pam_unix.so
account     sufficient    pam_succeed_if.so uid < 500 quiet
account     required      pam_permit.so

password    requisite     pam_cracklib.so try_first_pass retry=3
password    sufficient    pam_unix.so md5 shadow nullok try_first_pass use_authtok
password    required      pam_deny.so

session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so

0
 
LVL 14

Expert Comment

by:cjl7
ID: 33628212
Well, you need to enable the module (pam_time) in the account section.

Be very careful, this might break things!!! Do not logout of all your shells as root when you try this!!! (and so on...)

Consider yourself warned. ;)

If you have followed the HOWTO mentioned before all you need to enforce this is to add the following to your system-auth-ac in the account section

account  required  pam_time.so

You don't need to restart pam to test this, and be sure to verify thoroughly before you logout of your shells.

//jonas
0
 

Author Comment

by:rawandnet
ID: 33660224

Under /etc/pam.d/system-auth-ac I added the highlighted text.
#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth        required      pam_env.so
auth        sufficient    pam_unix.so nullok try_first_pass
auth        requisite     pam_succeed_if.so uid >= 500 quiet
auth        required      pam_deny.so
 
account     required      pam_time.so
account     required      pam_unix.so
account     sufficient    pam_succeed_if.so uid < 500 quiet
account     required      pam_permit.so
 
password    requisite     pam_cracklib.so try_first_pass retry=3
password    sufficient    pam_unix.so md5 shadow nis nullok try_first_pass use_authtok
password    required      pam_deny.so
 
session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so
 


Under /etc/security/time.conf for testing I denied access to all users, including root
*;*;*;!A10000-2400
But still root users and other users can login to the system, why is that?
0
 
LVL 14

Expert Comment

by:cjl7
ID: 33662273
Hmm, try to put it under the 'session' part.
0
 

Author Comment

by:rawandnet
ID: 33669428
still deoesn't work! put it under

session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so
account     required      pam_time.so
0
 
LVL 14

Accepted Solution

by:
cjl7 earned 2000 total points
ID: 33669792
Sorry, my bad.

You have to change account     required      pam_time.so  to session     required      pam_time.so
0
 

Author Closing Comment

by:rawandnet
ID: 33700049
thank you
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you use Debian 6 Squeeze and you are tired of looking at the childish graphical GDM login screen that is used by default, here's an easy way to change it. If you've already tried to change it you've probably discovered that none of the old met…
In my business, I use the LTS (Long Term Support) versions of Linux. My workstations do real work, and so I rarely have the patience to deal with silly problems caused by an upgraded kernel that had experimental software on it to begin with from a r…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
Suggested Courses

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question