summaryrefslogtreecommitdiff
path: root/src-repo/README.md
diff options
context:
space:
mode:
authorDennis Kobert <dennis@kobert.dev>2026-03-11 14:15:45 +0100
committerDennis Kobert <dennis@kobert.dev>2026-03-11 14:16:07 +0100
commita9a74679fbec07cf158f2295513e3d4c4adc2666 (patch)
tree5dcac28283ef53c2869bdedb9badff0896900bb6 /src-repo/README.md
parent116bd5a46adc7e9caa27f58b19cafe68d3e085f0 (diff)
Port pam-any from pam-bindings to nonstick crateHEADmain
The pam-bindings crate has a critical bug where pam_try! returns PAM_SUCCESS on error in release builds (anowell/pam-rs#16), causing authentication to always succeed. This replaces it with nonstick and a custom pam_client module with raw PAM FFI for thread-safe conversation forwarding.
Diffstat (limited to 'src-repo/README.md')
-rw-r--r--src-repo/README.md35
1 files changed, 35 insertions, 0 deletions
diff --git a/src-repo/README.md b/src-repo/README.md
new file mode 100644
index 0000000..b6d45a7
--- /dev/null
+++ b/src-repo/README.md
@@ -0,0 +1,35 @@
+# PAM Any
+A PAM module that runs multiple other PAM modules in parallel, succeeding as long as one of them succeeds.
+
+## Installation
+Install [Rust](https://www.rust-lang.org/learn/get-started)
+
+Build (`cargo build --release`)
+
+Copy the PAM module to the location where PAM modules belong
+```bash
+sudo cp target/release/libpam_any.so /lib64/security
+```
+Depending on the distro, the folder might be `/lib` or `/lib64`. On Fedora it's `/lib64`.
+
+Create / edit a file in `/etc/pam.d`. For example, `/etc/pam.d/sudo` for sudo authentication. Here is an example file:
+```
+auth sufficient libpam_any.so { "mode": "One", "modules": { "login": "Password", "pam-random": "Random Chance" } }
+```
+The text after `libpam_any.so` is a JSON object:
+`mode`: Can be either `"One"` or `"All"`. "One" means that you can authenticate with any of the specified methods. For example, you can *either* type your password or use your fingerprint. "All" means that you must authenticate all of the specified modules, but in any order.
+`modules`: Is an object where the key is a file that exists in `/etc/pam.d` and the value is the display name of the service. In the example above, `pam-any` will internally start PAM authentication based on the `/etc/pam.d/login` file (Text password), and `/etc/pam.d/pam-random` file [(A test module that randomly succeeds / fails)](https://github.com/ChocolateLoverRaj/pam-random). As soon as one of the two modules authenticates successfully, the `pam-any` module will authenticate successfully. If all sub-modules fail (wrong password), then `pam-any` will fail.
+
+## Development
+I created a VM to test stuff without messing up the distro I code in.
+- Create a Fedora VM (can probably be any distro)
+- Create a user named `test`
+- Enable SSH server
+- Enable root password
+- Enable root SSH
+- Setup password-less SSH login
+- Setup [`pam-random`](https://github.com/ChocolateLoverRaj/pam-random) as a 2nd test module
+- Update the `IP` variable in `test.sh`
+- Run `bash ./test.sh`
+- Inside the VM install `pamtester`
+- Inside the VM run `pamtester pam-any test authenticate`