4 ms·
It's not readable and understandable, though. I have more experience with PAM than most Linux admins, I think, and yet I still have to refer to man pages or Go
by jfrunyon 5y ago
It's not readable and understandable, though.
I have more experience with PAM than most Linux admins, I think, and yet I still have to refer to man pages or Google every time I need to do something with it. The keywords and options are already basically nonsense.
- cormacrelf 5y agoNot to mention that linux-pam's `[success=2 default=ignore]` isn't even standard, I think OpenPAM only has the five control flags required/requisite/sufficient/binding/optional. (One may reasonably despair as to the difference between "required" and "requisite".) It's almost as if PAM were developed before the invention of the if-then-else construct in the 1950s.[0] [0]: https://github.com/e-n-f/if-then-else/blob/master/if-then-else.md https://github.com/e-n-f/if-then-else/blob/master/if-then-el...
- tytso 5y agoOriginally pam.conf was envisioned to be quite simple. Say, about the number of lines in /etc/inetd.conf. It was only later that people started doing these really complex things, and most of that was because Linux distributions were shipping far more distributed computing components than was originally were envisioned in 1995. Since ordering was critical in PAM config files, and it was presumed that typical sysadmins weren't going to be editing PAM config files, it had to ship with mentions of every single package that might require a PAM config file. And this is what caused it to get super complex --- and not very well documented, since the presumption was that only distro-engineers needed to understand it, and tech writers have always been underappreciated and underpaid for as long as I can remember in the field (and probably longer).
- thaumasiotes 5y agoJust to say, if I'm reading a config file and see "pam_winbind.so", I have a much better idea of what's going on than if the same file says "winbind" instead.
- jfrunyon 5y agoYou already know that it's PAM-related, since it's a PAM config file. What extra info does the `pam_` give you? .so does give you some info (namely, that it's an external shared object), but I'm not entirely certain how that alone gives you any better idea what's going on: that shared object could do literally anything. You need to know how PAM uses the shared object to know what's going on.
- thaumasiotes 5y ago> You already know that it's PAM-related, since it's a PAM config file. What extra info does the `pam_` give you? The filename, obviously.