8 ms·
So the fact that PAM was adopted by Linux is mostly my fault. I was the tech lead for Kerberos at MIT, and in 1995 I was visiting Sun to discuss how kerberos
by tytso 5y ago
So the fact that PAM was adopted by Linux is mostly my fault. I was the tech lead for Kerberos at MIT, and in 1995 I was visiting Sun to discuss how kerberos might be included in Solaris. One of the technical discussions that we had was that each time people wanted to add support for various new large scale distributed infrastructures, whether it was Yellow Pages, or Hesiod (YP's rough equivalent developed at MIT Project Athena), or OpenLDAP, or Kerberos, or when we wanted to automatically mount the user's home directory, either using NFS as in Sun, or creating a temporary home directory, or creating a symlink into AFS and then getting AFS tokens, etc. we had to keep on modifying the sources for /bin/login. And this was a positive drag. Basically each large scale site was editing the source code for /bin/login and there was a private customized copy of login at MIT Project Athena, CMU Project Andrew, various US National Labs, yadda, yadda, yadda.
This was how things were done before PAM, and it presumed that you could twist the arms of the proprietary Unix vendors hard enough that they would give you to the source to /bin/login, which of course back then was encumbered by the AT&T Unix license, which means you needed to pay AT&T to get a Source License before you went back to twisting the arms of the proprietary Unix vendor. And if you had a multi-vendor deployment, you might need to separately customize the /bin/login for OSF/1, Solaris, AIX, HP/UX, AUX, and Irix for your large scale deployment --- since all of the proprietary Unix vendors had added their own, incompatible, "value adds" to the OS. Yelch!
The Solaris developers told me about this cool library called Pluggable Authentication Modules which they had been working on, and it was clear to me that this was the answer we were looking for. No longer would each site need to hand edit C code to customize what was supposed to happen vis-a-vis using the user's password to get Kerberos tickets, or get AFS tokens, and what might be needed for session startup such as site-specific ways of attaching the user's home directory.
So I took the idea back from the Bay Area, and I started talking to folks in the Linux community and said, this is the answer to allow us to be able to distribute advanced systems such as Yellow Pages, Kerberos, OpenAFS, etc., and when the user installs the right packages we can automatically make /bin/login do the right thing. Huzzah! Michael K. Johnson at Red Hat and I managed to recruit Andrew Morgan to be the maintainer of Linux-PAM, and it started shipping in Linux distributions in 1996. (Red Hat Linux 3.0.4, shipped in August 1996 had PAM support --- note, this is RHL 3.0.4 which is not RHEL 3. Red Hat Linux predated Red Hat Enterprise Linux.)
Although we did a clean-room reimplementation of the PAM spec, using only the man pages which the Solaris developers had provided to me, it started shipping in Linux distributions before Sun managed to ship their implementation of PAM in Solaris in 1997, even though they developed the spec and had a prototype before we had even started coding.
So the history in Christine's talk isn't quite right. PAM was not developed because of the existence of SSH. It's true that SSH was first written in 1995 as well, and the fact that it made it easier to integrate SSH was a bonus, but the primary concern that I (as a Linux developer and Kerberos Tech Lead) and Sun was most interested in was how to avoid custom, site-specific customized versions of /bin/login so we could more easily promote adoption of new technologies like Kerberos without requiring the site administrator be able to modify /bin/login, or having a combinatorial explosion of different /bin/logins for all of the different distributed computing systems which needed changes to /bin/login.
Oh, and Java was released as a Beta in 1995. The reason why PAM modules wasn't written in Java was because (a) it would have been insane to use something the size of a JVM for a critical system program like /bin/login, and (b) Sun Microsystems' marketing arm hadn't yet started promoting Java like crazy promising "write once, run^H^H^H^H debug everywhere", and claiming that Java was the right answer no matter what the question was. Also, (c) I believe that the Solaris engineers, for whom I have immense respect, had way more good taste than that. :-)
- xena 5y agoCan you email me@christine.website? I'd love to talk and poke the brain of an expert. Maybe even do an interview or something.
- deleted 5y ago[deleted]
- rodgerd 5y agoAnd it was a good call. PAM has plenty of shortcomings, but compared to the alternative options, it was a vast improvement.
- yeetaccount 5y agoYou make HN interesting. Reminds me of slashdot 20 years ago.
- thunderbong 5y agoSo I'm sitting in a corner of the world and suddenly I come in touch with this nugget of computer history told in the first person. There is this feeling of an expanse, of seeing something way larger than oneself, that one experiences when this occurs. Thank you. And thank you HN.
- rawoke083600 5y agoWas thinking the exact same thing. It always amazes me (in a really good way) when there are these "key-people/nerd-celebs" that casually comment and partake on HN ! Like this post or when John Carmack comments on some people's post.
- jtchang 5y agoWhenever I come across some code and think "who could possibly have thought this was a good idea?" I realize there is usually a story behind it. I feel like this comment belongs right along side the PAM source, if only to remind others that we weren't all that nutty coding it this way. Thanks for this writeup!
- 5y ago