Bug 2102 - [PATCH] Specify PAM Service name in sshd_config
Summary: [PATCH] Specify PAM Service name in sshd_config
Status: CLOSED DUPLICATE of bug 2246
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: PAM support (show other bugs)
Version: 6.2p1
Hardware: All All
: P5 enhancement
Assignee: Assigned to nobody
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-14 06:28 AEST by Ken Schmidt
Modified: 2021-04-23 15:02 AEST (History)
3 users (show)

See Also:


Attachments
patch to allow configuring the pam service (4.61 KB, application/octet-stream)
2013-05-14 06:28 AEST, Ken Schmidt
no flags Details
patch to allow configuring the pam service (255 bytes, patch)
2014-06-10 05:55 AEST, Petr Lautrbach
no flags Details | Diff
rebased patch for curent HEAD (4.99 KB, patch)
2015-09-18 02:41 AEST, Jakub Jelen
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Ken Schmidt 2013-05-14 06:28:51 AEST
Created attachment 2267 [details]
patch to allow configuring the pam service

The attached patch allows openssh to specify which pam service name to
authenticate users against by specifying the PAMServiceName attribute in
the sshd_config file.  Because the parameter can be included in the Match
directive sections, it allows different authentication based on the Match
directive.  In our case, we use it to allow different levels of
authentication based on the source of the authentication attempts
(securID auth in untrusted zones, password auth in trusted zones).  The
default is still to use the binary name.
Comment 1 Petr Lautrbach 2014-06-10 05:55:29 AEST
Created attachment 2439 [details]
patch to allow configuring the pam service
Comment 2 Petr Lautrbach 2014-06-10 05:57:39 AEST
The PAMServiceName option is also useful for systems with multiple sshd instances with different levels of access control, see https://bugzilla.redhat.com/show_bug.cgi?id=1060237

The attached patch is Ken Schmidt's patch rebased for the latest sources.
Comment 3 Jakub Jelen 2015-09-18 02:41:19 AEST
Created attachment 2711 [details]
rebased patch for curent HEAD

After another discussion about difficult setup with more authentication methods and some of them using PAM in Fedora bug [1], I decided to give a try this patch once more, if it would be acceptable for upstream as portable change.

There are no changes in the patch, but it is updated to apply clean on current HEAD. Also making obsolete Petr's patch, since it is just a file with comment.

[1] https://bugzilla.redhat.com/show_bug.cgi?id=1263133
Comment 4 Damien Miller 2015-12-18 14:31:36 AEDT

*** This bug has been marked as a duplicate of bug 2246 ***
Comment 5 Damien Miller 2021-04-23 15:02:26 AEST
closing resolved bugs as of 8.6p1 release