Browse Docs

🔐 PAM

/etc/pam.d

In /etc/pam.d, there is one PAM file per service.

Syntax: module_type control_flag path_to_module_agent

Module types

  • auth — authentication.
  • account — account-based restrictions (validity, time of day, etc.).
  • session — things that run at login/logout.
  • password — password updates.

Control flags

  • required — success needed; a failure is reported but only after the rest of the stack has run.
  • requisite — like required, but a failure returns immediately without running the rest of the stack.
  • sufficient — if this module succeeds, it is the last module tested in the stack.
  • optional — its result is only taken into account if no other module succeeded or failed.
  • [value=action value=action2 ...] — advanced control: map a module result to a specific action.

Sample:

1account [default=bad \
2         success=ok  \
3         user_unknown=ignore \
4         service_err=ignore  \
5         system_err=ignore   \
6         authinfo_unavail=ignore] /lib/security/$ISA/pam_ldap.so

pam_faillock — account lockout

 1# /etc/pam.d/password-auth
 2auth        required      pam_env.so
 3auth        required      pam_faillock.so preauth silent audit deny=5
 4auth        sufficient    pam_unix.so nullok try_first_pass
 5auth        [default=die] pam_faillock.so authfail audit deny=5
 6auth        sufficient    pam_faillock.so authsucc audit deny=5
 7auth        requisite     pam_succeed_if.so uid >= 1000 quiet_success
 8auth        required      pam_deny.so
 9
10account     required      pam_access.so
11account     required      pam_faillock.so
1faillock --user <user>          # show the failed-login counter.
2faillock --user <user> --reset  # reset it.

pam_faillock is the modern replacement for the deprecated pam_tally2.

Sunday, October 4, 2026 Tuesday, August 15, 2023