LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 10-08-2014, 02:43 AM   #31
Bourdieu
Member
 
Registered: Jan 2006
Location: Paris
Distribution: Slackware current
Posts: 38

Rep: Reputation: 11

According to this http://www.hashbangbash.com/downloads/pam/NOTES.txt

Quote:
Thu Sep 18 16:24:55 EDT 2014 (vbatts)
* including fresh package builds for x86_64

Sat Jul 26 17:41:01 CDT 2014 (rworkman)
* updated most everything to -current versions (with some newer)
* updated the new stuff to latest upstream versions
And especially this http://www.slackware.com/~vbatts/pam/
Quote:
Hey there,

Timeline:
Started circa the release of Slackware-14.2
was the hackings on Linux-PAM integreation to Slackware Linux.
To date it has just keep up with the -current development branch.

Overview:
This is the addition of two packages (pam, cracklib), and the rebuild of a series of packages, to overhaul the authentication in Slackware Linux, using Linux-PAM
It looks like Vincent Batts and Robby Workman are testing the integration of Linux Pam for the next slackware release.

I think this a good news. It will greatly ease the integration of Kerberos/LDAP authentication in slackware.

Last edited by Bourdieu; 10-08-2014 at 05:25 AM. Reason: Mistake about the authors of thoses changes
 
5 members found this post helpful.
Old 10-09-2014, 01:23 PM   #32
Richard Cranium
Senior Member
 
Registered: Apr 2009
Location: McKinney, Texas
Distribution: Slackware64 15.0
Posts: 3,858

Rep: Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225
Did I sleep through the release of Slackware 14.2?
 
Old 10-09-2014, 03:29 PM   #33
EYo
Member
 
Registered: Jun 2009
Distribution: Slackware
Posts: 190

Rep: Reputation: 153Reputation: 153
Next version prediction!

Good news indeed.

Quote:
Originally Posted by Richard Cranium View Post
Did I sleep through the release of Slackware 14.2?
No, but I'm ready for beta , so here's my 14.2 prediction ...
Setting Orange, The Aftermath 63, 3180 YOLD

Better hurry
 
2 members found this post helpful.
Old 10-10-2014, 10:58 AM   #34
ivandi
Member
 
Registered: Jul 2009
Location: Québec, Canada
Distribution: CRUX, Debian
Posts: 528

Original Poster
Rep: Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866
Quote:
Originally Posted by Bourdieu View Post
It looks like Vincent Batts and Robby Workman are testing the integration of Linux Pam for the next slackware release.

I think this a good news. It will greatly ease the integration of Kerberos/LDAP authentication in slackware.
Yeah, hope we'll see something in the ChangeLog.

Service configs in /etc/pam.d need a lot of testing and customization. And for now Batts and Workman's configs look plain vanilla. So I am pretty sure there will be no PAM in 14.2. Lets hope for 15.

That said I uploaded several PAM enabled slackbuilds for those willing to tweak service configs.

Tested cups, vsftpd, at, cron(dcron has no PAM support so I replaced it with cronie from SBo).

Will test openvpn at some point.

Not sure about ipopd, imapd. Is there somebody who still uses wu-imap.

Cheers
 
Old 10-13-2014, 11:03 AM   #35
ivandi
Member
 
Registered: Jul 2009
Location: Québec, Canada
Distribution: CRUX, Debian
Posts: 528

Original Poster
Rep: Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866
Added cracklib. Kerberos has his own passord policy. So it's your choice.

Added slackbuilds for xdm xlockmore screen.
Changed PAM slackbuild to make unix_chkpwd sgid shadow. That makes xlock and screen C+a x work. No need for sgid shadow for xlock.

Added PASSWDTYPE=pam to alpine slackbuild to make imapd and ipop3d actually use PAM. Works fine.

Replaced sendmail. I prefer killing brain cells with a glass of wine than reading sendmail.cf. Exim is in SBo and I changed the slackbuild to use PAM. Put a reasonable default config, relay on auth over tls only. Works fine with PAM+LDAP.

I think I'll stop here. There are some 30 slackbuilds that provide a complete PAM, LDAP, Kerberos, NFS4, ADS support. If some work on PAM is going on at slackware.com I think my little project will be helpful. For me the advantages of having these technologies in Slackware are more than obvious.


Cheers.
 
3 members found this post helpful.
Old 10-13-2014, 11:10 AM   #36
kikinovak
MLED Founder
 
Registered: Jun 2011
Location: Montpezat (South France)
Distribution: CentOS, OpenSUSE
Posts: 3,453

Rep: Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154
Quote:
Originally Posted by ivandi View Post
replaced sendmail. I prefer killing brain cells with a glass of wine than reading sendmail.cf.
modquote!!!
 
Old 10-13-2014, 05:26 PM   #37
ivandi
Member
 
Registered: Jul 2009
Location: Québec, Canada
Distribution: CRUX, Debian
Posts: 528

Original Poster
Rep: Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866
Sendmail, c'est spécial

Anyway, lets look at the Slackware's mail subsystem. Sendmail uses procmail as LDA. Procmail supports mbox and maildir. UW-IMAP supports mbox mbx and mix. It has tmail and dmail to support delivery in mbx/mix but both are not shipped by default ?!?. So we are left with the old flat file mbox. IMO nowadays mbox is only suitable for collecting mails from failed cron jobs.

At least exim supports mbx and has a human readable config. I am doing my best to keep compatible, but in it's present state Slackware's mail subsystem is not suitable for more than several dozen users setup.

Hope someone will prove me wrong.

Cheers.
 
Old 10-13-2014, 07:12 PM   #38
Richard Cranium
Senior Member
 
Registered: Apr 2009
Location: McKinney, Texas
Distribution: Slackware64 15.0
Posts: 3,858

Rep: Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225
I use getmail, dovecot and procmail. I have 2 users.
 
Old 10-14-2014, 12:36 AM   #39
kikinovak
MLED Founder
 
Registered: Jun 2011
Location: Montpezat (South France)
Distribution: CentOS, OpenSUSE
Posts: 3,453

Rep: Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154
Quote:
Originally Posted by ivandi View Post
Sendmail, c'est spécial

At least exim supports mbx and has a human readable config. I am doing my best to keep compatible, but in it's present state Slackware's mail subsystem is not suitable for more than several dozen users setup.

Hope someone will prove me wrong.

Cheers.
I'm happily using Postfix and Dovecot.

http://www.microlinux.fr/slackware/L...Mail-HOWTO.txt
 
Old 12-13-2014, 02:13 PM   #40
ivandi
Member
 
Registered: Jul 2009
Location: Québec, Canada
Distribution: CRUX, Debian
Posts: 528

Original Poster
Rep: Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866
The recent discussion about PAM revived my interest in this project. So I did a clean install of the current (skipped only KDE) and pamified it. Did some cleanup and recompiled more stuff that uses pam or kerberos. The process went flawlessly. XFCE, xdm, xlock, network-manager, Console-kit, polkit ... work as expected. The default authentication method is pam_unix (shadow) so nothing changes for the user
Code:
auth		required	pam_unix.so		nullok
account		required	pam_unix.so
session		optional	pam_ck_connector.so	nox11
session		required	pam_unix.so
password	required	pam_unix.so		nullok
The number of packages that have to be recompiled is considerable and growing. I think we are close to 14.2 release so my intention is to maintain this stuff until the the start of the next development cycle. If Pat considers PAM for Slackware 15 this project is a good starting point.

BTW this link http://hashbangbash.com/downloads/pam/ seems to be dead. Does somebody know what's going on with VBatts project.

Cheers
 
2 members found this post helpful.
Old 12-13-2014, 04:18 PM   #41
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,097

Rep: Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174
I just read this on his twitter, dunno really if related (hashbangbash.com is his own domain/homepage): I suppose you can try pinging him on freenode or write a message (as written here).

If anybody needs something from that repository, here is a mirror (updated at the beginning of october).
 
Old 12-14-2014, 06:36 AM   #42
vbatts
Member
 
Registered: Jun 2005
Location: Raleigh, NC, USA
Distribution: slackware
Posts: 88

Rep: Reputation: 63
Quote:
Originally Posted by ivandi View Post
BTW this link http://hashbangbash.com/downloads/pam/ seems to be dead. Does somebody know what's going on with VBatts project.
Terribly sorry. Dumb VPS project went flakey and I haven't been able to migrate cleanly to another provider yet.
 
Old 12-14-2014, 07:05 AM   #43
ReaperX7
LQ Guru
 
Registered: Jul 2011
Location: California
Distribution: Slackware64-15.0 Multilib
Posts: 6,558
Blog Entries: 15

Rep: Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097
Nice work ivandi! You probably should add package kmod to the list. Kmod does have a tool that uses PAM if available.

If you redo any Slackbuilds for SBo, it might be useful to name them with the *-pam.SlackBuild schema. Most likely several Slackbuild scripts will need PAM enabling modifications.
 
Old 12-16-2014, 12:06 PM   #44
vbatts
Member
 
Registered: Jun 2005
Location: Raleigh, NC, USA
Distribution: slackware
Posts: 88

Rep: Reputation: 63
http://www.hashbangbash.com/downloads/pam/ is back online. Sorry for the inconvenience. Not all parts of the site are up, but that is.
 
Old 12-17-2014, 01:05 AM   #45
kikinovak
MLED Founder
 
Registered: Jun 2011
Location: Montpezat (South France)
Distribution: CentOS, OpenSUSE
Posts: 3,453

Rep: Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154
@vbatts: is there any chance you might put up a package repository for a PAM-ified Slackware stable? On a 1-to-10-scale, this would be 12-helpful.

Cheers,

Niki
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Managing multiple kerberos/ADS realms edgood1 Linux - Software 0 06-09-2009 02:44 PM
ADS / winbind / samba / kerberos HELP!!! jsheffie Red Hat 5 08-16-2006 09:01 AM
Samba, Kerberos and ADS problems deadlock Linux - Networking 0 01-26-2006 11:27 AM
suse9.1client W2k ADS kerberos and pam fatcake Linux - Networking 1 06-09-2005 01:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 05:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration