133 lines
4.3 KiB
Groff
133 lines
4.3 KiB
Groff
.\" Copyright (c) 2001 Mark R V Murray
|
|
.\" All rights reserved.
|
|
.\" Copyright (c) 2001 Networks Associates Technology, Inc.
|
|
.\" All rights reserved.
|
|
.\"
|
|
.\" This software was developed for the FreeBSD Project by ThinkSec AS and
|
|
.\" NAI Labs, the Security Research Division of Network Associates, Inc.
|
|
.\" under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"), as part of the
|
|
.\" DARPA CHATS research program.
|
|
.\"
|
|
.\" Redistribution and use in source and binary forms, with or without
|
|
.\" modification, are permitted provided that the following conditions
|
|
.\" are met:
|
|
.\" 1. Redistributions of source code must retain the above copyright
|
|
.\" notice, this list of conditions and the following disclaimer.
|
|
.\" 2. Redistributions in binary form must reproduce the above copyright
|
|
.\" notice, this list of conditions and the following disclaimer in the
|
|
.\" documentation and/or other materials provided with the distribution.
|
|
.\" 3. The name of the author may not be used to endorse or promote
|
|
.\" products derived from this software without specific prior written
|
|
.\" permission.
|
|
.\"
|
|
.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
|
|
.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
.\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
|
|
.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
.\" SUCH DAMAGE.
|
|
.\"
|
|
.\" %FreeBSD: src/lib/libpam/modules/pam_ssh/pam_ssh.8,v 1.8.2.2 2002/07/03 21:41:30 des Exp %
|
|
.\"
|
|
.\" $FreeBSD$
|
|
.Dd November 26, 2001
|
|
.Dt PAM_SSH 8
|
|
.Os
|
|
.Sh ̾¾Î
|
|
.Nm pam_ssh
|
|
.Nd SSH PAM ¥â¥¸¥å¡¼¥ë
|
|
.Sh ½ñ¼°
|
|
.Op Ar service-name
|
|
.Ar module-type
|
|
.Ar control-flag
|
|
.Pa pam_ssh
|
|
.Op Ar options
|
|
.Sh ²òÀâ
|
|
.Nm
|
|
¤Ï PAM ÍÑ SSH ǧ¾Ú¥µ¡¼¥Ó¥¹¥â¥¸¥å¡¼¥ë¤Ç¤¢¤ê¡¢
|
|
ǧ¾Ú¤È¥»¥Ã¥·¥ç¥ó´ÉÍý¤Î PAM ¤Î 2 ¤Ä¤Î¥«¥Æ¥´¥ê¤Ø¤Îµ¡Ç½¤òÄ󶡤·¤Þ¤¹¡£
|
|
.Ar module-type
|
|
¥Ñ¥é¥á¡¼¥¿Ãæ¤Ç¤Ï
|
|
.Dq Li auth
|
|
.Dq Li session
|
|
¤Èɽ¸½¤µ¤ì¤Þ¤¹¡£
|
|
¤½¤Î¾¤ÎʬÌî¤Î¤Ë¤Ï¡¢¥Ì¥ë´Ø¿ô¤òÄ󶡤·¤Þ¤¹¡£
|
|
.Ss SSH ǧ¾Ú¥â¥¸¥å¡¼¥ë
|
|
SSH
|
|
ǧ¾Ú¥³¥ó¥Ý¡¼¥Í¥ó¥È¤Ï¡¢¥æ¡¼¥¶¤ÎËܿͳÎǧ¤Î´Ø¿ô
|
|
.Pq Fn pam_sm_authenticate
|
|
¤òÄ󶡤·¤Þ¤¹¡£´Ø¿ô¤Ï¡¢¥æ¡¼¥¶¤ËÂФ·¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÍ׵ᤷ¡¢
|
|
¤½¤ì¤ò»È¤Ã¤Æ³ºÅö¥æ¡¼¥¶¤Î SSH ¥¡¼¤¬²òÆÉ¤Ç¤¤ë¤«¤ò³Î¤«¤á¤Þ¤¹¡£
|
|
.Pp
|
|
¤³¤Îǧ¾Ú¥â¥¸¥å¡¼¥ë¤Ç¤Ï¡¢¼¡¤Ë¼¨¤¹¥ª¥×¥·¥ç¥ó¤¬ÍøÍѤǤ¤Þ¤¹¡£
|
|
.Bl -tag -width ".Cm use_first_pass"
|
|
.It Cm debug
|
|
¥Ç¥Ð¥Ã¥¯¾ðÊó¤ò
|
|
.Dv LOG_DEBUG
|
|
¥ì¥Ù¥ë¤Ç
|
|
.Xr syslog 3
|
|
¤ÇµÏ¿¤·¤Þ¤¹¡£
|
|
.It Cm use_first_pass
|
|
¤³¤Îǧ¾Ú¥â¥¸¥å¡¼¥ë¤¬¥¹¥¿¥Ã¥¯Ãæ¤ÇÀèÆ¬¤Ë¤Ï¤Ê¤¤¤È¤¤Ë¡¢
|
|
¤³¤ì¤è¤ê¤âÁ°¤Î¥â¥¸¥å¡¼¥ë¤¬¡¢
|
|
¥æ¡¼¥¶¤Î¥Ñ¥¹¥ï¡¼¥É¤òÆþ¼ê¤·¤Æ¤¤¤ë¾ì¹ç¤Ë¤Ï¡¢
|
|
¤½¤Î¥Ñ¥¹¥ï¡¼¥É¤ò¥æ¡¼¥¶¤Îǧ¾Ú¤ËÍøÍѤ·¤Þ¤¹¡£
|
|
¤â¤·Ç§¾Ú¤Ë¼ºÇÔ¤¹¤ë¤È¡¢¤³¤Îǧ¾Ú¥â¥¸¥å¡¼¥ë¤Ï
|
|
¥Ñ¥¹¥ï¡¼¥É¤ÎÍ×µá¤ò¤»¤º¤Ë¡¢¼ºÇÔ¤òÊÖ¤·¤Þ¤¹¡£
|
|
¤³¤Îǧ¾Ú¥â¥¸¥å¡¼¥ë¤¬¥¹¥¿¥Ã¥¯Ãæ¤ÇÀèÆ¬¤Ë¤¢¤ë¾ì¹ç¡¢
|
|
¤â¤·¤¯¤Ï¡¢¤³¤ì¤è¤êÁ°¤Î¥â¥¸¥å¡¼¥ë¤¬¥æ¡¼¥¶¤Î¥Ñ¥¹¥ï¡¼¥É¤ò
|
|
Æþ¼ê¤·¤Ê¤«¤Ã¤¿¾ì¹ç¤Ë¤Ï¡¢¤³¤Î¥ª¥×¥·¥ç¥ó¤Ï̵¸ú¤Ë¤Ê¤ê¤Þ¤¹¡£
|
|
.It Cm try_first_pass
|
|
¤³¤Î¥ª¥×¥·¥ç¥ó¤Ï
|
|
.Cm use_first_pass
|
|
¥ª¥×¥·¥ç¥ó¤Ë»÷¤Æ¤¤¤Þ¤¹¤¬¡¢
|
|
Á°¤Î¥â¥¸¥å¡¼¥ë¤ÇÆÀ¤¿¥Ñ¥¹¥ï¡¼¥É¤¬¼ºÇÔ¤·¤¿¾ì¹ç¤Ï
|
|
¥æ¡¼¥¶¤Ë¾¤Î¥Ñ¥¹¥ï¡¼¥É¤òÍ׵ᤷ¤Þ¤¹¡£
|
|
.El
|
|
.Ss SSH ¥»¥Ã¥·¥ç¥ó´ÉÍý¥â¥¸¥å¡¼¥ë
|
|
SSH
|
|
¥»¥Ã¥·¥ç¥ó´ÉÍý¥³¥ó¥Ý¡¼¥Í¥ó¥È¤Ï
|
|
¥»¥Ã¥·¥ç¥ó¤Î³«»Ï
|
|
.Pq Fn pam_sm_open_session
|
|
¤È½ªÎ»
|
|
.Pq Fn pam_sm_close_session
|
|
¤Î´Ø¿ô¤òÄ󶡤·¤Þ¤¹¡£
|
|
.Fn pam_sm_open_session
|
|
´Ø¿ô¤Ï SSH ¥¨¡¼¥¸¥§¥ó¥È¤ò³«»Ï¤µ¤»¡¢
|
|
ǧ¾Ú²áÄø¤Ç²òÆÉ¤µ¤ì¤¿ÈëÌ©¸°¤ò¥¨¡¼¥¸¥§¥ó¥È¤ËÅϤ·¤Þ¤¹¡£
|
|
¤½¤·¤Æ¡¢¥¨¡¼¥¸¥§¥ó¥È¤¬¼¨¤·¤¿´Ä¶ÊÑ¿ô¤ò¥»¥Ã¥È¤·¤Þ¤¹¡£
|
|
.Fn pam_sm_close_session
|
|
´Ø¿ô¤ÏÁ°¤Ë³«»Ï¤µ¤ì¤¿ SSH ¥¨¡¼¥¸¥§¥ó¥È¤Ë
|
|
.Dv SIGTERM
|
|
¤òÁ÷¤Ã¤Æ½ªÎ»¤µ¤»¤Þ¤¹¡£
|
|
.Pp
|
|
¤³¤Î¥»¥Ã¥·¥ç¥ó´ÉÍý¥â¥¸¥å¡¼¥ë¤Ç¤Ï¡¢¼¡¤Ë¼¨¤¹¥ª¥×¥·¥ç¥ó¤¬»ÈÍѤǤ¤Þ¤¹¡£
|
|
.Bl -tag -width ".Cm use_first_pass"
|
|
.It Cm debug
|
|
¥Ç¥Ð¥Ã¥¯¾ðÊó¤ò
|
|
.Dv LOG_DEBUG
|
|
¥ì¥Ù¥ë¤Ç
|
|
.Xr syslog 3
|
|
¤ÇµÏ¿¤·¤Þ¤¹¡£
|
|
.El
|
|
.Sh ´ØÏ¢¥Õ¥¡¥¤¥ë
|
|
.Bl -tag -width ".Pa $HOME/.ssh2/id_dsa_*" -compact
|
|
.It Pa $HOME/.ssh/identity
|
|
SSH1/OpenSSH RSA ¸°¡£
|
|
.It Pa $HOME/.ssh/id_dsa
|
|
OpenSSH DSA ¸°¡£
|
|
.It Pa $HOME/.ssh2/id_rsa_*
|
|
SSH2 RSA ¸°¡£
|
|
.It Pa $HOME/.ssh2/id_dsa_*
|
|
SSH2 DSA ¸°¡£
|
|
.El
|
|
.Sh ´ØÏ¢¹àÌÜ
|
|
.Xr ssh-agent 1 ,
|
|
.Xr syslog 3 ,
|
|
.Xr pam.conf 5 ,
|
|
.Xr pam 8
|