| [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] |
"Sam" == Sam Hartman <hartmans@xxxxxxx> writes:Hearing no comments whatsoever, I'll go fix this in Debian and submit a patch that can be ignored like all the rest.
The question is why does this module get to influence the return value at all in the setcred, chauthtok or close_session phase even though its return is ignored in the auth, open_session and first chauttok phase.
As a side note, I'm actually unclear on whether requiring modules
whose auth phase fails to return PAM_SUCCESS or PAM_IGNORE in the
setcred phase is a good idea. I thought one of the goals of the
frozen chain stuff was to make sure I didn't have to return the same
value in both phases. I had always assumed that this was intended to
avoid module authors having to keep the same state between calls. Yet
it seems that if I should return PAM_SUCCESS or PAM_IGNORE if my auth
phase called, I end up having all the complexity I did before, plus
the complexity of the frozen chain.
_______________________________________________ Pam-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/pam-list
[Home] [Kernel List] [Red Hat Install] [Linux for the blind] [Red Hat Watch List] [Gimp] [Kerberos: The Definitive Guide]
![]() |
![]() |