Subject: Re: integrating PAM
To: Peter Seebach <seebs@plethora.net>
From: Bill Studenmund <wrstuden@netbsd.org>
List: current-users
Date: 01/23/2003 17:10:00
On Thu, 23 Jan 2003, Peter Seebach wrote:

> In message <Pine.NEB.4.33.0301231538260.16372-100000@vespasia.home-net.icnt.net
> >, Bill Studenmund writes:
> >Why do you really care so much about not using PAM?
>
> Space efficiency on small systems, NIH, etcetera.  Some emotional reasons,
> some mild technical ones.  In particular, I'm not sure some of the BSD Auth
> features can be made available through PAM - there's no good way for a
> user app to get access to any extra data that PAM doesn't have a good model
> for.

Please elaborate on the extra data bit. If you could look into it, it
would help.

We want to start with PAM as we can put BSD Auth on top much more easily
than PAM over BSD Auth; getting PAM puts us on a path that will get us
both.

If thought PAM won't do all BSD Auth needs, then we need to do a different
module method (that will have a PAM interface), and build BSD Auth on top
of that. Or we need to add to "PAM".

Take care,

Bill