Subject: Re: PAM and su -K
To: Greywolf <greywolf@starwolf.com>
From: Roland Dowdeswell <elric@imrryr.org>
List: tech-userlevel
Date: 01/22/2005 15:17:06
On 1106340433 seconds since the Beginning of the UNIX epoch
Greywolf wrote:
>
>[Thus spake Martin Husemann ("MH: ") 9:06am...]
>
>MH: On Thu, Jan 20, 2005 at 10:09:22PM -0800, Greywolf wrote:
>MH: > So PAM is going to force dynamic loading in the root utilities, thus
>MH: > preventing one from building one's /bin and /sbin statically
>MH:
>MH: This does not strictly follow from what Jason said. If it were the case
>MH: it would even prevent us from creating install media ;-)
>
>That's because you don't need authentication programs on the install
>media.

Well, actually it does not follow because there is no reason to
suppose that one could not build a static libpam.a which contains
only a set of predefined modules in a certain order.  When I looked
at Linux pam this was possible.  Do not make the mistake of presuming
that because pam can dynamically load modules that its only mode
of operation ever will be that.

--
    Roland Dowdeswell                      http://www.Imrryr.ORG/~elric/