On Tue, 17 Dec 2024, Michal Sekletar wrote: > On Tue, Dec 17, 2024 at 5:40 AM Damien Miller <djm@xxxxxxxxxxx> wrote: > > > User-specified environment variables are not propogated to the > > environment where sshd invokes PAM modules because the SSH protocol > > sends them at the time a session is opened, well after authentication > > has completed. At best, they could be made available to the PAM > > session modules but there's no way to make user-specified environment > > available to auth and account modules. > > I am interested in pam_systemd.so which is a session module. Hence, > would you accept a patch that exposes these variables during this > phase of a session setup? We could potentially allow-list some variables, but I'd like to get some input from people who (for example) maintain PAM for distributions on what is acceptable. -d _______________________________________________ openssh-unix-dev mailing list openssh-unix-dev@xxxxxxxxxxx https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev