Re: pam and ftp

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, Sep 12, 2002 at 11:28:59PM +0200, ingo@fargonauten.de wrote:
> Hi Ed,
> 
> why don't you simply run one daemon per interface with slightly
> different configurations?

I've thought of this, but haven't quite figured out how to make this
happen cleanly.  The pam_listfile check against /etc/ftpusers is done
within the ftp pam module.  In order to use a different authentication
module, I think I need to modify the wu-ftpd source.  If I did this, I'd
have to do that every time Red Hat issues a patch or new release, and
this would get kind of ugly long-term.  If anybody simply upgraded the
ftp server without modifying the sources first, we'd suddenly have a
security hole.  I'd like to centralize the authentication checks in one
place if I can and isn't that what PAM is for?

-- 
Ed Wilts, Mounds View, MN, USA
mailto:ewilts@ewilts.org
Member #1, Red Hat Community Ambassador Program



_______________________________________________

Pam-list@redhat.com
https://listman.redhat.com/mailman/listinfo/pam-list

[Index of Archives]     [Fedora Users]     [Kernel]     [Red Hat Install]     [Linux for the blind]     [Gimp]

  Powered by Linux