#include <strings.h>
#include <syslog.h>
#include <security/pam_appl.h>
#include <security/pam_modules.h>
static void
debug(pam_handle_t *pamh, int flags, int argc, const char **argv, char *mod)
{
const char *user;
const char *service;
if (argc < 1 || strcmp(argv[0], "debug") != 0)
return;
(void) pam_get_item(pamh, PAM_SERVICE, (const void **)&service);
(void) pam_get_item(pamh, PAM_USER, (const void **)&user);
syslog(LOG_AUTH | LOG_DEBUG, "%s pam_deny:%s(%x) for %s",
service ? service : "No Service Specified", mod, flags,
user ? user : "No User Specified");
}
int
pam_sm_authenticate(pam_handle_t *pamh, int flags, int argc, const char **argv)
{
debug(pamh, flags, argc, argv, "pam_sm_authenticate");
return (PAM_AUTH_ERR);
}
int
pam_sm_setcred(pam_handle_t *pamh, int flags, int argc, const char **argv)
{
debug(pamh, flags, argc, argv, "pam_sm_setcred");
return (PAM_CRED_ERR);
}
int
pam_sm_acct_mgmt(pam_handle_t *pamh, int flags, int argc, const char **argv)
{
debug(pamh, flags, argc, argv, "pam_sm_acct_mgmt");
return (PAM_ACCT_EXPIRED);
}
int
pam_sm_open_session(pam_handle_t *pamh, int flags, int argc, const char **argv)
{
debug(pamh, flags, argc, argv, "pam_sm_open_session");
return (PAM_SESSION_ERR);
}
int
pam_sm_close_session(pam_handle_t *pamh, int flags, int argc, const char **argv)
{
debug(pamh, flags, argc, argv, "pam_sm_close_session");
return (PAM_SESSION_ERR);
}
int
pam_sm_chauthtok(pam_handle_t *pamh, int flags, int argc, const char **argv)
{
debug(pamh, flags, argc, argv, "pam_sm_chauthtok");
return (PAM_AUTHTOK_ERR);
}