PAM-PKCS#11 - GDM login without clicking on username

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

PAM-PKCS#11 - GDM login without clicking on username

Sebastian Stolz
Hello,

i'm using pam_pkcs11 on Ubuntu 10.04 (GDM Login).

The following line i have added to /etc/pam.d/gdm:

auth    sufficient      pam_pkcs11.so
config_file=/etc/pam_pkcs11/pam_pkcs11.conf

is it possible configuring pam to get the username from pam_pkcs11
(mapper) without clicking on username or
typing it in (su / console login)



kind regards

Sebastian
_______________________________________________
opensc-user mailing list
[hidden email]
http://www.opensc-project.org/mailman/listinfo/opensc-user
Reply | Threaded
Open this post in threaded view
|

Re: PAM-PKCS#11 - GDM login without clicking on username

Ludovic Rousseau
2010/8/17 Sebastian Stolz <[hidden email]>:
> Hello,

Hello,

Sorry for the delay.

> i'm using pam_pkcs11 on Ubuntu 10.04 (GDM Login).
>
> The following line i have added to /etc/pam.d/gdm:
>
> auth    sufficient      pam_pkcs11.so
> config_file=/etc/pam_pkcs11/pam_pkcs11.conf
>
> is it possible configuring pam to get the username from pam_pkcs11
> (mapper) without clicking on username or
> typing it in (su / console login)

pam_pkcs11 can get the login name from the card. But I guess gdm will
not call the PAM stack if no login is given/selected.

I tried with login (text login on the console) and PAM is not called
if I just hit the Enter key.
I tried with a test application (blank provided with the Linux PAM
sources) and I can authenticate without giving my login:

$ LANG=C ./blank
==> called pam_start()
  got: `Success'
total time: 0,11289 seconds
Please insert your Smart card or enter your username.
login:                               <<<<<<<<<<<< no login given here.
just enter.
Found the Smart card.
Welcome Ludovic Rousseau (User PIN)!
Smart card PIN:
==> called pam_authenticate()
  got: `Success'
total time: 4,944448 seconds
==> called pam_end()
  got: `Success'
total time: 4,944913 seconds

You should report the feature request to gdm.

Bye

--
 Dr. Ludovic Rousseau
_______________________________________________
opensc-user mailing list
[hidden email]
http://www.opensc-project.org/mailman/listinfo/opensc-user