[tac_plus] PAM for enable authentication

Christopher J. Pilkington cjp at 0x1.net
Mon Feb 10 21:29:29 UTC 2014


I'm attempting to use tac_plus for authentication for our firewalls
which do not support the "priv-lvl" method of auto-enabling users.

We normally use PAM for authentication.

We thought of doing enable = nopassword, but there is an attack where a
user can enable as themselves, then disable, then enable as another
user without a password.

I see enable only supports file, cleartext, nopassword or des. Would it
be possible for it to support PAM?

Thanks,
-cjp



More information about the tac_plus mailing list