Security Handbook/PAM

This section is on further securing Pluggable Authentication Modules (PAM). == PAM == PAM is a suite of shared libraries that provide an alternative way providing user authentication in programs. The  USE flag is turned on by default. Thus the PAM settings on Gentoo Linux are pretty reasonable, but there is always room for improvement.

First install to allow password policies to be set:

This will add the cracklib which will ensure that the user passwords are at least 8 characters and contain a minimum of 2 digits, 2 other characters, and are more than 3 characters different from the last password. Check the PAM cracklib documentation for more options.

Every service not configured with a PAM file in will use the rules in. The defaults are set to deny, as they should be.

Also, can be added to generate more elaborate logging. And pam_limits can be used, which is controlled by. See the section for more on these settings.