From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id E41121FF0AA for ; Tue, 06 Oct 2026 11:23:53 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 552142159E; Tue, 06 Oct 2026 11:23:50 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1791278624; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding; bh=6mitF/S9XfhWGV14y95+dXG+9V7Ml6iEohYsbJ9QyKY=; b=otiMjvijO3bjF5cR/6cMTUCeF5bdXRlDijw2H5ThdU3GAajOGevQkGhM74eMa6+szbOqmL uL4vuN9B6bwf+qPbOR9HGO0DoZuO0jc/kyrXoEgTLe+9Lx4WizbdG6upeOtLqpo6s6qI/n QBeMMbAK1mwhMqWJ3Cp7YtDgfxAvwGZtAwAh4mQFka7ekb8hT1CrZigBIvhDfUCnAyGCYD g1qxVCh+qc03NaDMp+XkXlSl6nZ/817Kyv1U5APTTL0nS8TF6ay3avi+1ao15JmJbXG6BZ bzbDxcT2QI5tzeXa8Te52gUigcVAdaT6IhIh0VXlKi64QvTzvfuDDNJKAhUp5g== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH docs] fix #5371: user management: document the PAM service of the PAM realm Date: Tue, 6 Oct 2026 09:23:40 +0000 Message-ID: <20261006092340.7-1-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.142 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: 5LTXV7U3C7UP7MVNXNSLPT6LOM5YHDPN X-Message-ID-Hash: 5LTXV7U3C7UP7MVNXNSLPT6LOM5YHDPN X-MailFrom: me@dualfroz.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Since pve-access-control commit 01f191c ("fix #1670: change PAM service name to project specific name"), the PAM realm authenticates with the PAM service name 'proxmox-ve-auth'. This allows changing the PAM configuration for logins to Proxmox VE only, for example to not allow logins of users with an empty password, which the default 'nullok' option of pam_unix in common-auth does. But this is only mentioned in the commit message. Document the service name, the fallback to the 'other' service if no such configuration exists, and that this configuration is local to each node, like the system users. Signed-off-by: Michal Fox --- Notes: checked in a Debian trixie container with the PAM realm plugin: without /etc/pam.d/proxmox-ve-auth, a user with an empty password could log in with any password, as in the bug. with a copy of /etc/pam.d/other, with common-auth inlined without 'nullok', this login failed, while the one of a user with a password still worked. rendered the chapter with asciidoc, without new warnings. pveum.adoc | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pveum.adoc b/pveum.adoc index d089cb6..49cfd68 100644 --- a/pveum.adoc +++ b/pveum.adoc @@ -184,6 +184,14 @@ endpoint only apply to the local node and not cluster-wide. Even though {pve} has a multi-master design, using different passwords for different nodes can still offer a security benefit. +{pve} uses the PAM service name `proxmox-ve-auth` to authenticate users of this +realm. This allows changing the PAM configuration only for logins to {pve}, +without affecting other services like the login on the console or via SSH, by +creating the file `/etc/pam.d/proxmox-ve-auth`. If this file does not exist, +PAM uses the configuration of the `other` service, so a copy of +`/etc/pam.d/other` is a good starting point. Like the system users, this +configuration is local to each node. + In terms of configurability, an administrator can choose to require two-factor authentication with logins from the realm and to set the realm as the default authentication realm. -- 2.43.0