[Freeipa-devel] [PATCH] first version of LOCAL pam backend

Simo Sorce ssorce at redhat.com
Mon Mar 2 14:46:31 UTC 2009


On Mon, 2009-03-02 at 09:35 -0500, Rob Crittenden wrote:
> Sumit Bose wrote:
> > Hi,
> > 
> > please find enclosed a first version of the pam backend for the LOCAL
> > domain.
> > 
> > - currently authenticate, chauthtok and acct_mgmt work
> > - so far only glibc compatible sha512 passwords are used
> > - NSS is used for sha512 and random number generation
> > - currently I use direct libldb calls to be able to test things, I will
> > change this when Simo's work on sysdb is done
> > 
> > bye,
> > Sumit
> 
> Just a really minor review...
> 
> - Could the be used in a multi-threaded env? Do you need locking around 
> nspr_nss_init()?

Nothing is thread safe in sssd, so no.

> - in gen_salt() it looks like buflen is unused
> - looks like you used TAB at least once

Sumit,
please check these 2 and post a patch if needed.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York




More information about the Freeipa-devel mailing list