# PAM question

**URL:** <https://forums.suse.com/t/pam-question/25006>\
**Category:** SLES Configure-Administer\
**Created:** [January 21, 2014, 9:35pm UTC](https://forums.suse.com/t/pam-question/25006 "2014-01-21T21:35:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://forums.suse.com/u/cisaksen)\
**Post date:** [January 21, 2014, 9:35pm UTC](https://forums.suse.com/t/pam-question/25006/1 "2014-01-21T21:35:30Z")

</div>

Using SUSE 11 sp3 for VMWARE -

Samba/winbind I have followed several examples about how to setup a SAMBA share using AD authentication but not allowing AD users the ability to log in by any means. I have setup the samba share with the ad users explicitly set in the samba.conf. Then I would go into /etc/pam.d/common-auth and add after “auth required pam\_winbind.so use\_first\_pass” [COLOR="#800080"]require\_membership\_of=[sid of domain admins][/COLOR] and this works except!!  
At the top of the common-auth states: # This file is autogenerated by pam-config. All changes will be overwritten and they do.

So where would I set the require\_membership\_of= to restrict log in capabilities. Or is there a way to prevent pam-conf from overriding any changes, or is there a way to set them in pam-conf.

Thanks

---

<div class="post-metadata">

**Author:** ![mikewillis](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@mikewillis](https://forums.suse.com/u/mikewillis)\
**Post date:** [January 25, 2014, 6:19pm UTC](https://forums.suse.com/t/pam-question/25006/2 "2014-01-25T18:19:57Z")

</div>

Well no one else has offered an answer yet, so I’m going to suggest one approach you could take would be to make /etc/pam.d/common-auth a file rather than a symlink to /etc/pam.d/common-auth-pc. That way pam-config won’t change it.

`
$ cd /etc/pam.d/
$ unlink common-auth
$ grep -v ^# common-auth-pc > common-auth`
