# SM3: User authentication via PAM

**URL:** <https://forums.suse.com/t/sm3-user-authentication-via-pam/29657>\
**Category:** SUSE Multi Linux Manager\
**Created:** [April 11, 2017, 6:41pm UTC](https://forums.suse.com/t/sm3-user-authentication-via-pam/29657 "2017-04-11T18:41:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Albert](https://avatars.discourse-cdn.com/v4/letter/a/48db29/32.png) [@Albert](https://forums.suse.com/u/Albert)\
**Post date:** [April 11, 2017, 6:41pm UTC](https://forums.suse.com/t/sm3-user-authentication-via-pam/29657/1 "2017-04-11T18:41:15Z")

</div>

According to the Best Practices Guide, “Chapter 16. System Auditing and Security Management”, “To enable a user to authenticate against PAM, on the SUSE Manager Web interface go to the Create User page and select the checkbox labeled Pluggable Authentication Modules (PAM) positioned below the password and password confirmation fields.”.

Has anyone used this. The Create User page does NOT have a checkbox to enable PAM authentication. ![](https://ibin.co/3IiWet6DPpdQ.png)

---

<div class="post-metadata">

**Author:** ![dgersic](https://avatars.discourse-cdn.com/v4/letter/d/8491ac/32.png) [@dgersic](https://forums.suse.com/u/dgersic)\
**Post date:** [April 12, 2017, 4:41am UTC](https://forums.suse.com/t/sm3-user-authentication-via-pam/29657/2 "2017-04-12T04:41:02Z")

</div>

On Tue, 11 Apr 2017 15:44:02 +0000, achinayoung waubonsee wrote:  
[color=blue]

> According to the Best Practices Guide, “Chapter 16. System Auditing and  
> Security Management”, “To enable a user to authenticate against PAM, on  
> the SUSE Manager Web interface go to the Create User page and select the  
> checkbox labeled Pluggable Authentication Modules (PAM) positioned below  
> the password and password confirmation fields.”.
> 
> Has anyone used this. The Create User page does _NOT_ have a checkbox to  
> enable PAM authentication.[image: [https://ibin.co/3IiWet6DPpdQ.png]](https://ibin.co/3IiWet6DPpdQ.png)[/color]

Hm. I’m using PAM with SuMa at a customer. Works fine. It’s case  
sensitive in the user names, which was surprising, but other than that,  
no complaints.

My Create User page has a PAM checkbox.

–  
David Gersic  
Knowledge Partner [http://forums.microfocus.com](http://forums.microfocus.com)  
If you find this post helpful, please click on the star below.

---

<div class="post-metadata">

**Author:** ![pgurzick](https://avatars.discourse-cdn.com/v4/letter/p/a87d85/32.png) [@pgurzick](https://forums.suse.com/u/pgurzick)\
**Post date:** [April 12, 2017, 9:53am UTC](https://forums.suse.com/t/sm3-user-authentication-via-pam/29657/3 "2017-04-12T09:53:23Z")

</div>

[QUOTE=achinayoung\_waubonsee;37437]According to the Best Practices Guide, “Chapter 16. System Auditing and Security Management”, “To enable a user to authenticate against PAM, on the SUSE Manager Web interface go to the Create User page and select the checkbox labeled Pluggable Authentication Modules (PAM) positioned below the password and password confirmation fields.”.

Has anyone used this. The Create User page does NOT have a checkbox to enable PAM authentication. ![](https://ibin.co/3IiWet6DPpdQ.png)[/QUOTE]

You have to do the folllowing:  
echo “pam\_auth\_service = susemanager” \>\> /etc/rhn/rhn.conf

and then  
echo “#%PAM-1.0” \> /etc/pam.d/susemanager  
echo “auth include common-auth” \>\> /etc/pam.d/susemanager  
echo “account include common-account” \>\> /etc/pam.d/susemanager  
echo “password include common-password” \>\> /etc/pam.d/susemanager  
echo “session include common-session” \>\> /etc/pam.d/susemanager

restart  
then the option will now be available.

---

<div class="post-metadata">

**Author:** ![Albert](https://avatars.discourse-cdn.com/v4/letter/a/48db29/32.png) [@Albert](https://forums.suse.com/u/Albert)\
**Post date:** [April 13, 2017, 8:30pm UTC](https://forums.suse.com/t/sm3-user-authentication-via-pam/29657/4 "2017-04-13T20:30:33Z")

</div>

Thanks. That worked!
