New options added to sp_ldapadmin  Enabling PAM in Adaptive Server

Chapter 7: Security Changes

Pluggable Authentication Module (PAM) support

Adaptive Server version 12.5.2 introduces Pluggable Authentication Modules (PAM) support, which allows multiple authentication service modules to be stacked and made available without modifying the applications that require the authentication.

PAM integrates Adaptive Server more closely with Sun and Linux operating systems and simplifies the management and administration of user accounts and authentication mechanisms. PAM reduces the total cost of ownership through this closer integration. An additional benefit is that users can customize or write their own authentication and authorization modules.

NotePAM support is currently available on Linux and on Solaris platforms. For more information on PAM user authentication, see your operating system documentation.

Figure 7-1 shows how PAM works:

Figure 7-1: PAM architecture

Adaptive Server passes the login name and credentials obtained from the login packet to the PAM API. PAM loads a service provider module as specified in the Operating System configuration files and calls appropriate functions to complete the authentication process.





Copyright © 2004. Sybase Inc. All rights reserved. Enabling PAM in Adaptive Server

View this book as PDF