PAM Configuration
Linux systems rely on PAM (Pluggable Authentication Modules) to manage authentication, authorization, and account management. Secure PAM configurations are critical to mitigating brute-force attacks, unauthorized access, and session risks. This section details how to enforce multi-factor authentication (MFA), account lockouts, and session management using PAM modules.
Multi-Factor Authentication (MFA)¶
Enforce MFA by integrating PAM modules that require users to authenticate with multiple factors (e.g., password + token, biometric + hardware key). Common modules include:
- pam_u2f.so (USB-based FIDO2 keys)
- pam_totp.so (Generic TOTP support)
Example configuration for TOTP in /etc/pam.d/common-auth:
Example configuration for U2F in /etc/pam.d/common-auth:
Notes:
- Install required packages (e.g., google-authenticator, libpam-u2f).
- Users must run google-authenticator to generate TOTP secrets before configuring MFA.
- Place MFA modules before pam_unix.so to ensure they are enforced.
Account Lockout Mechanisms¶
Prevent brute-force attacks by configuring account lockouts using pam_faillock. pam_tally2 is deprecated and should not be used in modern systems.
Example configuration in /etc/pam.d/common-auth:
auth required pam_faillock.so preauth audit silent deny 6 unlock_time 300
auth [success=1 default=ignore] pam_faillock.so authsucc
Example configuration in /etc/pam.d/common-account:
Key settings:
- deny 6: Lock the account after 6 failed attempts.
- unlock_time 300: Lockout duration (300 seconds).
Check lockout status:
Session Management¶
Control resource limits and environment variables during user sessions using modules like pam_limits and pam_env.
Example session limits in /etc/security/limits.conf:
Example environment variable setup in /etc/pam.d/common-session:
Additional tips:
- Use pam_unix.so for session tracking.
- Combine with pam_selinux.so (if SELinux is enabled) for context-aware session management.
Auditing and Monitoring¶
Audit PAM events to detect suspicious activity. Use auditd to track authentication attempts:
Example audit rule to monitor PAM events:
Check audit logs:
Log locations:
- Authentication logs: /var/log/secure (RHEL/CentOS) or /var/log/auth.log (Debian/Ubuntu).
- Use journalctl -u systemd-logind for systemd-based systems.
Key takeaways¶
- Enforce MFA using
pam_totporpam_u2fand ensure they precedepam_unix. - Implement account lockouts with
pam_faillockto limit brute-force attempts. - Manage sessions via
pam_limitsto restrict resource usage andpam_envfor environment variables. - Audit PAM events with
auditdand monitor logs in/var/log/secureor/var/log/auth.log. - Always test configurations in non-production environments to avoid unintended access denial.