Skip to content

PAM Configuration

Linux systems rely on PAM (Pluggable Authentication Modules) to manage authentication, authorization, and account management. Secure PAM configurations are critical to mitigating brute-force attacks, unauthorized access, and session risks. This section details how to enforce multi-factor authentication (MFA), account lockouts, and session management using PAM modules.


Multi-Factor Authentication (MFA)

Enforce MFA by integrating PAM modules that require users to authenticate with multiple factors (e.g., password + token, biometric + hardware key). Common modules include:
- pam_u2f.so (USB-based FIDO2 keys)
- pam_totp.so (Generic TOTP support)

Example configuration for TOTP in /etc/pam.d/common-auth:

auth required pam_totp.so
auth required pam_unix.so

Example configuration for U2F in /etc/pam.d/common-auth:

auth required pam_u2f.so
auth required pam_unix.so

Notes:
- Install required packages (e.g., google-authenticator, libpam-u2f).
- Users must run google-authenticator to generate TOTP secrets before configuring MFA.
- Place MFA modules before pam_unix.so to ensure they are enforced.


Account Lockout Mechanisms

Prevent brute-force attacks by configuring account lockouts using pam_faillock. pam_tally2 is deprecated and should not be used in modern systems.

Example configuration in /etc/pam.d/common-auth:

auth required pam_faillock.so preauth audit silent deny 6 unlock_time 300
auth [success=1 default=ignore] pam_faillock.so authsucc

Example configuration in /etc/pam.d/common-account:

account required pam_faillock.so

Key settings:
- deny 6: Lock the account after 6 failed attempts.
- unlock_time 300: Lockout duration (300 seconds).

Check lockout status:

faillock --user <username>


Session Management

Control resource limits and environment variables during user sessions using modules like pam_limits and pam_env.

Example session limits in /etc/security/limits.conf:

<username> soft nofile 2048
<username> hard nofile 4096

Example environment variable setup in /etc/pam.d/common-session:

session required pam_env.so
session required pam_limits.so

Additional tips:
- Use pam_unix.so for session tracking.
- Combine with pam_selinux.so (if SELinux is enabled) for context-aware session management.


Auditing and Monitoring

Audit PAM events to detect suspicious activity. Use auditd to track authentication attempts:

Example audit rule to monitor PAM events:

auditctl -w /etc/pam.d/ -p wa -k pam_config
auditctl -w /var/log/secure -p r -k pam_logs

Check audit logs:

ausearch -k pam_config
ausearch -k pam_logs

Log locations:
- Authentication logs: /var/log/secure (RHEL/CentOS) or /var/log/auth.log (Debian/Ubuntu).
- Use journalctl -u systemd-logind for systemd-based systems.


Key takeaways

  • Enforce MFA using pam_totp or pam_u2f and ensure they precede pam_unix.
  • Implement account lockouts with pam_faillock to limit brute-force attempts.
  • Manage sessions via pam_limits to restrict resource usage and pam_env for environment variables.
  • Audit PAM events with auditd and monitor logs in /var/log/secure or /var/log/auth.log.
  • Always test configurations in non-production environments to avoid unintended access denial.