FreeBSD Manual Pages
PAM_WORKER(8) System Manager's Manual PAM_WORKER(8) NAME pam_worker -- PAM authentication helper for use with pam_exec(8) SYNOPSIS pam_worker profile DESCRIPTION The pam_worker utility is a helper program designed to perform PAM (Plug- gable Authentication Modules) authentication for a given profile. It is intended to be used in combination with pam_exec(8) to allow non-setuid programs to perform authentication. pam_worker is installed with the setuid bit set, which allows it to perform privileged operations required for PAM authentication. This design enables non-privileged programs to authenticate users through PAM by invoking pam_worker as a setuid helper. The utility reads the user's password from standard input and uses it to authenticate against the specified PAM profile. SECURITY CONSIDERATIONS Since pam_worker is installed with the setuid bit set, it is critical to ensure proper security controls are in place: * pam_worker must only be invoked by trusted programs (typically via pam_exec(8)) * The PAM profile used must be carefully configured to prevent unautho- rized access * The pam_worker binary itself must be protected from tampering When used with pam_exec(8), the pam_worker utility should be invoked with appropriate restrictions to prevent privilege escalation. OPTIONS profile The name of the PAM profile to use for authentication. This pro- file determines which authentication modules will be used. EXAMPLES To configure pam_worker for use with pam_exec(8): In /etc/pam.d/system-auth: auth required pam_exec.so return_prog_exit_status expose_authtok /usr/libexec/pam_worker login This configuration allows the pam_exec(8) module to invoke pam_worker with the "login" PAM profile. SEE ALSO pam(3), pam.conf(5), pam_exec(8) STANDARDS The pam_worker utility does not conform to any standard. FreeBSD ports 15.quarterly January 14, 2026 PAM_WORKER(8)
NAME | SYNOPSIS | DESCRIPTION | SECURITY CONSIDERATIONS | OPTIONS | EXAMPLES | SEE ALSO | STANDARDS
Want to link to this manual page? Use this URL:
<https://man.freebsd.org/cgi/man.cgi?query=pam_worker&sektion=8&manpath=FreeBSD+Ports+15.1.quarterly>
