pam_opendirectory(8) System Manager's Manual pam_opendirectory(8)

pam_opendirectoryOpenDirectory PAM module

[service-name] function-class control-flag pam_opendirectory [options]

The OpenDirectory PAM module supports the authentication, account management and password management function classes. In terms of the function-class parameter, these are “auth”, “account” and “password” respectively.

The OpenDirectory authentication module permits or denies users based on OpenDirectory password authentication.

The following option may be passed to this authentication module:

Allow null passwords.

The OpenDirectory account management module permits or denies users based whether the account is enabled in OpenDirectory.

The following option may be passed to this account management module:

Skip validating the user's shell.
Skip validating the user's home directory.
=min
Sets the mbr_check_membership(3) cache timeout to min minutes. When this option is used, the min value must be specified, and it must be an integer.

The OpenDirectory password management module supports password changing and enforces the OpenDirectory password policy.

mbr_check_membership(3), pam.conf(5), pam(8), pwpolicy(8), DirectoryService(8)

February 7, 2009 macOS 14.6