pam_smartcard(8) System Manager's Manual pam_smartcard(8)

pam_smartcardSmartcard PAM module

[service-name] function-class control-flag pam_smartcard [options]

The Smartcard PAM module supports authentication function class. In terms of the function-class parameter, this is “auth.

This module permits or denies users based on smartcard authentication support in the Open Directory database, and the presence of an appropriate smartcard in the reader attached to the local machine. When a card is locked, the user is asked to unlock it with his PIN.

Continues evaluation even if user's shell is not valid. Normally, users with a shell like /usr/bin/false are considered as disabled.
Return failure when an appropriate smartcard is not present.

auth sufficient pam_smartcard.so

pam.conf(5), pam(8) SmartCardServices(7)

August 27, 2015 macOS 15.2