Re: configure /etc/pam.d/crond to use pam_mount

Simone Gaiarin <[email protected]> Sat, 08 Oct 2016 13:11:40 +0000
Newsgroups gmane.linux.pam
Message-ID <CAO-Exud_SvUCetGtoMYVj8EJwfPHORqk3_wTa_tjPXxa=F-Wfw@mail.gmail.com>
--===============6337154444371583275==
Content-Type: multipart/alternative; boundary=001a113622061905c1053e5a457e

--001a113622061905c1053e5a457e
Content-Type: text/plain; charset=UTF-8

pam_mount decrypt the disk using the password the user input in the login
screen of the OS. Now in the moment I'm logged in and the disk is decrypted
how can I make cron see the disk? I'm not interested in having cron running
jobs when I'm not logged in (and so the disk is encrypted).

I guess that your question arise from the fact that cron can run jobs when
the user is not logged in, but it's a scenario I'm not interested in.
Actually my jobs run with anacron.

Possibly /etc/pam.d/crond deals with this last case. If this is not the
solution, do you have any other solution to deal with this problem?

Thank you

On Sat, Oct 8, 2016 at 2:53 PM Matus UHLAR - fantomas <[email protected]>
wrote:

> On 08.10.16 11:55, Simone Gaiarin wrote:
> >Hi I have a LUKS encrypted disk that I mount during the login phase using
> >pam_mount. The problem I'm facing is that cron jobs cannot see the the
> >content of the disk.
> >
> >After an intensive research I've understood that I need to configure
> >/etc/pam.d/crond in order to properly load the pam_mount module. I've
> tried
> >this without any success, so I'm asking here to get some help from an
> >expert of PAM.
>
> >I''ve configured pam_mount using these instructions:
> >https://wiki.archlinux.org/index.php/Pam_mount
> >https://wiki.archlinux.org/index.php/Talk:Pam_mount
>
> I wonder if pam_mount does not need user's password in orderto mount the
> encrypted filesystem. Otherwise it would be quite useless to have it
> encrypted, wouldn't it?
>
>
> --
> Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/
> Warning: I wish NOT to receive e-mail advertising to this address.
> Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
> It's now safe to throw off your computer.
>
> _______________________________________________
> Pam-list mailing list
> [email protected]
> https://www.redhat.com/mailman/listinfo/pam-list
>

--001a113622061905c1053e5a457e
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">pam_mount decrypt the disk using the password the user inp=
ut in the login screen of the OS. Now in the moment I&#39;m logged in and t=
he disk is decrypted how can I make cron see the disk? I&#39;m not interest=
ed in having cron running jobs when I&#39;m not logged in (and so the disk =
is encrypted).<br><br>I guess that your question arise from the fact that c=
ron can run jobs when the user is not logged in, but it&#39;s a scenario I&=
#39;m not interested in. Actually my jobs run with anacron.<div><br></div><=
div>Possibly /etc/pam.d/crond deals with this last case. If this is not the=
 solution, do you have any other solution to deal with this problem?</div><=
div><br></div><div>Thank you</div></div><br><div class=3D"gmail_quote"><div=
 dir=3D"ltr">On Sat, Oct 8, 2016 at 2:53 PM Matus UHLAR - fantomas &lt;<a h=
ref=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br></div>=
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">On 08.10.16 11:55, Simone Gaiarin wrote:<br =
class=3D"gmail_msg">
&gt;Hi I have a LUKS encrypted disk that I mount during the login phase usi=
ng<br class=3D"gmail_msg">
&gt;pam_mount. The problem I&#39;m facing is that cron jobs cannot see the =
the<br class=3D"gmail_msg">
&gt;content of the disk.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;After an intensive research I&#39;ve understood that I need to configur=
e<br class=3D"gmail_msg">
&gt;/etc/pam.d/crond in order to properly load the pam_mount module. I&#39;=
ve tried<br class=3D"gmail_msg">
&gt;this without any success, so I&#39;m asking here to get some help from =
an<br class=3D"gmail_msg">
&gt;expert of PAM.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
&gt;I&#39;&#39;ve configured pam_mount using these instructions:<br class=
=3D"gmail_msg">
&gt;<a href=3D"https://wiki.archlinux.org/index.php/Pam_mount" rel=3D"noref=
errer" class=3D"gmail_msg" target=3D"_blank">https://wiki.archlinux.org/ind=
ex.php/Pam_mount</a><br class=3D"gmail_msg">
&gt;<a href=3D"https://wiki.archlinux.org/index.php/Talk:Pam_mount" rel=3D"=
noreferrer" class=3D"gmail_msg" target=3D"_blank">https://wiki.archlinux.or=
g/index.php/Talk:Pam_mount</a><br class=3D"gmail_msg">
<br class=3D"gmail_msg">
I wonder if pam_mount does not need user&#39;s password in orderto mount th=
e<br class=3D"gmail_msg">
encrypted filesystem. Otherwise it would be quite useless to have it<br cla=
ss=3D"gmail_msg">
encrypted, wouldn&#39;t it?<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
--<br class=3D"gmail_msg">
Matus UHLAR - fantomas, <a href=3D"mailto:[email protected]" class=3D"gmail=
_msg" target=3D"_blank">[email protected]</a> ; <a href=3D"http://www.fanto=
mas.sk/" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">http://ww=
w.fantomas.sk/</a><br class=3D"gmail_msg">
Warning: I wish NOT to receive e-mail advertising to this address.<br class=
=3D"gmail_msg">
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.<br cla=
ss=3D"gmail_msg">
It&#39;s now safe to throw off your computer.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
_______________________________________________<br class=3D"gmail_msg">
Pam-list mailing list<br class=3D"gmail_msg">
<a href=3D"mailto:[email protected]" class=3D"gmail_msg" target=3D"_blank=
">[email protected]</a><br class=3D"gmail_msg">
<a href=3D"https://www.redhat.com/mailman/listinfo/pam-list" rel=3D"norefer=
rer" class=3D"gmail_msg" target=3D"_blank">https://www.redhat.com/mailman/l=
istinfo/pam-list</a><br class=3D"gmail_msg">
</blockquote></div>

--001a113622061905c1053e5a457e--


--===============6337154444371583275==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Pam-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/pam-list
--===============6337154444371583275==--