This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Support
  • Community Support
  • Ideas & Suggestions
  • Pam Agent Challenge Force UserIDs to uppercase (normalize)
  • Options
    • Subscribe to RSS Feed
    • Mark as New
    • Mark as Read
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content

Pam Agent Challenge Force UserIDs to uppercase (normalize)

JayGuillette
Apprised Contributor JayGuillette Apprised Contributor
Apprised Contributor
Options
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Printer Friendly Page
  • Report Inappropriate Content
‎2020-07-14 04:51 PM
Status: New

UserIDs are not case sensitive in Windows because they have been forced to be upper case or normalized, so that if a UserID is x12345 that is the same as X12345.  By default, Linux is case sensitive.  If a userID of x12345 is sent to the PAM challenge in an include group, and the only entry is X12345, the userID will not match and therefore not be challenged.

If the PAM module had the option to normalize or force the case on Letters in a UserID, it would make the PAM agent similar to the Windows agent in regards to challenge group lookups. 

  • challenge
  • group lookup
  • idea
  • ideas
  • ideation
  • pam 8.1
  • rsa ideas
  • RSA Link Idea
  • RSA Link Platform Idea
  • RSA Link Platform Suggestion
  • RSA Link Suggestion
  • RSA SecurID
  • RSA SecurID Access
  • SecurID
  • SecurID Access Prime
  • Suggestion
0 Likes
  • Back to Idea Exchange
  • Previous
  • Next
2 Comments
JayGuillette
Apprised Contributor JayGuillette Apprised Contributor
Apprised Contributor
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Report Inappropriate Content
‎2020-11-11 10:57 AM
‎2020-11-11 10:57 AM

This configurable feature has been coded into PAM agent 8.1.2

Fixed in 8.1.2.126

Implemented support for a new CHALLENGE_IGNORE_CASE configuration setting
which my be configured in the /etc/sd_pam.conf file.
If enabled, user name comparisons with either the challenge group members
or the challenged user list are case insensitive.

Status changed to: Proposed
rsalinkadmin
Administrator rsalinkadmin Administrator
Administrator
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Report Inappropriate Content
‎2021-08-12 09:02 PM
‎2021-08-12 09:02 PM
 

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
  • Back to Idea Exchange
  • Previous
  • Next
Idea Statuses
  • New 76
  • Needs Info 0
  • Investigating 0
  • Accepted 0
  • Declined 0
  • Delivered 0
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.