whatis pam
PAM
Also known as: Pluggable Authentication Modules
Pluggable Authentication Modules, the framework Linux programs use to handle logins, passwords, 2FA, and session setup.
What Is PAM in Linux?
Programs like login, sshd, sudo, and display managers do not check passwords themselves. They call PAM, which runs the stack of modules configured in /etc/pam.d/<service>.
Adding a module lets you require TOTP codes, lock accounts after failed attempts, enforce password quality, or create home directories on first login, without changing the programs.
Example
cat /etc/pam.d/sshd Learn more about PAM
- PAM Explained: How Linux Actually Decides Who Gets In Every login, sudo and ssh session runs through a stack of PAM modules before it succeeds. The four module types, what required and sufficient really do, why order changes the outcome, and how to edit it without locking yourself out.
- nsswitch.conf, getent and SSSD: Where User Accounts Come From Users do not have to live in /etc/passwd. One file decides which sources the system consults for accounts, groups and hostnames, getent shows you the answer, and SSSD is what plugs a directory in.