console.handlers(5) - Linux man page
Name
console.handlers - file specifying handlers of console lock and unlock eventsDescription
The format is:
handler-filename lock|unlock [flag ...]
Where handler-filename is a name of the executable to be run, lock or unlock specifies on which event it should be run, and flags specify how should pam_console call it.
Additionally there should be a line which specifies glob patterns of console devices.
The format of this line is: console-name consoledevs regex [regex ...]
Where console-name is a name of the console class - currently ignored - and regexes are regular expression patterns which specify the name of the tty device. Only the first such line is consulted.
Flags
- logfail
- The pam_console module should log error to the system log if the return value of the handler is not zero or if the handler can not be executed.
- wait
- The pam_console should wait for the handler to exit before continuing.
- setuid
- The handler should be executed with uid/gid of the user which obtained the console lock.
- tty
- The handler will get a tty name as obtained from PAM as a parameter.
- user
- The handler will get an user name as obtained from PAM as a parameter.
Anything else will be added directly as a parameter to the handler executable.
