pam_pkcs11 - PKCS #11/NSS PAM login module

Property Value
Distribution CentOS 6
Repository CentOS x86_64
Package filename pam_pkcs11-0.6.2-17.el6.x86_64.rpm
Package name pam_pkcs11
Package version 0.6.2
Package release 17.el6
Package architecture x86_64
Package type rpm
Category System Environment/Base
License LGPLv2+
Maintainer -
Download size 193.24 KB
Installed size 1.09 MB
This Linux-PAM login module allows a X.509 certificate based user
authentication. The certificate and its dedicated private key are thereby
accessed by means of an appropriate PKCS #11 module. For the
verification of the users' certificates, locally stored CA
certificates as well as either online or locally accessible CRLs and
OCSP are used. This version uses NSS to validate the Certificates and manage
the PKCS #11 smartCards.
Additional included pam_pkcs11 related tools
- pkcs11_eventmgr: Generate actions on card insert/removal/timeout events
- pklogin_finder: Get the loginname that maps to a certificate
- pkcs11_inspect: Inspect the contents of a certificate


Package Version Architecture Repository
pam_pkcs11-0.6.2-17.el6.i686.rpm 0.6.2 i686 CentOS
pam_pkcs11-0.6.2-17.el6.i686.rpm 0.6.2 i686 CentOS
pam_pkcs11 - - -


Name Value - - - - - - - - - - - - - - - - - - - - - - - - - - - -
rtld(GNU_HASH) -


Name Value
config(pam_pkcs11) = 0.6.2-17.el6 - - -
pam_pkcs11 = 0.6.2-17.el6
pam_pkcs11(x86-64) = 0.6.2-17.el6 -


Type URL
Binary Package pam_pkcs11-0.6.2-17.el6.x86_64.rpm
Source Package pam_pkcs11-0.6.2-17.el6.src.rpm

Install Howto

Install pam_pkcs11 rpm package:

# yum install pam_pkcs11




2018-02-08 - Bob Relyea <> 0.6.2-17
- Fix crash when using certs with UPNs
- Fix crash when using the generic mapper
2016-01-11 - Bob Relyea <> 0.6.2-15
- Use PKIX for path validation.
- Fix cert_policy parameter in default pam_pkcs11.conf file.
2014-05-13 - Bob Relyea <> 0.6.2-14
- Handle PKCS #11 modules when NSS or pam_pkcs11 only specify a partial path
- Fix coverity issues (found in 7.0 coverity scan)
2013-08-13 - Bob Relyea <> 0.6.2-13
- If the ssl part is specified for ldap, default to ldaps unless
otherwise specified in the .conf file
2012-02-29 - Bob Relyea <> 0.6.2-12.1
- Silence unexpected error messages when logged in remotely console
2011-01-18 - Bob Relyea <> 0.6.2-11.1
- Silence expected errors from the console
- make sure change log has correct dates and email
Resolves: #654460, #586149
2010-08-12 - Ray Strode <> 0.6.2-10
- Fix more argument parsing
Resolves: #586422
2010-08-06 - Ray Strode <> - 0.6.2-9
- Fix argument parsing
Resolves: #586422
2010-07-26 - Bob Relyea <> - 0.6.2-8
- Make sure we return zero for the count if there are no certs
in getcertlist
2010-06-04 - Bob Relyea <> - 0.6.2-7
- fix ldap compare

See Also

Package Description
pam_ssh_agent_auth-0.9.3-123.el6_9.i686.rpm PAM module for authentication with ssh-agent
pam_ssh_agent_auth-0.9.3-123.el6_9.x86_64.rpm PAM module for authentication with ssh-agent
pango-1.28.1-11.el6.i686.rpm System for layout and rendering of internationalized text
pango-1.28.1-11.el6.x86_64.rpm System for layout and rendering of internationalized text
pango-devel-1.28.1-11.el6.i686.rpm Development files for pango
pango-devel-1.28.1-11.el6.x86_64.rpm Development files for pango
pangomm-2.26.0-1.el6.i686.rpm C++ interface for Pango
pangomm-2.26.0-1.el6.x86_64.rpm C++ interface for Pango
pangomm-devel-2.26.0-1.el6.i686.rpm Headers for developing programs that will use pangomm
pangomm-devel-2.26.0-1.el6.x86_64.rpm Headers for developing programs that will use pangomm
papi-5.1.1-12.el6.i686.rpm Performance Application Programming Interface
papi-5.1.1-12.el6.x86_64.rpm Performance Application Programming Interface
papi-devel-5.1.1-12.el6.i686.rpm Header files for the compiling programs with PAPI
papi-devel-5.1.1-12.el6.x86_64.rpm Header files for the compiling programs with PAPI
papi-static-5.1.1-12.el6.x86_64.rpm Static libraries for the compiling programs with PAPI