{
    "mode": "man",
    "parameter": "PAM_EXEC",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/PAM_EXEC/8/json",
    "generated": "2026-10-04T08:35:27Z",
    "synopsis": "pamexec.so [debug] [exposeauthtok] [seteuid] [quiet] [quietlog] [stdout] [log=file]\n[type=type] command [...]",
    "sections": {
        "NAME": {
            "content": "pamexec - PAM module which calls an external command\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "pamexec.so [debug] [exposeauthtok] [seteuid] [quiet] [quietlog] [stdout] [log=file]\n[type=type] command [...]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "pamexec is a PAM module that can be used to run an external command.\n\nThe child's environment is set to the current PAM environment list, as returned by\npamgetenvlist(3) In addition, the following PAM items are exported as environment variables:\nPAMRHOST, PAMRUSER, PAMSERVICE, PAMTTY, PAMUSER and PAMTYPE, which contains one of the\nmodule types: account, auth, password, opensession and closesession.\n\nCommands called by pamexec need to be aware of that the user can have control over the\nenvironment.\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "debug\nPrint debug information.\n\nexposeauthtok\nDuring authentication the calling command can read the password from stdin(3). Only first\nPAMMAXRESPSIZE bytes of a password are provided to the command.\n\nlog=file\nThe output of the command is appended to file\n\ntype=type\nOnly run the command if the module type matches the given type.\n\nstdout\nPer default the output of the executed command is written to /dev/null. With this option,\nthe stdout output of the executed command is redirected to the calling application. It's\nin the responsibility of this application what happens with the output. The log option is\nignored.\n\nquiet\nPer default pamexec.so will echo the exit status of the external command if it fails.\nSpecifying this option will suppress the message.\n\nquietlog\nPer default pamexec.so will log the exit status of the external command if it fails.\nSpecifying this option will suppress the log message.\n\nseteuid\nPer default pamexec.so will execute the external command with the real user ID of the\ncalling process. Specifying this option means the command is run with the effective user\nID.\n",
            "subsections": []
        },
        "MODULE TYPES PROVIDED": {
            "content": "All module types (auth, account, password and session) are provided.\n",
            "subsections": []
        },
        "RETURN VALUES": {
            "content": "PAMSUCCESS\nThe external command was run successfully.\n\nPAMBUFERR\nMemory buffer error.\n\nPAMCONVERR\nThe conversation method supplied by the application failed to obtain the username.\n\nPAMINCOMPLETE\nThe conversation method supplied by the application returned PAMCONVAGAIN.\n\nPAMSERVICEERR\nNo argument or a wrong number of arguments were given.\n\nPAMSYSTEMERR\nA system error occurred or the command to execute failed.\n\nPAMIGNORE\npamsetcred was called, which does not execute the command. Or, the value given for the\ntype= parameter did not match the module type.\n",
            "subsections": []
        },
        "EXAMPLES": {
            "content": "Add the following line to /etc/pam.d/passwd to rebuild the NIS database after each local\npassword change:\n\npassword optional pamexec.so seteuid /usr/bin/make -C /var/yp\n\n\nThis will execute the command\n\nmake -C /var/yp\n\nwith effective user ID.\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "pam.conf(5), pam.d(5), pam(7)\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "pamexec was written by Thorsten Kukuk <kukuk@thkukuk.de> and Josh Triplett\n<josh@joshtriplett.org>.\n\nLinux-PAM                                    05/07/2023                                  PAMEXEC(8)",
            "subsections": []
        }
    },
    "summary": "pamexec - PAM module which calls an external command",
    "flags": [],
    "examples": [
        "Add the following line to /etc/pam.d/passwd to rebuild the NIS database after each local",
        "password change:",
        "password optional pamexec.so seteuid /usr/bin/make -C /var/yp",
        "This will execute the command",
        "make -C /var/yp",
        "with effective user ID."
    ],
    "see_also": [
        {
            "name": "pam.conf",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/pam.conf/5/json"
        },
        {
            "name": "pam.d",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/pam.d/5/json"
        },
        {
            "name": "pam",
            "section": "7",
            "url": "https://www.chedong.com/phpMan.php/man/pam/7/json"
        }
    ]
}