{
    "mode": "man",
    "parameter": "pam_succeed_if",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/pam_succeed_if/8/json",
    "generated": "2026-10-05T05:00:28Z",
    "synopsis": "pamsucceedif.so [flag...] [condition...]",
    "sections": {
        "NAME": {
            "content": "pamsucceedif - test account characteristics\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "pamsucceedif.so [flag...] [condition...]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "pamsucceedif.so is designed to succeed or fail authentication based on characteristics of\nthe account belonging to the user being authenticated or values of other PAM items. One use\nis to select whether to load other modules based on this test.\n\nThe module should be given one or more conditions as module arguments, and authentication\nwill succeed only if all of the conditions are met.\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "The following flags are supported:\n\ndebug\nTurns on debugging messages sent to syslog.\n\nuseuid\nEvaluate conditions using the account of the user whose UID the application is running\nunder instead of the user being authenticated.\n\nquiet\nDon't log failure or success to the system log.\n\nquietfail\nDon't log failure to the system log.\n\nquietsuccess\nDon't log success to the system log.\n\naudit\nLog unknown users to the system log.\n\nConditions are three words: a field, a test, and a value to test for.\n\nAvailable fields are user, uid, gid, shell, home, ruser, rhost, tty and service:\n\nfield < number\nField has a value numerically less than number.\n\nfield <= number\nField has a value numerically less than or equal to number.\n\nfield eq number\nField has a value numerically equal to number.\n\nfield >= number\nField has a value numerically greater than or equal to number.\n\nfield > number\nField has a value numerically greater than number.\n\nfield ne number\nField has a value numerically different from number.\n\nfield = string\nField exactly matches the given string.\n\nfield != string\nField does not match the given string.\n\nfield =~ glob\nField matches the given glob.\n\nfield !~ glob\nField does not match the given glob.\n\nfield in item:item:...\nField is contained in the list of items separated by colons.\n\nfield notin item:item:...\nField is not contained in the list of items separated by colons.\n\nuser ingroup group[:group:....]\nUser is in given group(s).\n\nuser notingroup group[:group:....]\nUser is not in given group(s).\n\nuser innetgr netgroup\n(user,host) is in given netgroup.\n\nuser notinnetgr group\n(user,host) is not in given netgroup.\n",
            "subsections": []
        },
        "MODULE TYPES PROVIDED": {
            "content": "All module types (account, auth, password and session) are provided.\n",
            "subsections": []
        },
        "RETURN VALUES": {
            "content": "PAMSUCCESS\nThe condition was true.\n\nPAMAUTHERR\nThe condition was false.\n\nPAMSERVICEERR\nA service error occurred or the arguments can't be parsed correctly.\n",
            "subsections": []
        },
        "EXAMPLES": {
            "content": "To emulate the behaviour of pamwheel, except there is no fallback to group 0 being only\napproximated by checking also the root group membership:\n\nauth required pamsucceedif.so quiet user ingroup wheel:root\n\n\nGiven that the type matches, only loads the othermodule rule if the UID is over 500. Adjust\nthe number after default to skip several rules.\n\ntype [default=1 success=ignore] pamsucceedif.so quiet uid > 500\ntype required othermodule.so arguments...\n\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "glob(7), pam(7)\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "Nalin Dahyabhai <nalin@redhat.com>\n\nLinux-PAM                                    05/07/2023                            PAMSUCCEEDIF(8)",
            "subsections": []
        }
    },
    "summary": "pamsucceedif - test account characteristics",
    "flags": [],
    "examples": [
        "To emulate the behaviour of pamwheel, except there is no fallback to group 0 being only",
        "approximated by checking also the root group membership:",
        "auth required pamsucceedif.so quiet user ingroup wheel:root",
        "Given that the type matches, only loads the othermodule rule if the UID is over 500. Adjust",
        "the number after default to skip several rules.",
        "type [default=1 success=ignore] pamsucceedif.so quiet uid > 500",
        "type required othermodule.so arguments..."
    ],
    "see_also": [
        {
            "name": "glob",
            "section": "7",
            "url": "https://www.chedong.com/phpMan.php/man/glob/7/json"
        },
        {
            "name": "pam",
            "section": "7",
            "url": "https://www.chedong.com/phpMan.php/man/pam/7/json"
        }
    ]
}