Comment by fl0wenol

8 years ago

I'm pretty sure this is somewhat unique to the history of pam_ldap and its stewardship by PADL Software compared to other PAM modules; its dense nature encourages commercial engagement for those who care enough to know how it works or want to use it for their own purposes. They're not motivated to make it easier to understand (i.e., for outsiders to contribute to or maintain).

pam_sss is easier to understand and its functionality expands upon it, but it was a redesign.

This is really fascinating - I agree that PAM LDAP appears to be especially obscure compared to other modules.