Check and Clear PAM Authentication Timestamps Safely
You will use pam_timestamp_check to answer a narrow question: is the PAM timestamp for an authenticated user still valid? You will also learn how to clear that timestamp and how to distinguish a real timestamp result from a broken installation. Allow about ten minutes. You need a shell account, the libpam-modules-bin package, and a PAM configuration that uses pam_timestamp.
The route
Jump straight to the step you need, or tick off Done means at the end.
This guide describes the installed Ubuntu package libpam-modules-bin 1.5.3-5ubuntu5.7. The local manual page is dated 7 May 2023. The command's timestamp is created by the pam_timestamp PAM module, not by this checker alone.
1. Confirm the command and its privilege boundary
Start by checking which executable will run and whether it has the privilege bit that the program requires:
$ command -v pam_timestamp_check
/usr/sbin/pam_timestamp_check
$ stat -c '%A %U %G %n' /usr/sbin/pam_timestamp_check
-rwsr-xr-x root root /usr/sbin/pam_timestamp_check
The exact stat line varies with local ownership and permissions. The relevant detail is the s in the owner execute position, shown above as rws. The manual says the program returns status 2 when it is not setuid root. On this machine the packaged file is currently not setuid, so an ordinary check prints pam_timestamp_check must be setuid root and returns 2. That is an installation or packaging condition, not evidence that a timestamp has expired.
Do not add the setuid bit casually. It changes how an executable obtains privilege and should be handled by your distribution's package and security policy. If the installed file is unexpectedly missing the bit, record the package state and ask the system administrator to repair it through the normal package-management process.
2. Check the default timestamp
With a correctly installed executable, run the command without options:
$ pam_timestamp_check
$ printf 'exit status: %s\n' "$?"
exit status: 0
Status 0 means the default timestamp is valid. The command normally has no success message, so capture its status immediately. Running another command before printf would replace the status you need to inspect.
A status of 7 means the timestamp is not valid. That can mean it has expired, was never created, or does not match the user and target being checked. The checker does not ask for a password and does not create a fresh timestamp. A PAM-aware application must perform the authentication flow that creates one.
Checkpoint: make the result explicit in a shell condition rather than relying on memory:
$ if pam_timestamp_check; then
> echo 'PAM timestamp is valid'
> else
> rc=$?
> echo "PAM timestamp check failed with status $rc"
> fi
3. Check a timestamp for another target user
By default, the command checks the timestamp associated with the user being authenticated as herself. When PAM authenticates as a different user, the timestamp file uses a different name. Pass that target account as the final argument:
$ pam_timestamp_check root
$ printf 'root target status: %s\n' "$?"
root target status: 7
Replace root with the account that the PAM transaction targets. A status of 7 in this example is only an example result: your machine may return 0, 7, or an error caused by its PAM and timestamp state. Do not interpret a check for one target user as a check for every account.
Use the target account that the calling PAM service actually requests. Guessing the account name is a common distraction when troubleshooting a command that sometimes prompts and sometimes does not.
4. Clear the timestamp
Use -k when you deliberately want to remove the selected timestamp instead of checking it:
$ pam_timestamp_check -k
$ printf 'clear exit status: %s\n' "$?"
clear exit status: 0
This is a state-changing, security-sensitive action. It causes the next PAM transaction that relies on this timestamp to authenticate again, but it does not change the PAM configuration and does not revoke unrelated sessions or credentials. Add the target user when the timestamp belongs to a different target:
$ pam_timestamp_check -k root
$ printf 'root clear exit status: %s\n' "$?"
root clear exit status: 0
If the command fails, do not assume the timestamp was removed. Check the returned status and investigate before starting a task that depends on re-authentication. There is no undo command for restoring the old timestamp; the practical recovery is to authenticate again through the relevant PAM application, which lets pam_timestamp create a new timestamp when its configuration permits that.
5. Watch validity continuously when troubleshooting
The -d option changes the command from a one-shot exit-status check into a polling loop. It prints the status on standard output and continues indefinitely:
$ pam_timestamp_check -d
valid
valid
invalid
The exact output and timing depend on the installed implementation and timestamp state. Stop the loop with Ctrl-C. Use a short terminal session for diagnosis, not a service or unattended job, because the command is designed to keep polling until interrupted.
Do not combine -d with a script that expects one exit status and immediate completion. If you need a single answer, omit -d and test the exit status instead.
6. Interpret failures without changing configuration
The documented return values are useful when a shell message is too vague:
| Status | Meaning | First check |
|---|---|---|
| 0 | Timestamp is valid | Continue with the PAM operation |
| 2 | Binary is not setuid root | Inspect the executable permissions and package state |
| 3 | Invalid invocation | Check the option spelling and argument count |
| 4 | User is unknown | Check the target account name |
| 5 | Permissions error | Check access to the timestamp location and controlling context |
| 6 | Invalid controlling terminal | Run it from the terminal context expected by the PAM setup |
| 7 | Timestamp is not valid | Authenticate again through the PAM application |
The timestamp files live below /var/run/sudo/... according to the manual page. Do not edit or delete files there by hand: their names and layout are implementation details, and manual changes can produce confusing results. Use -k for a supported removal operation.
Done means
pam_timestamp_checkis the expected executable and its setuid-root requirement has been checked.- A one-shot check returned a status that you interpreted immediately, with 0 meaning valid and 7 meaning not valid.
- A different target account was supplied explicitly when the PAM transaction authenticates as that account.
-kwas used only when clearing the timestamp was intentional and re-authentication is acceptable.- No timestamp files or PAM configuration files were edited by hand.