LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-19-2001, 11:56 AM   #1
adamrau
Member
 
Registered: Sep 2001
Posts: 42

Rep: Reputation: 15
Is it possible to have only 1 user signed in at a time or only allow console Sign Ins


1) Can i have only one user signed in at a time? If so, how?
I dont want multiple users signed in.

2) Can I setup my system to only allow signin via console, not from anywhere else? If so, How?
I only want console access which means the only person that can log onto my system, is the person PHYSICALLY using it.

Thanks and sorry if my questions are a little out of the ordinary.

Much thanks in advance
Adam
 
Old 11-19-2001, 01:06 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Hmm. Can't see anything weird in this question?..

For controlling tty's for root look in /etc/securetty, for users in /etc/usertty, and then look in /etc/security, for access.conf and the other conf's in there to allow logins by host, time, period (also $TMOUT).

I've never seen a way to exclusively lock out other users tho, except for /etc/nologin, and that ain't "interactive" IIRC). Only root or root-owned processes have caps to control restrictions, ie, I don't think a user-process could deny another user's login.
 
Old 11-19-2001, 01:27 PM   #3
d3funct
Member
 
Registered: Jun 2001
Location: Centralia, WA
Posts: 274

Rep: Reputation: 31
Lightbulb

I just answered this question over at Tek-Tips . You can control user access with /etc/login.access file, specifying which users can login and from where remote host or specify tty device.

A record in this file consists of three colon:delimited fields: a plus (+) or minus (-) sign indicating whether users are allowed access, usr login names allowed access and the remote system or temintal from which they can login.

example

+:joe:bilbo.shire.org

You can list more than one user or location. You can also use the ALL option in place of either users or locations to allow access by all users and locations. The ALL option can be qualified with the EXCEPT option to allow access by certain specified ones. the following entry allows any user to log into the system using the console except for Frodo and Sam
You
+:ALL EXCEPT frodo sam : console

I hope this helps.
 
Old 11-19-2001, 01:30 PM   #4
adamrau
Member
 
Registered: Sep 2001
Posts: 42

Original Poster
Rep: Reputation: 15
Hey,
Thanks for all your help. Just one question.
I dont have an /etc/login.access file. Can i just create one and then add in what you have stated???

Thanks again
 
Old 11-19-2001, 01:41 PM   #5
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
you should be fien to create it.

so going by that solution, hw can you stop anyone else logging in? restricting those logging in is fine, but i guess the desired solutino is that any known user can log in, but no one else can when someone already is... presumably you could automate login.access, re-writing the file when a user logs in and out...?
 
Old 11-19-2001, 02:14 PM   #6
d3funct
Member
 
Registered: Jun 2001
Location: Centralia, WA
Posts: 274

Rep: Reputation: 31
I would assume if you wanted to restrict logins to a particular set of persons you would do:

-:ALL EXCEPT frodo sam : console

Which would say "restrict (-) ALL EXCEPT frodo and sam, from logging in on the console (or whatever tty or remote host you wish. That's an assumption on my part, but it makes sense to me. Works kinda like a hosts.deny and hosts.allow file only in just one place.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
sign on invisible in gaim - NOT invi after sign on saravkrish Linux - Software 7 09-12-2005 10:55 PM
Plug-ins sends user back to windows. ejbest Linux - Software 3 01-18-2005 12:37 PM
Plug-ins, Plug-ins, Plug-ins, those damn Plug-ins!! GRRRR!! Ausar Linux - Newbie 1 06-09-2004 03:10 PM
redhat pre 7.2 had login.def to force standard user to sign on first ForumKid Linux - General 1 08-14-2003 04:32 PM
how much time are you on the console? gui10 Linux - General 14 04-17-2002 12:28 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:15 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration