LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-29-2010, 04:30 PM   #1
DejaCpp
LQ Newbie
 
Registered: Jul 2006
Posts: 7

Rep: Reputation: 0
Prevent Root GUI Login


I am using RH 5 and I am trying to prevent root gui login. I have:

1. deleted contents of /etc/securetty
2. added auth required pam_listfile.so item=user sense=deny file=/etc/root-no-login onerr=succeed to /etc/pam.d/gdm and the root-no-login file contains root
3. added auth required pam_succeed_if.so user != root quiet to /etc/pam.d/gdm
4. added -:root:all to the /etc/access_conf

Number 2 works on my RHEL 4 and 3 works on Fedora. 1 & 2 prevented console login. I didn't try setting the shell to /bin/nologin because I feared I might lock root out. Any ideas. Thanks.
 
Old 10-30-2010, 04:52 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by DejaCpp View Post
2. added auth required pam_listfile.so item=user sense=deny file=/etc/root-no-login onerr=succeed to /etc/pam.d/gdm and the root-no-login file contains root
/etc/pam.d/gdm sources /etc/pam.d/system-auth, so unless your "auth required pam_listfile" line comes first and you have copied required lines over from system-auth, behaviour will be partially controlled there. The only other GDM-related root-login-governing settings I found where 'echo -en "AllowRoot=false\nAllowRemoteRoot=false\n" >> /etc/X11/gdm/gdm.conf-custom'. You should not mess with roots shell, leave it as it is.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Prevent login of apache and root using PAM dhirajsharma Linux - Security 2 08-14-2008 09:53 PM
Emptying securetty does not prevent root login OgreCoder Linux - Security 6 11-20-2007 06:49 AM
Can't login as root in GUI ashutosh mehra Linux - Desktop 3 08-28-2006 06:07 PM
wrong login shell prevent root login cefs99 Linux - Security 4 05-31-2006 08:28 AM
OpenSSH, prevent root login, how? cylarz Linux - Security 1 04-22-2006 05:23 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration