LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 08-27-2016, 05:38 PM   #1
emiinfo
LQ Newbie
 
Registered: Sep 2015
Location: Bangalore(india)
Distribution: Redhat5/6/,centos,ubuntu.
Posts: 16

Rep: Reputation: Disabled
Deny specific users to use the su command


Hello,

how can i deny other users except (user1) using the su command?

here the things which i have tried.

there is a user1 and i have added him to wheel group.
and modified the PAM/su file


removed following line:

[#auth required pam_wheel.so use_uid]



but still othe users are able to use su from there shell




thanks
Amit
 
Old 08-27-2016, 07:38 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,311
Blog Entries: 28

Rep: Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137
Take them out of the wheel group maybe? I know that, on BSD, users must be a member of wheel to use su (only because I've been familiarizing myself with FreeBSD--you must actively add your user to wheel in FreeBSD).

http://www.cyberciti.biz/tips/restri...u-command.html
 
Old 08-28-2016, 03:25 PM   #3
emiinfo
LQ Newbie
 
Registered: Sep 2015
Location: Bangalore(india)
Distribution: Redhat5/6/,centos,ubuntu.
Posts: 16

Original Poster
Rep: Reputation: Disabled
hello,
Thanks bro.

but By default all users are allowed to access the su command.even if they are not member of the wheel.

just wnated to allow only one user to access the su.





thanks
Amit
 
Old 08-28-2016, 03:29 PM   #4
descendant_command
Senior Member
 
Registered: Mar 2012
Posts: 1,876

Rep: Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643
Why?
 
Old 08-28-2016, 04:12 PM   #5
emiinfo
LQ Newbie
 
Registered: Sep 2015
Location: Bangalore(india)
Distribution: Redhat5/6/,centos,ubuntu.
Posts: 16

Original Poster
Rep: Reputation: Disabled
Hello,

I don't know , i am using RH 6


please help me solving this issue
 
Old 08-28-2016, 04:13 PM   #6
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,263
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
You do that by NOT giving them the passwords of other users - especially root.
 
1 members found this post helpful.
Old 08-28-2016, 04:22 PM   #7
emiinfo
LQ Newbie
 
Registered: Sep 2015
Location: Bangalore(india)
Distribution: Redhat5/6/,centos,ubuntu.
Posts: 16

Original Poster
Rep: Reputation: Disabled
ok.. that is fine. but whenever users type su commd in there shell its promting to type password.
and i wnat them not to execute the su command
except user_1.

one more thing wanted to ask is that default redhat? (every users can execute su cmd)





thank
Amit
 
Old 08-28-2016, 04:37 PM   #8
Timothy Miller
Moderator
 
Registered: Feb 2003
Location: Arizona, USA
Distribution: Debian, EndeavourOS, OpenSUSE, KDE Neon
Posts: 4,003
Blog Entries: 26

Rep: Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521
yes, the su command is meant to be usable by any user, since it asks for the TARGET users password, not the current users password. So it's completely useless command unless you know the password of the user you are attempting to su to. Unlike sudo, this doesn't allow users any more rights than if they have access to the system in the first place, since they have to know the password of the user they want to become in order to use it.

Last edited by Timothy Miller; 08-28-2016 at 04:39 PM.
 
1 members found this post helpful.
Old 08-28-2016, 04:52 PM   #9
emiinfo
LQ Newbie
 
Registered: Sep 2015
Location: Bangalore(india)
Distribution: Redhat5/6/,centos,ubuntu.
Posts: 16

Original Poster
Rep: Reputation: Disabled
Thanks you everyone...and Timothy Miller.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Debian 8-NFS-Deny access to specific IP to specific "share" directory george102 Linux - Server 0 06-13-2016 04:45 AM
deny a user access to specific command krock923 Linux - Security 7 10-11-2012 03:04 PM
[squid-users] deny website and allow it to specific Ip Address its_my_style Linux - Networking 4 07-18-2010 09:18 PM
How to make a specific command(s) work for specific users or group only naren_0101bits Linux - General 3 08-28-2005 05:22 PM
Giving Specific users access to the reboot command shassouneh Linux - Security 15 03-24-2004 05:10 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 05:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration