LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-17-2010, 03:17 AM   #1
techdiver
LQ Newbie
 
Registered: Nov 2010
Posts: 3

Rep: Reputation: 0
Deprecated pam_stack module called from service "su-l"


Hi there,

I get the following message in /var/log/secure: Nov 15 09:27:21 su: Deprecated pam_stack module called from service "su-l"

I have done some research and it seems I need to get rid of pam_stack.so in /etc/pam.d/su but I can't find out what to use in its place.

Below is a copy of my /etc/pam.d/su file:

Code:
auth sufficient pam_rootok.so
auth required pam_stack.so service=system-auth
auth sufficient pam_stack.so service=su-root-members
auth sufficient pam_stack.so service=su-oracle-members
auth sufficient pam_stack.so service=su-other-members
auth sufficient pam_stack.so service=su-vnc-members
auth required pam_deny.so
account required pam_stack.so service=system-auth
password required pam_stack.so service=system-auth
session required pam_selinux.so close
session required pam_stack.so service=system-auth
session required pam_selinux.so open multiple
session optional pam_xauth.so
From what I understand, I need to replace the line "auth required pam_stack.so service=system-auth" with "auth include system-auth"

My problem is how do I then go about limiting access to su based on group membership without pam_stack.so?

Any advice will be greatly appreaciated.

Thanks!
 
Old 11-17-2010, 02:09 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Quote:
Originally Posted by techdiver View Post
From what I understand, I need to replace the line "auth required pam_stack.so service=system-auth" with "auth include system-auth"
That is correct.


Quote:
Originally Posted by techdiver View Post
My problem is how do I then go about limiting access to su based on group membership without pam_stack.so?
How about "pam_listfile"?
 
1 members found this post helpful.
Old 11-24-2010, 01:55 AM   #3
techdiver
LQ Newbie
 
Registered: Nov 2010
Posts: 3

Original Poster
Rep: Reputation: 0
Thanks. That's exactly what I needed.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
vsftpd: Deprecated pam_stack module called from service "vsftpd" walidaly Linux - Security 1 10-05-2010 04:41 AM
ACPI S3 (so-called "Standby" or "Sleep") in GNU/Linux posix_memalign Linux - Laptop and Netbook 1 01-17-2009 01:54 PM
Logs filling up with "smbd/service.c:make_connection" - "couldn't find service" DumbTerminal Linux - Networking 14 07-16-2007 06:33 AM
service called "doom" using udp port 666 djcham Linux - Networking 1 12-13-2006 01:38 PM
Root can log on, user account can't. "Error in service module" Charlie Spencer Linux - Newbie 3 09-13-2006 01:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration