LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-11-2004, 08:54 AM   #1
slug420
Member
 
Registered: Jul 2004
Posts: 68

Rep: Reputation: 15
how to stop pam from authenticating su


so I configured pam with tacplus to authenticate ssh connections against a tacacs server, but now when users log in (to local accounts not using the tacplus authentication) they cant use other commands such as passwd and su which are being restricted by pam. Here is what I see in /var/logmessages:

Aug 11 09:38:07 linux PAM-warn[26364]: function=[pam_sm_chauthtok] service=[passwd] terminal=[<unknown>] user=[cdeedc] ruser=[<unknown>] rhost=[<unknown>]


Where do I need ot make changes so that these additional commands are not looking to pam for authorization, or how do I authorize users to execute these commands using PAM?

right now /etc/pam.d/passwd is as it was when I installed pam the the exception of commenting every line out in an attempt to kill the authorization:

#%PAM-1.0
#auth required pam_unix2.so nullok
#account required pam_unix2.so
#password required pam_pwcheck.so nullok
#password required pam_unix2.so nullok use_first_pass use_authtok
#password required pam_make.so /var/yp
#session required pam_unix2.so


TIA
 
Old 08-12-2004, 01:16 PM   #2
bastard23
Member
 
Registered: Mar 2003
Distribution: Debian
Posts: 275

Rep: Reputation: 30
Umm... the same way you configured pam for ssh?

Why do you want to do this? Do want remote user to authenticate w/ tacacs (Your cisco router, right) and local users not to authenticate at all? Why not have everyone authenticate to the router? (I'm total unfamiliar with tacacs)

Good Luck,
chris
 
Old 08-13-2004, 07:55 AM   #3
slug420
Member
 
Registered: Jul 2004
Posts: 68

Original Poster
Rep: Reputation: 15
I figured it out.......stupid me

Im running suse and in yast you can set a security level for the box

I set it to paranoid, which apparently supercedes file permissions that you have set and disables certain commands (like su)

my pam configuration was fine i just had to crank the suse security setting backa notch
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How do I stop services from restarting after I stop them? M$ISBS Linux - Software 3 10-27-2005 08:13 PM
sendmail and authenticating smtp jgnasser Linux - Networking 3 01-23-2005 01:03 AM
vsftpd + pam + virtual users - Pam cannot load database file. mdkelly069 Linux - Networking 3 09-22-2004 11:07 PM
ProFTPd. Authenticating using /etc/passwd instead of PAM wenberg Linux - Software 2 01-04-2004 10:14 AM
SSH Redhat 8 Not Authenticating SteveT Linux - Networking 2 10-23-2003 05:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration