LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-14-2006, 05:15 PM   #1
Notwerk
Member
 
Registered: Apr 2005
Location: Jordan
Distribution: Debian (Sarge), Ubuntu (6.06)
Posts: 271

Rep: Reputation: 31
Looking for layman documentation for PAM


As the title suggests, I'm looking for some documentation for PAM that is a little dumbbed-down

PS: I'm trying to get an FC3 box to allow ONLY root to reboot/shutdown/halt/poweroff. Also, I want the machine to automatically do an fsck EVERYTIME it is booted up (which happens very rarely).

Any recommendations appreciated.
 
Old 01-15-2006, 01:42 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
there's very little documentation for it really.

for the halt access, i think you should just remove those users from the wheel group (gid 10) and that should prevent them doing it.

as for the fsck thing, use tune2fs to reduce the mount count, but really an ext3 or other journalling filesystem has no reason at all to do this.
 
Old 01-15-2006, 01:49 AM   #3
Notwerk
Member
 
Registered: Apr 2005
Location: Jordan
Distribution: Debian (Sarge), Ubuntu (6.06)
Posts: 271

Original Poster
Rep: Reputation: 31
Wheel group has root as its only member. Actually I'm pretty sure this is better handled through PAM (at least on FC3), but i can't seem to figure out how to use it.

Just so i'm clear on this point:
ext3 does NOT need fsck? What if bad blocks develop on the disk? would ext3 journalling still be able to recover from that?

Thanx for the info
 
Old 01-15-2006, 02:01 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
ahh i was assuming it'd be the same as for fc4, which is using wheel (unless i added users myself and forgot. If you comment out the pam_console.so reference then that should top them too. basically that prevents acceptance for any known local users.
 
Old 01-15-2006, 02:23 AM   #5
Notwerk
Member
 
Registered: Apr 2005
Location: Jordan
Distribution: Debian (Sarge), Ubuntu (6.06)
Posts: 271

Original Poster
Rep: Reputation: 31
It would be very interesting to see where the Fedora Project is headed with regards to PAM. I think it will all be clear with the release of FC5.

Thanx for your help.

[edit]
i got it working, thanx to your last suggestion
[/edit]

Last edited by Notwerk; 01-15-2006 at 02:24 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
RHEL License for a Layman jowizzle Linux - Enterprise 5 10-15-2005 04:36 PM
In layman terms...boot floppy E.T.Me Mandriva 3 01-08-2005 02:19 PM
X Documentation ? Ikebo Programming 6 10-02-2004 09:02 PM
vsftpd + pam + virtual users - Pam cannot load database file. mdkelly069 Linux - Networking 3 09-22-2004 11:07 PM
Documentation For RH 9.0 Crotch Linux - Newbie 2 04-25-2004 05:42 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:30 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration