Re: [Security-Discuss] 2006 su problem

Anne Wilson <[email protected]> Mon, 17 Oct 2005 19:06:35 +0100
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Monday 17 Oct 2005 18:47, Erwann Robin wrote:
> look at /etc/pam.d/su.
> you will find a line :
> auth       sufficient   pam_succeed_if.so use_uid user ingroup wheel
>
> it was commented in the previous version but has been activated in
> the 2006
> LE2005 version :
> # Uncomment the following line to implicitly trust users in the
> "wheel" group.
> #auth       sufficient   pam_wheel.so trust use_uid
>
That explains it.  So I have the choice of commenting that line out or 
removing myself from the wheel group.  What else would I lose by 
cutting that group out?  I'll go that way if there is no big problem.

Anne
-- 
Registered Linux User No.293302 (http://counter.li.org/)
Mandriva hints & tips: http://twiki.mdklinuxfaq.org
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)

iD8DBQBDU+gvkFAvMr/nNX8RAmLMAJ9JroKTLFL1d9nnw7f54LzA9+uj2ACfTDuS
Z1idVdlhCQkW9pxvBsn+3lQ=
=HW7D
-----END PGP SIGNATURE-----