Re: [Security-Discuss] 2006 su problem
AAW <[email protected]> Mon, 17 Oct 2005 22:05:07 -0500
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On Monday, October 17, 2005 1:06pm, Anne Wilson wrote: > On Monday 17 Oct 2005 18:47, Erwann Robin wrote: > > look at /etc/pam.d/su. > > you will find a line : > > auth sufficient pam_succeed_if.so use_uid user ingroup wheel > > > > it was commented in the previous version but has been activated in > > the 2006 > > LE2005 version : > > # Uncomment the following line to implicitly trust users in the > > "wheel" group. > > #auth sufficient pam_wheel.so trust use_uid > > That explains it. So I have the choice of commenting that line out or > removing myself from the wheel group. What else would I lose by > cutting that group out? I'll go that way if there is no big problem. > > Anne msec will probably overwrite your changes, Anne. You can either up your security level to 3 (Higher) or customize msec (see man msec, man mseclib for info, also /usr/share/doc/msec-<version>/*). I didn't see that option listed in draksec, so you'd need to add the following to /etc/security/msec/level.local (create if needed): enable_pam_root_from_wheel(no) HTH, Arn
message.footer
(text/plain, 232 B)
____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________