Re: [Security-Discuss] 2006 su problem

AAW <[email protected]> Mon, 17 Oct 2005 22:05:07 -0500
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Monday, October 17, 2005 1:06pm, Anne Wilson wrote:
> On Monday 17 Oct 2005 18:47, Erwann Robin wrote:
> > look at /etc/pam.d/su.
> > you will find a line :
> > auth       sufficient   pam_succeed_if.so use_uid user ingroup wheel
> >
> > it was commented in the previous version but has been activated in
> > the 2006
> > LE2005 version :
> > # Uncomment the following line to implicitly trust users in the
> > "wheel" group.
> > #auth       sufficient   pam_wheel.so trust use_uid
>
> That explains it.  So I have the choice of commenting that line out or
> removing myself from the wheel group.  What else would I lose by
> cutting that group out?  I'll go that way if there is no big problem.
>
> Anne

msec will probably overwrite your changes, Anne. You can either up your 
security level to 3 (Higher) or customize msec (see man msec, man mseclib 
for info, also /usr/share/doc/msec-<version>/*). I didn't see that option 
listed in draksec, so you'd need to add the following 
to /etc/security/msec/level.local (create if needed):
	enable_pam_root_from_wheel(no)

HTH,
Arn
message.footer (text/plain, 232 B)
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________