Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20110523110842.GA9938@openwall.com>
Date: Mon, 23 May 2011 15:08:42 +0400
From: Solar Designer <solar@...nwall.com>
To: owl-users@...ts.openwall.com
Subject: Re: su, syslog, pam

On Mon, May 23, 2011 at 02:54:55PM +0400, Anatoly Pugachev wrote:
> I failed to 'su - ' as ordinary user in Owl.

Why do that?  Anyway, if you must, run:

control su wheelonly

Does this help?  On a default install of Owl, it'd enable su for use by
users in group wheel.  (There's also the wheel setting, which
corresponds to BSD-like behavior, but I think wheelonly is better most
of the time... if you enable any of these at all, which you normally
should not.)

# control su list
public wheel wheelonly restricted

> Added myself to 'wheel'
> group and re-login, as well commented out pam_rootok and uncommented
> pam_wheel in /etc/pam.d/su.

Please use control(8) instead of editing these files manually (although
you can if you know what you're doing).

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.