Re: Locking out users by name for direct login. Allow SU - only

From: Eigenvector (m44_master_at_yahoo.com)
Date: 05/21/05

  • Next message: Fred: "License question..."
    Date: Fri, 20 May 2005 17:05:44 -0700
    
    

    "Ted Linnell" <edlinnell@acslink.net.au> wrote in message
    news:qnir81d5on1ba7p8gjska9qndk08c947kf@4ax.com...
    > "Eigenvector" <m44_master@yahoo.com> wrote:
    >
    > >
    > >"DM" <don.monk@genmills.com> wrote in message
    > >news:WZ6je.20$Hj1.1093@news.uswest.net...
    > >> Does anyone know a method to lockout non root users from direct access
    > >> (telnet, ssh, remsh, etc.)? I would like to be able for certain non
    > >> root users only allow then to be SU - to. It would be a kind of user
    > >> equivalent to securetty for root.
    > >>
    > >> Any help is greatly appreciated.
    > >>
    > >> Thanks,
    > >
    > >Yeah, just lock the account - passwd -l <user>
    > >
    > >Locking the account shouldn't stop them from being switch user'ed into.
    I
    > >guess I haven't tried that directly, but I know it works for root su'ing
    > >into daemon accounts.
    > >> DM
    > >>
    > >
    > But then only root can su to the account, any other user will require
    > a password and find the account disabled.
    >
    > Ted.
    Oh, you're right, I wasn't even thinking about that part. Duhhhh.


  • Next message: Fred: "License question..."

    Relevant Pages

    • Re: user privledges
      ... > redhat 7.2 i created a user account for myself to use on a daily basis. ... > fare i have just been su - and entering the root pass. ... it started but would not install because i did ... sofware to /opt/musicmatch as a normal user. ...
      (comp.security.unix)
    • Re: hi all..
      ... And with sudo, I certainly wouldn't because they already have root. ... If you somehow had access to my account right now, ... install an effective key logger without root. ...
      (Fedora)
    • Re: cant login as root
      ... > The only reason they don't have a local account is they were too lazy to ... If you're root you create and maintain a user account. ... local root accounts are themselves a hazard. ...
      (comp.os.linux.setup)
    • Re: hi all..
      ... and someone gets access your shell account, ... Only root can install an su binary. ... Of course, if I have sudo ...
      (Fedora)
    • Re: Forest to Child -- Permissions
      ... My account can login to all the DCs and has full administrator priv. ... first DC in the root. ... the member servers only ... never happen unless some admin has been mucking about. ...
      (microsoft.public.windows.server.dns)