Re: Error in /etc/pam.d/su ??

From: Kris Kennaway <kris_at_obsecurity.org>
Date: Thu, 21 Oct 2004 09:56:44 -0700
On Thu, Oct 21, 2004 at 02:56:52PM +0200, Roman Kennke wrote:
> Hi there,
> 
> I just upgraded RELENG_5. Now it seems, that su lets me into root
> without a passwd.
> Checking /etc/pam.d/su it seems that there is an include control flag,
> which isn't recognized:
> 
> auth            include         system
> account         include         system
> 
> I suppose this must be changed to required or requisite? I am no PAM
> expert, but this seems like a serious bug to me.

If it's not recognized on your system, you haven't done a complete
upgrade to RELENG_5 - it's been recognized there for a long time now.

Kris

Received on Thu Oct 21 2004 - 14:56:39 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:38:18 UTC