|
发表于 2003-8-25 17:28:56
|
显示全部楼层
我实验了一下,su 和sudo是2个概念
visudo,加
Cmnd_Alias SU=/bin/su
tower ALL=!SU
此时用tower不能sudo su,但然可以直接su
---------------------------------------------------
问题是我照着vsftpd的pam文件改了su 的pam
auth required pam_listfile.so item=user sense=deny file=/etc/sudeny onerr=succeed
auth sufficient /lib/security/pam_rootok.so
auth required /lib/security/pam_stack.so service=system-auth
account required /lib/security/pam_stack.so service=system-auth
password required /lib/security/pam_stack.so service=system-auth
session required /lib/security/pam_stack.so service=system-auth
session optional /lib/security/pam_xauth.so
--------------------------------------------------
添加/etc/sudeny后,好象没有作用,原来在其他服务的pam文件中加上pam_listfile都有用的,这次不知问题处在那里????? |
|