Re: Allow logins only via su? Never via xdm/gdm or login prompt?

From: Walter Roberson (roberson_at_ibd.nrc-cnrc.gc.ca)
Date: 06/30/03


Date: 30 Jun 2003 21:29:15 GMT

In article <3F00A192.AE1A6345@noaa.gov>,
Stowell Davison <Stowell.Davison@noaa.gov> wrote:
:This is a multi-part message in MIME format.

MIME has no place in newsgroups that do not specifically permit it :(

:We have a few accounts that must be accessible to
:several people. I'd like to allow login to these
:accounts only via su; never from a gdm/xdm login
:screen or a text mode login prompt. Is there any
:way to impose such a restriction?

You'll have to tell us exactly which OS you are using, and which
version of it.

I seem to recall hearing that you could do something like that with
SunOS.

Under SGI's IRIX, I can't think of any way that is certain to handle
it. What might have a chance, though, would be to modify
/etc/default/login to set SITECHECK, and have the sitecheck program
reject all logins to that account. It appears that the 'su' program
might bypass SITECHECK, thus allowing you to login in to that account.

-- 
Ceci, ce n'est pas une idée.


Relevant Pages

  • Re: Repost: Local logon and Network Access settings
    ... think require network login since they are over the wire do in fact ... In the default situation, Authenticated Users ... is a member of User on a member machine, and, Users are granted ... user accounts that should be allowed to log into the machines in SomeOU. ...
    (microsoft.public.windows.group_policy)
  • Re: Repost: Local logon and Network Access settings
    ... > think require network login since they are over the wire do in fact ... In the default situation, Authenticated Users ... > is a member of User on a member machine, and, Users are granted ... > user accounts that should be allowed to log into the machines in SomeOU. ...
    (microsoft.public.windows.group_policy)
  • =?ISO-8859-1?Q?Re:_RE:_Prob:_failed_to_verify_krb5_credentials:_Server_not_?= =?ISO-8859
    ... Every user shall login with its already existing AD accounts. ... These are the logins, which I try to enter in the login prompt when I visit http://wiki.test.lan:8080. ... I did a nslookup on the unix system and it showed me the server as ... AD, thats also in the keytab file, is TWikiUser. ...
    (comp.protocols.kerberos)
  • Re: Account Lockout Policies
    ... Allowing accounts to remain dormat for 30 days ... If a technical solution is unavoidable due to a lack of management buy-in, ... Extract login details from the security logs. ...
    (microsoft.public.security)
  • AIX password enumeration possible
    ... BPR personnel can neither confirm or deny this behaviour exists in any OS other than AIX of versions mentioned below. ... In the case that the correct password is provided, the response is as follows: ... believed to be in the response from the login program after authentication ... Give accounts that have been restricted from remote logins strong passwords. ...
    (Bugtraq)

Loading