Operating System - HP-UX
1820548 Members
5430 Online
109626 Solutions
New Discussion юеВ

Configure PAM for restricting su

 
Vivek Bhatia
Trusted Contributor

Configure PAM for restricting su

Hi I want to configure PAM so that people cannot su to a particular group.

Need Help on this urgently.

Thanks
Vivek Bhatia
2 REPLIES 2
Steven E. Protter
Exalted Contributor

Re: Configure PAM for restricting su

Shalom Vivek,

http://docs.hp.com/en/1408/ADSLDUX.pdf

Typical file su in the pam.d directory

#%PAM-1.0
#auth sufficient /lib/security/$ISA/pam_rootok.so
# Uncomment the following line to implicitly trust users in the "wheel" group.
#auth sufficient /lib/security/$ISA/pam_wheel.so trust use_uid
# Uncomment the following line to require a user to be in the "wheel" group.
#auth required /lib/security/$ISA/pam_wheel.so use_uid
auth required /lib/security/$ISA/pam_stack.so service=system-auth
account required /lib/security/$ISA/pam_stack.so service=system-auth
password required /lib/security/$ISA/pam_stack.so service=system-auth
# pam_selinux.so close must be first session rule
session required /lib/security/$ISA/pam_selinux.so close
session required /lib/security/$ISA/pam_stack.so service=system-auth
# pam_selinux.so open and pam_xauth must be last two session rules
session required /lib/security/$ISA/pam_selinux.so open
session optional /lib/security/$ISA/pam_xauth.so


To enable su we uncomment the first valid line in that file.

Example is from Linux.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Vivek Bhatia
Trusted Contributor

Re: Configure PAM for restricting su

HI Potter,

Actully i want to block the switch user , that no one would be able to do a su - to users of certain group.

Please Help!!

Thanks
Vivek Bhatia