Gentoo Archives: gentoo-dev

From: Scott Moynes <smoynes@××××××××××××××.ca>
To: gentoo-dev@g.o
Subject: Re: [gentoo-dev] Su access restrictions
Date: Tue, 09 Apr 2002 13:08:38
Message-Id: 20020409181138.GB3819@marilyn
In Reply to: Re: [gentoo-dev] Su access restrictions by mrfab@arn.net
1 * mrfab@×××.net (mrfab@×××.net) wrote:
2 > I understand the value of pam in general--just not
3 > for this specific task.
4 >
5 > root:ALL EXCEPT GROUP wheel:DENY in /etc/suauth
6 > would effectivly emulate the current pam
7 > restriction in what I would consider to be a
8 > clearer manner.
9 >
10 > Personally, when I noticed su was restricted for
11 > users, the first place I looked was /etc/suauth,
12 > the second /etc/login.defs and only in the end
13 > at /etc/pam.d/
14
15 In this particular case, it seems to be a matter of developers
16 preference. Personally, whenever I want to tweak authentication I
17 check pam first, then search the particular application's
18 documentation for its methods. To me, it seems cleaner to have like
19 things together.
20
21 But, whatever.
22 --
23 Scott Moynes
24 "Anyone who considers arithmetical methods of producing random numbers
25 is, of course, in a state of sin." -- John Von Neumann