Gentoo Archives: gentoo-hardened

From: Krzysztof Nowicki <krissn@××.pl>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Problems with su on 20120215 policy and latest policycoreutils
Date: Sat, 10 Mar 2012 18:08:40
Message-Id: 5973469-aedce77401fa2190561f5836ed704ed1@pmq2.m5r2.onet
1 Hi,
2
3 Recently I've upgraded the policy to the latest testing version. I've also had to upgrade policycoreutils (+deps) to the versions from the overlay, since they're required by the policies. Everything seems to be working fine for now, but I noticed a problem with su. Every time I try to use it an error is displayed:
4
5 su: Authentication service cannot retrieve authentication info
6
7 This message is displayed regardless of the user executing su (even for root/sysadm_r).
8
9 I did some initial digging and it seems that when su is used, the unix_chkpwd helper is never executed. The helper itself works, because I can see some avc messages from it when logging over ssh. I tried to enable some debugging on pam but with no results.
10
11 Has anyone encountered these problems?
12
13 Best regards
14 Chris

Replies