| View previous topic :: View next topic |
| Author |
Message |
Rroet Apprentice


Joined: 27 May 2002 Posts: 176 Location: The Hague, The Netherlands
|
Posted: Mon May 27, 2002 6:12 pm Post subject: su - ? |
|
|
Hia,
I've created a user with normal rights, but this user isn't allowed to run 'su -' to get you know which status...
I find this rather disturbing because now I can't login as myself (which I do over NFS) and just get superuser status to update a package or 2 via the emerge system
Please help... |
|
| Back to top |
|
 |
pjp Administrator


Joined: 16 Apr 2002 Posts: 16032 Location: Colorado
|
Posted: Mon May 27, 2002 6:18 pm Post subject: |
|
|
| Is the user in the wheel group? |
|
| Back to top |
|
 |
Rroet Apprentice


Joined: 27 May 2002 Posts: 176 Location: The Hague, The Netherlands
|
Posted: Mon May 27, 2002 6:30 pm Post subject: |
|
|
no the user isn't in the Wheel group. I didn't know it needed that.
After changing it and re-logging, it didn't work ?! |
|
| Back to top |
|
 |
pjp Administrator


Joined: 16 Apr 2002 Posts: 16032 Location: Colorado
|
Posted: Mon May 27, 2002 6:34 pm Post subject: |
|
|
| Interesting. wheel has been the only reason I've noticed as causing problems. I think it has been posted about numerous times. If you haven't yet, you might search and see if someone else had the same problem. I seem to recall PAM being mentioned, but I don't remember exactly. |
|
| Back to top |
|
 |
fghellar Bodhisattva


Joined: 10 Apr 2002 Posts: 856 Location: Porto Alegre, BR
|
Posted: Mon May 27, 2002 6:35 pm Post subject: |
|
|
| Rroet wrote: | I didn't know it needed that. |
That's what the documentation was written for.
| Rroet wrote: | | After changing it and re-logging, it didn't work ?! |
You probably need to reboot. _________________ | www.gentoo.org | www.tldp.org | www.google.com | |
|
| Back to top |
|
 |
Rroet Apprentice


Joined: 27 May 2002 Posts: 176 Location: The Hague, The Netherlands
|
Posted: Mon May 27, 2002 6:41 pm Post subject: |
|
|
| I think ypserv took care of that. I changed my user to the wheel group and logged on again. That should fix it. |
|
| Back to top |
|
 |
Nitro Bodhisattva


Joined: 08 Apr 2002 Posts: 661 Location: Wisconsin, USA
|
Posted: Mon May 27, 2002 11:13 pm Post subject: |
|
|
| fghellar wrote: |
| Rroet wrote: | | After changing it and re-logging, it didn't work ?! |
You probably need to reboot. |
You don't need to reboot. You just need to re-login. To double check you current user's id and groups run 'id'. I'm not jumping on fgehllar, I just wanted to clarify that. Why hit a nail with a sledgeahmmer?
| Rroet wrote: | | I think ypserv took care of that. I changed my user to the wheel group and logged on again. That should fix it. |
Might want to take a peek at using LDAP for authentication, I think it works much better in my opinion. Just figured I'd mention it. _________________ - Kyle Manna
Please, please SEARCH before posting.
There are three kinds of people in the world: those who can count, and those who can't. |
|
| Back to top |
|
 |
fghellar Bodhisattva


Joined: 10 Apr 2002 Posts: 856 Location: Porto Alegre, BR
|
Posted: Tue May 28, 2002 2:50 am Post subject: |
|
|
| Nitro wrote: | | fghellar wrote: | | You probably need to reboot. |
You don't need to reboot. You just need to re-login. |
Thanks for the correction. I said that because I think I read somewhere that group information is loaded only once, at boot time. I can't seem to find it any more, though... _________________ | www.gentoo.org | www.tldp.org | www.google.com | |
|
| Back to top |
|
 |
pjp Administrator


Joined: 16 Apr 2002 Posts: 16032 Location: Colorado
|
Posted: Tue May 28, 2002 4:43 am Post subject: |
|
|
| Nitro wrote: | | Why hit a nail with a sledgeahmmer? | Sledgehammer probably takes one hit, whereas the hammer would take several? just joking around |
|
| Back to top |
|
 |
Nitro Bodhisattva


Joined: 08 Apr 2002 Posts: 661 Location: Wisconsin, USA
|
Posted: Tue May 28, 2002 9:31 pm Post subject: |
|
|
| kanuslupus wrote: | | Nitro wrote: | | Why hit a nail with a sledgeahmmer? | Sledgehammer probably takes one hit, whereas the hammer would take several? just joking around |
Well, rebooting, like the sledgehammer, would work without a doubt, right.  _________________ - Kyle Manna
Please, please SEARCH before posting.
There are three kinds of people in the world: those who can count, and those who can't. |
|
| Back to top |
|
 |
kabau n00b


Joined: 16 May 2002 Posts: 6 Location: Austin, TX
|
Posted: Fri May 31, 2002 2:23 am Post subject: Removing the wheel restriction |
|
|
To remove the wheel group restriction to su remove:
auth required pam_wheel.so use_uid
from /etc/pam.d/su.
Also, I recommend using sudo or super to do things as root. Much more secure and gives you a log of what commands get executed by root.
kabau |
|
| Back to top |
|
 |
|