rhel5下限值用户使用su切换身份
rhel5默認情況下,任何用戶都可以用su切換身份。為了安全我們可以做如下限值:
1:編輯文件 /etc/pam.d/su,修改源文件如下
#%PAM-1.0
auth??????????? sufficient????? pam_rootok.so
# Uncomment the following line to implicitly trust users in the "wheel" group.
#auth?????????? sufficient????? pam_wheel.so trust use_uid
# Uncomment the following line to require a user to be in the "wheel" group.
auth??????????? required??????? pam_wheel.so use_uid
auth??????????? include???????? system-auth
account???????? sufficient????? pam_succeed_if.so uid = 0 use_uid quiet
account???????? include???????? system-auth
password??????? include???????? system-auth
session???????? include???????? system-auth
session???????? optional??????? pam_xauth.so
2:編輯 /etc/group文件,把可以執(zhí)行su的用戶加入到wheel組即可
轉(zhuǎn)載于:https://blog.51cto.com/jarson/290414
總結(jié)
以上是生活随笔為你收集整理的rhel5下限值用户使用su切换身份的全部內(nèi)容,希望文章能夠幫你解決所遇到的問題。
- 上一篇: 中行数字信用卡怎么使用
- 下一篇: 如何客观评价王石 看看业内人士怎么说