home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sgi
- Path: sparky!uunet!utcsri!skule.ecf!epas!adam
- From: adam@epas.utoronto.ca (Adam Iles)
- Subject: Re: restricing root logins
- Organization: University of Toronto - EPAS
- Date: Tue, 10 Nov 1992 13:49:56 GMT
- Message-ID: <1992Nov10.134956.525@epas.toronto.edu>
- References: <1992Nov10.000731.2740@alias.com>
- Sender: news@epas.toronto.edu (USENET)
- Nntp-Posting-Host: epas.utoronto.ca
- Lines: 21
-
- In article <1992Nov10.000731.2740@alias.com> chk@alias.com (C. Harald Koch) writes:
- >Is it possible to restrict root logins to certain ttys? Right now, anyone can
- >login as root on any terminal line attached to our machines (including modems).
- >We want to be able to restrict this, so that root logins are allowed only on
- >"secure" terminals, i.e. those in the computer room. For other lines, we want
- >people to login as themselves and then su, so we have at least some idea who
- >became root.
- >
- >BSD Un*x had a configuration file listing "secure ttys"; is there an IRIX
- >equivalent?
-
- If you are willing to give root or restricted accounts a special shell
- (which could be a symbolic link to a standard shell) you could create
- /etc/dialups and /etc/d_passwd files to put an invalid password on all
- the "unsecure ttys." The information on these files is in the login(1)
- man page.
-
- --
- Adam Iles Fractals:
- EPAS Computing, University of Toronto The tie-dye of the 90's
- adam@epas.utoronto.ca
-