Query: pam_wheel
OS: linux
Section: 8
Format: Original Unix Latex Style Formatted with HTML and a Horizontal Scroll Bar
PAM_WHEEL(8) Linux-PAM Manual PAM_WHEEL(8)NAMEpam_wheel - Only permit root access to members of group wheelSYNOPSISpam_wheel.so [debug] [deny] [group=name] [root_only] [trust]DESCRIPTIONThe pam_wheel PAM module is used to enforce the so-called wheel group. By default it permits root access to the system if the applicant user is a member of the wheel group. If no group with this name exist, the module is using the group with the group-ID 0.OPTIONSdebug Print debug information. deny Reverse the sense of the auth operation: if the user is trying to get UID 0 access and is a member of the wheel group (or the group of the group option), deny access. Conversely, if the user is not in the group, return PAM_IGNORE (unless trust was also specified, in which case we return PAM_SUCCESS). group=name Instead of checking the wheel or GID 0 groups, use the name group to perform the authentication. root_only The check for wheel membership is done only. trust The pam_wheel module will return PAM_SUCCESS instead of PAM_IGNORE if the user is a member of the wheel group (thus with a little play stacking the modules the wheel members may be able to su to root without being prompted for a passwd).MODULE TYPES PROVIDEDThe auth and account module types are provided.RETURN VALUESPAM_AUTH_ERR Authentication failure. PAM_BUF_ERR Memory buffer error. PAM_IGNORE The return value should be ignored by PAM dispatch. PAM_PERM_DENY Permission denied. PAM_SERVICE_ERR Cannot determine the user name. PAM_SUCCESS Success. PAM_USER_UNKNOWN User not known.EXAMPLESThe root account gains access by default (rootok), only wheel members can become root (wheel) but Unix authenticate non-root applicants. su auth sufficient pam_rootok.so su auth required pam_wheel.so su auth required pam_unix.soSEE ALSOpam.conf(5), pam.d(5), pam(7)AUTHORpam_wheel was written by Cristian Gafton <gafton@redhat.com>. Linux-PAM Manual 05/31/2011 PAM_WHEEL(8)
Related Man Pages |
---|
pam_sepermit(8) - centos |
pam_listfile(8) - linux |
pam_listfile(8) - debian |
pam_sepermit(8) - debian |
pam_wheel(8) - debian |
Similar Topics in the Unix Linux Community |
---|
create or modify user account to have same access as root |
user list |
To What files root does not have access to?? |
system, wheel and everyone |
Permissions |