On Tue, 2003-09-09 at 01:09, Gordon Messmer wrote:
> lists wrote:
> > One work around that I have found is to comment out the first line in 
> > the sshd pam configuration.
> > 
> > #%PAM-1.0
> > #auth       required     pam_stack.so service=system-auth
> > auth       required     pam_nologin.so
> > account    required     pam_stack.so service=system-auth
> > password   required     pam_stack.so service=system-auth
> > session    required     pam_stack.so service=system-auth
> > session    required     pam_limits.so
> > session    optional     pam_console.so
> 
> Have you verified that users who enter the wrong password are not 
> allowed to log in?  It looks to me like they would be.
> 


I just tried it since I was wondering the same thing and yes you are
right.  You get prompted for a passwd and then no matter what you enter
you get a shell.

BAD IDEA GUYS

Bret


-- 
redhat-list mailing list
unsubscribe mailto:[EMAIL PROTECTED]
https://www.redhat.com/mailman/listinfo/redhat-list

Reply via email to