mirror of
https://git.proxmox.com/git/mirror_frr
synced 2025-08-08 10:56:37 +00:00
packaging: Just permit anything if PAM is enabled
With a current pam_rootok.so, it works only with `root` account. If the user is under `frrvty`, `frr` group, it gets the error: ``` % groups | grep -o -E "frrvty|frr" frrvty frr % vtysh -c 'end' vtysh_pam: Failed in account validation: Permission denied(6) ``` Checking the logs: ``` vtysh[23930]: pam_rootok(frr:account): root check failed ``` Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
This commit is contained in:
parent
4d92badcde
commit
e68c4f0539
2
debian/frr.pam
vendored
2
debian/frr.pam
vendored
@ -1,4 +1,4 @@
|
|||||||
# Any user may call vtysh but only those belonging to the group frrvty can
|
# Any user may call vtysh but only those belonging to the group frrvty can
|
||||||
# actually connect to the socket and use the program.
|
# actually connect to the socket and use the program.
|
||||||
auth sufficient pam_permit.so
|
auth sufficient pam_permit.so
|
||||||
account sufficient pam_rootok.so
|
account sufficient pam_permit.so
|
||||||
|
@ -4,8 +4,8 @@
|
|||||||
##### if running frr as root:
|
##### if running frr as root:
|
||||||
# Only allow root (and possibly wheel) to use this because enable access
|
# Only allow root (and possibly wheel) to use this because enable access
|
||||||
# is unrestricted.
|
# is unrestricted.
|
||||||
auth sufficient pam_rootok.so
|
auth sufficient pam_permit.so
|
||||||
account sufficient pam_rootok.so
|
account sufficient pam_permit.so
|
||||||
|
|
||||||
# Uncomment the following line to implicitly trust users in the "wheel" group.
|
# Uncomment the following line to implicitly trust users in the "wheel" group.
|
||||||
#auth sufficient pam_wheel.so trust use_uid
|
#auth sufficient pam_wheel.so trust use_uid
|
||||||
|
Loading…
Reference in New Issue
Block a user