38
Chapter 4. Workstation Security
If the administrator wants to deny access to multiple services, he can add a similar line to the PAM
configuration services, such as
/etc/pam.d/pop
and
/etc/pam.d/imap
for mail clients or
/etc/pam.d/ssh
for SSH clients.
For more information about PAM, see the chapter titled Pluggable Authentication Modules (PAM) in
the Official Red Hat Linux Reference Guide.
4.4.3. Limiting Root Access
Often, rather than completely deny access to the root user, the administrator may wish to allow access
only via setuid programs, such as
su
or
sudo
.
4.4.3.1. The
su
Command
When a user types the command
su
she is prompted for the root password and, after authentication,
given a root shell prompt.
Once logged in via the
su
command, the user is the root user and has absolute administrative access
to the system. In addition, once a user has attained root, it is possible in some cases for them to use
the
su
command to change to any other user on the system without being prompted for a password.
Because this program is so powerful, administrators may wish to limit who has access to the command.
One of the simplest ways to do this is to add users to the special administrative group called wheel.
To do this, type the following command as root:
usermod  G wheel username
To use the User Manager for this purpose, go to the Main Menu Button (on the Panel) => System
Settings => Users & Groups or type the command
redhat config users
at a shell prompt. Select
the Users tab, select the user from the user list, and click Properties from the button menu (or choose
File => Properties from the pull down menu).
Then select the Groups tab and click on the wheel group, as shown in Figure 4 2.
Figure 4 2. User Groups Pane






footer




 

 

 

 

 Home | About Us | Network | Services | Support | FAQ | Control Panel | Order Online | Sitemap | Contact

web hosting comparison

 

Our partners: PHP: Hypertext Preprocessor Best Web Hosting Java Web Hosting Inexpensive Web Hosting  Jsp Web Hosting

Cheapest Web Hosting Jsp Hosting Cheap Hosting

Visionwebhosting.net Business web hosting division of Web Design Plus. All rights reserved