Bug 13245 - Remote telnet access is not controlled by /etc/security/access.conf
Summary: Remote telnet access is not controlled by /etc/security/access.conf
Keywords:
Status: CLOSED WORKSFORME
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: inetd
Version: 6.2
Hardware: i386
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Jeff Johnson
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2000-06-29 22:47 UTC by jason
Modified: 2008-05-01 15:37 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2000-07-03 13:51:18 UTC
Embargoed:


Attachments (Terms of Use)

Description jason 2000-06-29 22:47:06 UTC
The /etc/security/access.conf file says that it will restrict access 
(login).  However, when you try something like this:

-:ALL EXCEPT jason:ALL

which should deny access to all except for account jason (connection from 
all - console & remote) locations.  This does not work.  Despite the 
above, other users are able to log in without problem.

Comment 1 Nalin Dahyabhai 2000-07-03 07:55:17 UTC
Does your /etc/pam.d/login file include the line:
account  required       /lib/security/pam_access.so


Comment 2 jason 2000-07-03 13:51:17 UTC
That's it!

By default installation /etc/pam.d/login file does not include the line:
account  required       /lib/security/pam_access.so

Where is this documented?  I looked everywhere.  I recommend that RH put this 
in by default if you are going to keep the /etc/security directory.  Or, put 
this required information in the header of the /etc/security/access file.

Thanks for the help.


Comment 3 Jeff Johnson 2000-07-27 19:04:09 UTC
This problem appears to be solved.


Note You need to log in before you can comment on or make changes to this bug.