Bug 153208 - pam_tally broken in pam-0.79-1
pam_tally broken in pam-0.79-1
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: pam (Show other bugs)
rawhide
x86_64 Linux
medium Severity medium
: ---
: ---
Assigned To: Tomas Mraz
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2005-04-02 20:41 EST by Thomas Zehetbauer
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version: pam-0.79-2
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2005-04-03 13:15:54 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Thomas Zehetbauer 2005-04-02 20:41:29 EST
I could no longer login/su after updating to pam-0.79-1

/etc/pam.d/system-auth contained:
  auth        optional      pam_tally.so no_magic_root
  account     required      pam_tally.so deny=5 no_magic_root
causes the following to be logged
  pam_tally: unknown option; no_magic_root
  pam_tally: option deny=5 allowed in auth phase only
  pam_tally: unknown option; no_magic_root
  su(pam_unix)[16773]: session opened for user root by thomasz(uid=500)
  pam_tally: unknown option; no_magic_root
  kernel: su[16774]: segfault at 0000000000000000 rip 00002aaaadfbb530 rsp
00007ffffffff450 error 4
and with the options removed:
  su(pam_unix)[17007]: session opened for user root by thomasz(uid=500)
  su(pam_unix)[17007]: session closed for user root
  kernel: su[17008]: segfault at 0000000000000000 rip 00002aaaadfbb530 rsp
00007ffffffff450 error 4
Comment 1 Tomas Mraz 2005-04-03 12:31:17 EDT
The pam_tally module is redesigned in pam-0.79. This redesign was necessary to
fix bug 60930.

So you need to rearrange the options according to the README.pam_tally provided
with the package.

However su shouldn't segfault. So could you please attach your
/etc/pam.d/system-auth and /etc/pam.d/su here and also could you please try to
obtain a backtrace from the crashing su binary?
Comment 2 Tomas Mraz 2005-04-03 13:15:54 EDT
Actually it's not necessary anymore - I know where the bug is. Upgrade to
pam-0.79-2 when it's available. However you will need to rearrange the options
anyway.

Note You need to log in before you can comment on or make changes to this bug.