[K12OSN] Huge security issue

Dan Young dyoung at mesd.k12.or.us
Fri Feb 9 17:05:50 UTC 2007


Daniel Kuecker wrote:
> gdm:
> 
> #%PAM-1.0
> auth            required                pam_mount.so # use_first_pass
> 
> auth       required    pam_env.so
> #auth       include     system-auth

Any reason for commenting out "auth include system-auth"?

Without including the "auth" section from /etc/pam.d/system-auth, gdm
never hits the pam_deny if the password is wrong.

-- 
Dan Young <dyoung at mesd.k12.or.us>
Multnomah ESD - Technology Services
503-257-1562




More information about the K12OSN mailing list