summaryrefslogtreecommitdiff
path: root/debian
diff options
context:
space:
mode:
authorDonatas Abraitis <donatas@opensourcerouting.org>2024-01-16 21:14:30 +0200
committerDonatas Abraitis <donatas@opensourcerouting.org>2024-01-28 19:50:06 +0200
commite68c4f053905de7bc965667d57c330d080441cad (patch)
treec819132d7c39400d8d899246a1b596f13727aaaa /debian
parent4d92badcde7573b97d2acc2228d0ca5fe7168e1e (diff)
packaging: Just permit anything if PAM is enabled
With a current pam_rootok.so, it works only with `root` account. If the user is under `frrvty`, `frr` group, it gets the error: ``` % groups | grep -o -E "frrvty|frr" frrvty frr % vtysh -c 'end' vtysh_pam: Failed in account validation: Permission denied(6) ``` Checking the logs: ``` vtysh[23930]: pam_rootok(frr:account): root check failed ``` Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
Diffstat (limited to 'debian')
-rw-r--r--debian/frr.pam2
1 files changed, 1 insertions, 1 deletions
diff --git a/debian/frr.pam b/debian/frr.pam
index 737b88953b..1077243a12 100644
--- a/debian/frr.pam
+++ b/debian/frr.pam
@@ -1,4 +1,4 @@
# Any user may call vtysh but only those belonging to the group frrvty can
# actually connect to the socket and use the program.
auth sufficient pam_permit.so
-account sufficient pam_rootok.so
+account sufficient pam_permit.so