summaryrefslogtreecommitdiff
path: root/redhat
diff options
context:
space:
mode:
authorDonatas Abraitis <donatas@opensourcerouting.org>2024-01-16 21:14:30 +0200
committerDonatas Abraitis <donatas@opensourcerouting.org>2024-01-28 19:50:06 +0200
commite68c4f053905de7bc965667d57c330d080441cad (patch)
treec819132d7c39400d8d899246a1b596f13727aaaa /redhat
parent4d92badcde7573b97d2acc2228d0ca5fe7168e1e (diff)
packaging: Just permit anything if PAM is enabled
With a current pam_rootok.so, it works only with `root` account. If the user is under `frrvty`, `frr` group, it gets the error: ``` % groups | grep -o -E "frrvty|frr" frrvty frr % vtysh -c 'end' vtysh_pam: Failed in account validation: Permission denied(6) ``` Checking the logs: ``` vtysh[23930]: pam_rootok(frr:account): root check failed ``` Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
Diffstat (limited to 'redhat')
-rw-r--r--redhat/frr.pam4
1 files changed, 2 insertions, 2 deletions
diff --git a/redhat/frr.pam b/redhat/frr.pam
index 17a62f1999..a574c5e575 100644
--- a/redhat/frr.pam
+++ b/redhat/frr.pam
@@ -4,8 +4,8 @@
##### if running frr as root:
# Only allow root (and possibly wheel) to use this because enable access
# is unrestricted.
-auth sufficient pam_rootok.so
-account sufficient pam_rootok.so
+auth sufficient pam_permit.so
+account sufficient pam_permit.so
# Uncomment the following line to implicitly trust users in the "wheel" group.
#auth sufficient pam_wheel.so trust use_uid