From owner-freebsd-questions@FreeBSD.ORG Fri Oct 7 17:02:21 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E8EC816A41F for ; Fri, 7 Oct 2005 17:02:21 +0000 (GMT) (envelope-from lavalamp@spiritual-machines.org) Received: from mail.digitalfreaks.org (arbitor.digitalfreaks.org [216.151.95.158]) by mx1.FreeBSD.org (Postfix) with ESMTP id 146CB43D4C for ; Fri, 7 Oct 2005 17:02:21 +0000 (GMT) (envelope-from lavalamp@spiritual-machines.org) Received: by mail.digitalfreaks.org (Postfix, from userid 1022) id 71C971141D; Fri, 7 Oct 2005 13:02:20 -0400 (EDT) Received: from localhost (localhost [127.0.0.1]) by mail.digitalfreaks.org (Postfix) with ESMTP id 706DB1141A; Fri, 7 Oct 2005 13:02:20 -0400 (EDT) Date: Fri, 7 Oct 2005 13:02:20 -0400 (EDT) From: "Brian A. Seklecki" X-X-Sender: lavalamp@arbitor.digitalfreaks.org To: =?iso-8859-1?q?Dag-Erling_Sm=F8rgrav?= In-Reply-To: <86k6gp8fsf.fsf@xps.des.no> Message-ID: <20051007130127.Y95280@arbitor.digitalfreaks.org> References: <20051007114027.Y95280@arbitor.digitalfreaks.org> <86k6gp8fsf.fsf@xps.des.no> MIME-Version: 1.0 Content-Type: MULTIPART/MIXED; BOUNDARY="0-935750738-1128704540=:95280" Cc: freebsd-questions@freebsd.org Subject: Re: pam_rootok(8) + pam.d/sudo symlink to pam.d/su X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 07 Oct 2005 17:02:22 -0000 This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. --0-935750738-1128704540=:95280 Content-Type: TEXT/PLAIN; charset=iso-8859-1; format=flowed Content-Transfer-Encoding: 8BIT sudo-1.6.8.9 via Ports. Is there any way to set PAM to trace/debug it's decision making process? ~BAS On Fri, 7 Oct 2005, Dag-Erling Smørgrav wrote: > "Brian A. Seklecki" writes: >> However, when I do that, all wheel-group users are automatically >> passing auth requirements due to: >> >> auth sufficient pam_rootok.so no_warn >> >> ...which I assume is happening because sudo(8) is running SUID root? > > No, unless sudo is broken. What sudo implementation are you using? > > DES > -- > Dag-Erling Smørgrav - des@des.no > > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org" > l8* -lava x.25 - minix - bitnet - plan9 - 110 bps - ASR 33 - base8 --0-935750738-1128704540=:95280--