From owner-freebsd-current@FreeBSD.ORG Mon May 19 11:41:18 2003 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 19FF637B404 for ; Mon, 19 May 2003 11:41:18 -0700 (PDT) Received: from fledge.watson.org (fledge.watson.org [204.156.12.50]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1CA2C43F93 for ; Mon, 19 May 2003 11:41:17 -0700 (PDT) (envelope-from robert@fledge.watson.org) Received: from fledge.watson.org (localhost [127.0.0.1]) by fledge.watson.org (8.12.9/8.12.9) with ESMTP id h4JIenOn061866; Mon, 19 May 2003 14:40:49 -0400 (EDT) (envelope-from robert@fledge.watson.org) Received: from localhost (robert@localhost)h4JIenmJ061863; Mon, 19 May 2003 14:40:49 -0400 (EDT) (envelope-from robert@fledge.watson.org) Date: Mon, 19 May 2003 14:40:49 -0400 (EDT) From: Robert Watson X-Sender: robert@fledge.watson.org To: Frank Bonnet In-Reply-To: <20030519110242.A21561@bart.esiee.fr> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-current@freebsd.org Subject: Re: "su" bug X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 May 2003 18:41:18 -0000 On Mon, 19 May 2003, Frank Bonnet wrote: > I notice at 5.1-BETA-20030507-JPSNAP I am able to "su -" anyone ( even > root ) without typing any passwd from a normal user account. > > The machine use nss_ldap if it makes a difference. Sounds bad. Are you running with any customizations to your PAM configuration; if so, could you post the diffs against /usr/src/etc/pam.d, as well as your nsswitch.conf file? Robert N M Watson FreeBSD Core Team, TrustedBSD Projects robert@fledge.watson.org Network Associates Laboratories