The
pam_timestamp.so
module accepts several directives. Below are the two most commonly
used options:
•
timestamp_timeout
— Specifies the number of seconds the during which the timestamp file
is valid (in seconds). The default value is 300 seconds (five minutes).
•
timestampdir
— Specifies the directory in which the timestamp file is stored. The default
value is
/var/run/sudo/
.
For more information about controlling the
pam_timestamp.so
module, refer to
Section 8.1,
“Installed Documentation”
.
7. PAM and Device Ownership
Red Hat Enterprise Linux allows the first user to log in on the physical console of the machine
the ability to manipulate some devices and perform some tasks normally reserved for the root
user. This is controlled by a PAM module called
pam_console.so
.
7.1. Device Ownership
When a user logs into a Red Hat Enterprise Linux system, the
pam_console.so
module is
called by
login
or the graphical login programs, gdm and kdm. If this user is the first user to
log in at the physical console — called the console user — the module grants the user
ownership of a variety of devices normally owned by root. The console user owns these devices
until the last local session for that user ends. Once the user has logged out, ownership of the
devices reverts back to the root user.
The devices affected include, but are not limited to, sound cards, diskette drives, and CD-ROM
drives.
This allows a local user to manipulate these devices without attaining root access, thus
simplifying common tasks for the console user.
By modifying the file
/etc/security/console.perms
, the administrator can edit the list of
devices controlled by
pam_console.so
.
Warning
If the gdm, kdm, or xdm display manager configuration file has been altered to
allow remote users to log in and the host is configured to run at runlevel 5, it is
advisable to change the
<console>
and
<xconsole>
directives within the
/etc/security/console.perms
to the following values:
<console>=tty[0-9][0-9]* vc/[0-9][0-9]* :0\.[0-9] :0 <xconsole>=:0\.[0-9]
:0
PAM and Device Ownership
305
Summary of Contents for ENTERPRISE LINUX 4.5.0 -
Page 1: ...Red Hat Enterprise Linux 4 5 0 4 5 0 Reference Guide ISBN N A Publication date ...
Page 2: ...Red Hat Enterprise Linux 4 5 0 ...
Page 4: ...Red Hat Enterprise Linux 4 5 0 ...
Page 24: ...xxiv ...
Page 26: ......
Page 36: ...12 ...
Page 72: ...48 ...
Page 112: ...88 ...
Page 122: ...98 ...
Page 140: ...116 ...
Page 142: ......
Page 300: ...276 ...
Page 318: ...294 ...
Page 320: ......
Page 332: ...308 ...
Page 350: ...326 ...
Page 378: ...354 ...
Page 388: ...364 ...
Page 394: ...370 ...
Page 395: ...Part IV Appendixes ...
Page 396: ......