We help IT Professionals succeed at work.

Can't login console as root, works everywhere else, also difference between console / local?

ldorazio
ldorazio asked
on
1,486 Views
Last Modified: 2013-12-16
In /etc/security/access.conf with CentOS (kernel 2.6.9-42.0.10.ELsmp) I have the following:
-:ALL EXCEPT root:LOCAL

Which I thought would ALLOW root to login at the console, but it's not. I tried to login as another user on the console, also didn't allow.

Then I saw on the Internet some people using "CONSOLE" instead of "LOCAL" but I don't understand the difference.

I want root and others to be able to SSH and I want root to be able to login at the console.

Then I also saw + instead of - and now I'm just confused. I need it to work. I wouldn't even mind if everybody could logon at the console, although that's less desirable.



Comment
Watch Question

Author

Commented:
That article is pretty good, it explains the - and + pretty well, but what about the LOCAL and CONSOLE, what is the difference if you list these two lines?
-:ALL EXCEPT root:LOCAL

or

-:ALL EXCEPT root:CONSOLE

Also, I'm using the top one, which I assume means "deny all users except allow root, on the local computer (not remote)", but it doesn't allow root to login locally (on the console).

What's the diff of LOCAL and CONSOLE ?

And if I want to just get rid of ALL of it, do I just delete the line, then there is no security?

Commented:
My guess on the LOCAL vs CONSOLE would be that console is the physical console, ie the keyboard on the PC or one of it's alternates.  LOCAL would be using su to assume identity as root through whatever remote connection you are using.

Again, that's my guess ...

Cheers!
hi, did you check your  /etc/securetty  file?
does it include the line "console" ?
also you have to check sshd configuration (/etc/ssh/sshd_config) to let people and root login :

PermitRootLogin yes

Author

Commented:
Good ideas, but didn't help to resolve the issue. Appears to be problem between 32-bit and 64-bit OS, when Bastille scripts are installed.

Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.