[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [OT] sudo: restrict to physical console only?



On Tue, Aug 04, 2020 at 11:44:04AM +0200, Marco Möller wrote:
> On 04.08.20 10:59, tomas@tuxteam.de wrote:

[pam sshd]

> Sorry, I will not have been clear enough, or did not understand your
> answer clearly, ssh and pam are both new to me, and I also never
> configured sudo myself.

Ah, got it. Then sudo is your first stop :-)

It's configured via /etc/sudoers.conf (there is a special command
to edit that file). Proceed with care, since botching it might
make it more difficult to access your box :-)

Not all is lost, however if something goes awry.

The relevant documentation is in sudoers(5). I think you are
looking for 'requiretty', there, although I'm not sure whether
that will be as restrictive as you envision. Perhaps you need
to tweak your PAM setup for that as well.

Sorry for just providing generic pointers. I'd have to experiment
around to be more concrete, but I currently try to avoid rabbit
holes...

Cheers
 - t

Attachment: signature.asc
Description: Digital signature


Reply to: