* Enable the `chfn' program. Note that by default non-root users are
still not permitted to change their account information, as specified in login.defs. svn path=/nixos/trunk/; revision=22049
This commit is contained in:
parent
39ea835dbc
commit
540c673364
@ -12,3 +12,7 @@ GID_MAX 29999
|
|||||||
|
|
||||||
TTYGROUP tty
|
TTYGROUP tty
|
||||||
TTYPERM 0620
|
TTYPERM 0620
|
||||||
|
|
||||||
|
# Uncomment this to allow non-root users to change their account
|
||||||
|
#information. This should be made configurable.
|
||||||
|
#CHFN_RESTRICT frwh
|
||||||
|
@ -204,6 +204,7 @@ in
|
|||||||
{ name = "sshd"; }
|
{ name = "sshd"; }
|
||||||
{ name = "xlock"; }
|
{ name = "xlock"; }
|
||||||
{ name = "chsh"; rootOK = true; }
|
{ name = "chsh"; rootOK = true; }
|
||||||
|
{ name = "chfn"; rootOK = true; }
|
||||||
{ name = "su"; rootOK = true; forwardXAuth = true; }
|
{ name = "su"; rootOK = true; forwardXAuth = true; }
|
||||||
# Note: useradd, groupadd etc. aren't setuid root, so it
|
# Note: useradd, groupadd etc. aren't setuid root, so it
|
||||||
# doesn't really matter what the PAM config says as long as it
|
# doesn't really matter what the PAM config says as long as it
|
||||||
|
@ -74,7 +74,7 @@ in
|
|||||||
config = {
|
config = {
|
||||||
|
|
||||||
security.setuidPrograms =
|
security.setuidPrograms =
|
||||||
[ "passwd" "su" "crontab" "ping" "ping6"
|
[ "passwd" "chfn" "su" "crontab" "ping" "ping6"
|
||||||
"fusermount" "wodim" "cdrdao" "growisofs"
|
"fusermount" "wodim" "cdrdao" "growisofs"
|
||||||
];
|
];
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user