summaryrefslogtreecommitdiff
path: root/modules/pam_securetty/README
diff options
context:
space:
mode:
authorSteve Langasek <steve.langasek@ubuntu.com>2019-01-03 21:23:37 -0800
committerSteve Langasek <vorlon@debian.org>2019-01-08 22:11:51 -0800
commit7e6c4749370338c9af7e1b959f8ab96d089786d6 (patch)
tree2da5e702d7da7b222237ea5ac71e208dd70791a6 /modules/pam_securetty/README
parentfa4960114fc50965a9696f2db7406a9d792e3ff8 (diff)
parent795badba7f95e737f979917859cd32c9bd47bcad (diff)
Merge upstream version 1.1.8
Diffstat (limited to 'modules/pam_securetty/README')
-rw-r--r--modules/pam_securetty/README10
1 files changed, 9 insertions, 1 deletions
diff --git a/modules/pam_securetty/README b/modules/pam_securetty/README
index d4ee5f97..14518411 100644
--- a/modules/pam_securetty/README
+++ b/modules/pam_securetty/README
@@ -7,7 +7,9 @@ DESCRIPTION
pam_securetty is a PAM module that allows root logins only if the user is
logging in on a "secure" tty, as defined by the listing in /etc/securetty.
pam_securetty also checks to make sure that /etc/securetty is a plain file and
-not world writable.
+not world writable. It will also allow root logins on the tty specified with
+console= switch on the kernel command line and on ttys from the /sys/class/tty/
+console/active.
This module has no effect on non-root users and requires that the application
fills in the PAM_TTY item correctly.
@@ -21,6 +23,12 @@ debug
Print debug information.
+noconsole
+
+ Do not automatically allow root logins on the kernel console device, as
+ specified on the kernel command line or by the sys file, if it is not also
+ specified in the /etc/securetty file.
+
EXAMPLES
auth required pam_securetty.so