* Ben Collins said: > > This is a VERY VERY good question. Our su is heavily patched to work > > like GNU su, and still does a poor job of it. Why don't we just use > > the GNU su in Red Hat's sh-utils package, since it's been patched for > > proper PAM support? > > Where do you get that shadow's su does not use PAM session management? > Stop spreading bogus information. Yes, it does, but the pam_limits stuff won't work anyway. The PAM takes place BEFORE changing the persona - the limits of the target are NEVER enforced (not even if you su - to root!). That's bad. marek
Attachment:
pgpVbDJv0PaJK.pgp
Description: PGP signature