Hi List,


We currently have the following config in /etc/pam.d/system-auth on a RHEL 6.3 staging server:



# This file is auto-generated.

# User changes will be destroyed the next time authconfig is run.

auth        required

#auth      sufficient

#auth      sufficient nullok try_first_pass

#auth      requisite uid >= 500 quiet

#auth      required

auth        required preauth audit silent deny=5

auth        [success=1 default=bad]

auth        [default=die] authfail audit deny=5

auth        sufficient authsucc audit deny=5

account  required

account  sufficient

account  sufficient uid < 500 quiet

account  required


After testing in our staging server, “su - root” and “sudo su – root” command are not working if "auth required" is enable in /etc/pam.d/system-auth

Would like to check if there are any areas that might be misconfigure.





Keng Lim


