If I login as say user1,  I want that user to be able to su - oracle, but not 
to say su - root (or to any other user).

If user2 logins I want them unable to su - X at all and especially not root.

If an admin logins in I want them to be able to su - anybody...

In a way before I could do that with the wheel group and pam.


Steven Jones

Technical Specialist - Linux RHCE

Victoria University, Wellington, NZ

0064 4 463 6272

From: Rob Crittenden [rcrit...@redhat.com]
Sent: Tuesday, 17 July 2012 9:33 a.m.
To: Steven Jones
Cc: freeipa-users@redhat.com
Subject: Re: [Freeipa-users] How to set a user group rule to allow su - oracle 

Steven Jones wrote:
> Is this possible?
> If so how is it done?

I'm not sure what you're asking.


