[Freeipa-users] Root overrides HBAC rules for the command su

2015-02-24 Thread Bloemen , Jurriën
Hi, In FreeIPA you can create users and restrict on which hosts the user can login to. This is all great and works fine. If a user1 is logged in to a system. Knows the password of user2 and issues the command su to be that user2 on that same system. This is not allowed because the user2 does

Re: [Freeipa-users] Root overrides HBAC rules for the command su

2015-02-24 Thread Sumit Bose
On Tue, Feb 24, 2015 at 09:15:11AM +, Bloemen, Jurriën wrote: Hi, In FreeIPA you can create users and restrict on which hosts the user can login to. This is all great and works fine. If a user1 is logged in to a system. Knows the password of user2 and issues the command su to be