/dev/console restriction

I'd like to know how Solaris handles this restriction.
Is it done via the username or via the UID?
We have servers managed by an outsourcer, and they have made a duplicate UID 0 account, and I want to know if that account will still be restricted to the console, or if they will be able to telnet/ssh into the servers with this account.
I would test it myself, but this is taking place on production machines and I cannot alter them for the tests.
Thanks.

It checks on UID. At least it does that in Solaris 10, and i believe it did just the same in Solaris 9, at least it makes lot more sence to trigger on UID rather than username..
http://cvs.opensolaris.org/source/xref/usr/src/cmd/login/login.c#1174

Similar Messages

  • Authentication Error in Cocomo Dev Console

    I have two Adobe IDs - one I've had for years and one I
    created just to test out Cocomo - and I am unable to logon via the
    Dev Console with either of these accounts. I always receive the
    message "Authentication Error" when I attempt to logon.
    I have tried using both the meeting URL and the account URL
    (they seem to be different - the URL I use to actually enter the
    meeting is different from the URL that is displayed as the "Account
    URL" in the management page on
    http://cocomo.acrobat.com)
    but I always get the same error.
    Client specs:
    OS: Windows XP SP2
    AIR version: 1.5
    Flash Player: 10
    Cocomo SDK: SDK Beta 0.9
    Proxy type: NTLM (this has caused issues in the past with
    Adobe products but the requests appear to be going out correctly in
    this instance).
    Any ideas what might be going on or how I can get a more
    detailed error description (I can't find any error logs anywhere)?
    Thanks,
    John.

    I'v tryed to creat account with AccountURL=
    http://connect.acrobat.com/<youraccountname>
    http://connectnow.acrobat.com/<youraccountname>
    http://connectnow.acrobat.com/<accountname
    from meeting URL>
    And I have Authentication Error" every time!
    My accot was created just fo this. What may be the problem?

  • Messages to /dev/sysmsg and /dev/console are displayed on the CDE Desktop

    I noticed that after reboots any message sent to /dev/sysmsg or /dev/console is displayed to the CDE Desktop (wallpaper). After I log out then log back in the problem disappears. This happens in global zones only and not in a non-global (local) zone.
    (the only service I see with "svcs -xv" is the Print Service)
    To repeat the problem I have to do the following:
    1. Reboot (init 6)
    2. Login to the CDE as a user.
    3. Open an Xterm window, and in the windows, "su" to root
    4. Observe a "su on ..." message on the CDE desktop in big white "OBP" looking mono-spaced text.
    5. Log out of the CDE
    6. Login to the CDE as a user.
    7. Open an Xterm window, and in the windows, "su" to root
    8. Problem has disappeared, no more logging of console like messages to the CDE desktop.
    As well, if I do something like this after I reboot, and on 1st log in:
    echo "Hi there" > /dev/console
    echo "Another Hello" > dev/sysmsg
    I'll see both messages print to the Desktop of the CDE. If I log out and log back in, I will no longer see this kind of behavior.
    My Hardware: Sun Netra CP3260
    My Software: Sun Solaris 10 5/08 Update 5 with 137137-09
    Additional info:
    /etc/syslog.conf - does have a line that directs some output to /dev/sysmsg
    /etc/default/su - does list: CONSOLE=/dev/console
    I did comment out the above two lines in my syslog.conf and /etc/default/su, and the behavior goes away, however this is a workaround and not a fix of the issue.
    Any ideas?
    Brian Jester
    Edited by: BrianJester on Apr 30, 2010 12:11 PM
    Edited by: BrianJester on Apr 30, 2010 12:22 PM

    Yes, I know this is an old post, but I’m trying to clean them up.
    Without your PowerShell script is will be impossible for anyone to answer this.
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • Improvements to Dev Console

    Is the Cocomo Dev Console AIR app going to be something that
    is kept up to date? It would be nice to see better editing of
    templates (e.g. edit the template itself rather than a room and
    overwriting the template) as well as being able to view and edit
    the storage scheme on nodes.

    Hi,
    Yes we do keep dev console upto date and keep adding new
    features in every drop of Afcs SDK. Currently , we don't have
    editing of templates in mind but we will definitely keep note of
    this feedback.
    Regarding editing of storage scheme, that is something we can
    add in near future. I will update you on its status very soon.
    Thanks
    Regards
    Hironmay Basu

  • Error msgs being sent to /dev/console

    Hi,
    I am a new Solaris user. I have more experience with Darwin and Linux. I recently installed Solaris 10 -- no X, just the basics.
    When the install was complete and I was finally presented with the login, I was frustrated to note that a number of informational error messages were being sent directly to /dev/console. These msgs were interfering with shell operations, and login itself.
    Has anyone else seen this behavior?

    This is default Solaris stuff with regard to console (/dev/console) messages:
    [root@iron ~]# more /etc/syslog.conf
    # Copyright (c) 2000-2002 by Sun Microsystems, Inc.
    # All rights reserved.
    #ident "@(#)syslog.conf 2.3 02/02/21 SMI"
    # This "syslog.conf" file was installed by JASS. This
    # file should be used to log information both locally as
    # well as to a centralized log server (or servers) so that
    # proactive log analysis can be done.
    *.err;kern.notice;auth.notice /dev/console
    *.alert root
    *.emerg *
    *.debug /var/adm/messages
    # *.debug @loghost1
    # *.debug @loghost2
    auth.notice /var/log/authlog

  • Cant Log In - getty: dev/console: Operation not supported by device

    Hello. My computer performance has dropped so I decided to run cron tasks and to rebuild the Launch Database. After doing this, I restarted my computer and all seemed well. I got to the login screen, clicked on my name, entered by credentials, and clicked login. I have my computer forced to use verbose mode for startup, shutdown, login, etc. So, at this point, the computer goes to the black verbose screen and I get a message that says:
    getty: dev/console: Operation not supported by device
    It hangs on that screen for about a minute and then returns back to the login screen. Same thing happens for all users, mine, the guest account, and the root account.
    I tried safe boot. Of course that was all happening in verbose mode, and stuff was flying on the screen. I left the room for a minute, and when I came back, the computer was off, so I started again and still couldn't log in.
    I reset PRAM and NVRAM to no avail.
    Any suggestions would be greatly appreciated. I would rather not have to archive and install because the space on my laptop is very limited and I might not have room for a complete archive and install.
    Thanks.

    in my case I looked back at the system.log when things were good and out of the blue (no punintended), crashdump 'crashed' with a segmentation fault (signal 11). Then getty starting restarting and now this happens on every boot. I replaced crashdump from the install disk and the same thing happens. Bad data should not cause a Unix process to take a segmentation fault (if written correctly) since this is a bad instruction/memory reference. So I am skeptical if a reinstall will help.

  • Foolish /dev/console tangle

    I recently poked my fingers in where they probably don't belong, namely by doing a SRIOCSREDIR in a naive little program, "just to see what would happen." Well, what happened is that I now have /dev/console more-or-less permanently trying to redirect itself to a particular pts/<number> whenever that device happens to come into existence. I believe that I've placed that pts/ device's name onto the "list of eligible devices," and that I would like to REMOVE it from that list -- but I don't see any documentation about a way to do so. SRIOCSREDIR seems to be a one-way street: you can ADD devices to the list, but apparently can't REMOVE them. What am I missing? How do I "back out" this little "oops" of mine? (Is there a way to get a LIST of the devices on the /dev/console redirection list?)
    Thanks in advance. Reply via e-mail if at all possible, because I'm not sure I'll be able to find my way back HERE when I want to.
    Chris Chiesa
    [email protected]

    Hi,
    We don't make the source available for the Dev Console and we
    don't any near future plans to do so. We feel the dev console app
    by itself satisfies what a developer would need to look into the
    details of his room. Out of curiosity, why you need it for ?
    Thanks
    Hironmay Basu

  • Dev console source available?

    I assume Dev console is pretty much using every possible api
    method to query objects etc .., so I was thinking if its possible
    to look at its source?

    Hi,
    We don't make the source available for the Dev Console and we
    don't any near future plans to do so. We feel the dev console app
    by itself satisfies what a developer would need to look into the
    details of his room. Out of curiosity, why you need it for ?
    Thanks
    Hironmay Basu

  • Cocomo Dev Console

    hi guys, if I edit my account and change 'Display Name for
    this Account' in the console. the name doesn't get updated till the
    console is restarted. thxs paddy ;)

    Hi,
    This issue has been fixed and will be updated in the next
    drop beta drop of SDK.
    Thanks for reporting.
    Hironmay Basu

  • Automatic login to virtual console doesn't create a 'session'

    I'm running an instance of Arch inside an LXC container. It's basically being used as a lightweight virtualisation approach, and so I have a wrapper program that spins up the instance, configures it, and drops the user in. As such, the user should be automatically logged in on boot.
    I'm following the method listed at https://wiki.archlinux.org/index.php/Au … al_console and it works fine; however, it doesn't register a 'session' (as I understand it): loginctl shows nothing. This means I can't shut down the machine as a regular user.
    I was previously starting a getty on /dev/console instead of at /dev/tty1, and this was correctly registering a session, but would hang as soon as you ran 'vi'. If vi was killed, the terminal size would shrink to a fraction of its existing size until fixed with 'reset'.
    Solving either of these problems would be great, if anybody has any ideas! I have polkit (1.09) installed.

    As I say, loginctl gives no results:
    SESSION UID USER SEAT
    0 sessions listed.
    systemctl list-units | grep polkit
    also returns nothing, which I wasn't expecting. Some more detail...
    $ systemctl status polkit
    polkit.service - Authorization Manager
    Loaded: loaded (/usr/lib/systemd/system/polkit.service; static)
    Active: inactive (dead)
    Docs: man:polkit(8)
    I can manually start polkit, and then get:
    # systemctl status polkit
    polkit.service - Authorization Manager
    Loaded: loaded (/usr/lib/systemd/system/polkit.service; static)
    Active: active (running) since Mon 2013-04-15 09:15:20 UTC; 6s ago
    Docs: man:polkit(8)
    Main PID: 98 (polkitd)
    CGroup: name=systemd:/system/polkit.service
    └─98 /usr/lib/polkit-1/polkitd --no-debug
    Though I also get these errors in the journalctl log:
    Apr 15 09:15:20 archibald polkitd[98]: Loading rules from directory /etc/polkit-1/rules.d
    Apr 15 09:15:20 archibald polkitd[98]: Error opening rules directory: Error opening directory '/etc/polkit-1/rules.d': Permission denied (g-file-error-quark, 2)
    Apr 15 09:15:20 archibald polkitd[98]: Loading rules from directory /usr/share/polkit-1/rules.d
    Apr 15 09:15:20 archibald polkitd[98]: Error opening rules directory: Error opening directory '/usr/share/polkit-1/rules.d': Permission denied (g-file-error-quark, 2)
    Last edited by osymandias (2013-04-15 09:18:11)

  • How can I exit console mode?

    I attempted to bring up the Force Quit dialog while logged in. To do so, I pressed Command-Option-Escape. When I did so, I was logged out, and my iMac entered what seems to be console mode. I received a message with the date and imac getty: dev/console: Operation not supported by device. I received no further prompts, and typing exit (or anything else) has no result. Booting off of my cloned backup has the same result. This screen appears after the boot panel with the progress bar, but does not let me get to the desktop. Any and all assistance with exiting this and getting my iMac to boot normally is greatly appreciated.
    Mac mini, 1.42GHz G4, 512MB RAM, Superdrive, 80GB HD; iMac 20'' 2.0GHz G5, 512MB RAM, Airport + BT   Mac OS X (10.4.5)  

    Problem solved - archive and install did the trick.

  • Automatic scrip execution on the console in single user mode on Solaris 10

    Hi All,
    On Solaris 8, I am able to launch my script automatically on the console when the system comes up into single user mode without having to enter the password. However, on Solaris 10, the script is display in the foreground on the console. When i do a ps -ef , I see the process running. Can someone please tell me how to get this to work on solaris 10?
    To automatically boot the system into single user mode:
    # svcadm milestone -d milestone/single-user:default
    Files edited for this to work on solaris 8:
    To login without a password:
    # cat > /etc/default/sulogin <<EOF
    PASSREQ=NO
    CONSOLE=/dev/console
    ALTSHELL=YES
    EOF
    # echo "/sbin/su -" > /sbin/rc1
    (Solaris 10, I used rcS instead of rc1)
    my script is called from the /.profile when the system comes up into single user mode.
    I did the same on solaris 10, but no success.
    Please let me know if you have any suggestions.
    Thank you,
    Brian

    try
    - add 'set -x' to your /etc/profile
    - add 'set -x' to /etc/rc? scripts
    - check /etc/vfstab for a nfs mountpoint not using 'bg'

  • Weblogic Console Access Denied - Admin Role group question

    I need to grant access to a user that is authenticated via OAM.
    My authentication is succeeding and I am getting the following back as my Principal:
    <weblogic.security.service.internal.WLSIdentityServiceImpl.getIdentityFromSubject Subject: 3
         Principal = class weblogic.security.principal.WLSUserImpl("IdentityGuardAppID")
         Principal = class weblogic.security.principal.WLSGroupImpl("cn=FUNC-LDAP-Browse,ou=secure,o=admin")
         Principal = class weblogic.security.principal.WLSGroupImpl("cn=FUNC-IDV-APP,ou=secure,o=admin")
    My authorization is failing and I think it's because I cannot figure out how to add the groups returned above to the Admin role in WLS.
    Normally, this is a breeze - I simply add it from the Realm Role under the Roles and Policies tab in myrealm.
    In this case, my group looks like a subject DN (i.e., it contains commas).
    Does anyone know how to add a group that contains a comma to the Admin Role?

    Hi Sameer Gawde,
    Would you please let me know complete error messages when use RSAT and PowerShell?
    In addition, the RSAT is based on MMC console. Please check if you have enabled group policy setting to restrict
    MMC snap-ins? In GPME, please refer to the path: User Configuration-> Policies-> Administrative Templates-> Windows Components-> Microsoft Management Console-> Restrict users to the explicitly permitted list of snap-ins. Meanwhile, please check
    if you configure the Don't run specified Windows applications setting (path:
    User Configuration-> Policies-> Administrative Templates-> System-> configure) to limit RSAT and apply to the domain admin group. This issue is really strange. Just please check and confirm. Thanks for understanding.
    Please logon DC via Admin account, then navigate to: ADUC-> Users. Please select and right click Domain
    Admins group and select Properties. Please select Member Of tab and check which did this group member of.
    Meanwhile, please open Component Services and expand “Component Services-> Computers-> My Computer”. 
    Then right click My Computer and select Properties. In COM Security tab, under Access Permissions, please check how configure the “Edit Limit”.
    By the way, please navigate to Event Viewer and check if can find some related clues.
    Hope this helps.
    Best regards,
    Justin Gu

  • SAP MDM Console

    Hi,
    I'm new to MDM Console. Can anyone please tell me how can I, from SAP MDM Console restrict a particular user from <u>viewing</u> specific records in MDM Data Manager.
    Thanking you in advance.
    Hemal

    Hi,
    You can achieve this using Masks.
    Step 1:
    In the Data Manager , you filter records based on what ever condition you are looking for. Add the filtered records to a Mask.
    If you have no masks defined in the Data Manager.
    Select Masks table from the top left corner list in the Data Manager and create a Mask.
    Once you finished creating the Mask, go back to the Main table and add the Filtered records to the created mask.
    (Select all the records right click and select Add to Mask and select the Mask).
    Step 2:
    a. For New Role:
    1. In the MDM Console for that particular repository, create a new role and in the role details grid, select Table/Fields tab and look for Masks table. In the Constraints column, you select the Mask you created in the Data Manager.
    2. Assign the created role to the user.
    b. For Existing Role:
    In MDM console select the role in the repository and
    in the role details grid, select Table/Fields tab and look for Masks table. In the Constraints column, you select the Mask you created in the Data Manager.
    Hope this helps.
    Let me know if you need any additional information.
    Thanks and Regards
    Subbu

  • AFCS Beta Drop 0.92 Available in the Dev Portal

    New goodness at afcs.acrobat.com. Login and hit the big purple Download button.
    Release Notes :
    Version 0.92
    What's new in this Release?
    0.92 is an "appetizer" release - we're focused primarily around long-term projects right now (like e-commerce, HTTP APIs, etc), but we wanted to update the SDK with some bug fixes and new features here and there while we continue work on the big stuff.
        * The "log in as guest, then as host, STILL logs you in as a guest" bug has been squashed
        * ColdFusion server scripts have been added for provisioning and authentication
        * SharedCursorPane :
            * now supports absolute and relative sizing  (.sizingMode)
            * now supports labelField and labelFunction
        * New Examples :
            * CustomUserField  with DataGrids  using various SDK API's.
            * Collaborative Picture Viewer: Allows users to upload pics and collaboratively annotate them
        * Reconnect Bugs are largely fixed - we're still hardening more of our components to more seamlessly reconnect after a temporary network drop
        * UserManager / Custom UserFields work :
             * API for deleting Custom UserFields .
                 * Events for registering and Deleting CustomUserFields .
         * For the Player 10 swc : NetStreamInfo has been exposed by the Audio and Webcam Pub/Sub components to allow for monitoring of latency and drops.
        * Dev Console :
            *  Now supports addition/deletion/modification of custom user fields
            * Modifying ItemStorageSchmes  in NodeConfigurations
            * FileShare  Configuration Bug for Publish/Access Model fixed.
        * Scalability / Performance work : We're still working to tune performance of the cluster to allow even more usage.
        * Tons of little Bug Fixes (more than 50 or so)
    What's next?
        * Working on HTTP/Remoting APIs. Specs should come soon!
        * Further work on improving audio quality
        * More long-term work on e-commerce enablement
        * More responses to your requests!

    Great .92 is here nice improvements as well,
        * Reconnect Bugs are largely fixed - we're still hardening more of our components to more seamlessly reconnect after a temporary network drop
    On Reconnect issue when the the session loses connectivity with the service due to temporary network drop.cocomo api tries to connect to the service automatically . Here it should give precedence to the developer rather it should automatically connect to the serivce after network drop or not by now there is no such provision.
    regards,
        ATIF

Maybe you are looking for

  • Doubt in BAPI - BAPI_TRANSACTION_COMMIT

    Hi Gurus, I am posting material from customer storage palce to activate storage location through the follwo\ing BAPI- BAPI_TRANSACTION_COMMIT. in that i got error as follow Material 30000004 not maintained in plant SUND Material 30000005 not maintain

  • Netbeans calls MS Web Service through BPEL

    I get the followng error when trying to invoke a microsoft web service through bpel: Pattern for exchange Id 206195522970609-30893-134221047015560007 is http://www.w3.org/2004/08/wsdl/in-out This is from the exception block. com.sun.bpel.model.meta.i

  • Failed to load IMAP envelope

    Hi All,      I have encountered a problem with JavaMail API, when a message exists on the Mail Server that has �null� for recipient field, JavaMail API throws an Exception when ever we try to retrieve getFrom() method, and also it returns �null� when

  • Cannot set date and time

    I am in the UAE and brought over an Apple TV 3rd generation from the US but cannot get it to set the date or time.  This product has not been released yet in this country.

  • Can't Complete Install

    Can't complete install of Photoshop Elements 10 & Premiere Elements 10, Disc 5.  Prior disks loaded fine but Disc 5 causes a window from my Lexmard printer to open which asks "What do you want to do? View & Print or Save to PC?"  Although I close the