*BSD News Article 99843


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.carno.net.au!harbinger.cc.monash.edu.au!news.rmit.EDU.AU!news.unimelb.edu.au!munnari.OZ.AU!news.ecn.uoknor.edu!feed1.news.erols.com!infeed1.internetmci.com!newsfeed.internetmci.com!in3.uu.net!198.3.221.51!news1.frb.gov!b1saboc
From: b1saboc@PROBLEM_WITH_INEWS_GATEWAY_FILE (Seth Bromberger)
Newsgroups: comp.unix.bsd.freebsd.misc
Subject: 2.2.2 login.conf problems?
Date: 17 Jul 1997 17:20:12 GMT
Organization: Another Netscape News Server User
Lines: 66
Message-ID: <5qlk8c$4772@farstar.frb.gov>
NNTP-Posting-Host: 192.168.3.71
X-Newsreader: TIN [version 1.2 PL2]
Xref: euryale.cc.adfa.oz.au comp.unix.bsd.freebsd.misc:44579

I'm running FreeBSD 2.2.2-RELEASE and have defined a "banned" login class
in login.conf and have edited the password file to force a (test) user (deng)
into this class.  The class as defined in login.conf has the following:
  banned|Denied Users:nologin=/etc/login.deny.msg

Here are my observations so far (please tell me if something's wrong):

1)  /bin/cat must be in /etc/shells for this to work at all.  (Are there
    security implications for this?)
2)  even if /bin/cat IS in /etc/shells, the nologin does not work consistently
    (i.e, most of the time, the login session gets terminated before the
    message is displayed, but sometimes it works -- see below).

Can anyone provide a clue as to why I'm seeing such inconsistent behavior?
Please post to this group or send mail to seth at inter<nospam>port dot net.
(remove the <nospam> and perform the appropriate substitutions.)

Sorry if this post is misdirected; I can't find a more appropriate newsgroup.


Here's an example of the inconsistency (telnetting from npsws1 to freebie,
the freeBSD box):

----- START OF LOG

npsws1 73: telnet freebie
Trying...
Connected to freebie.
Escape character is '^]'.
Local flow control on
Telnet TERMINAL-SPEED option ON

FreeBSD (freebie) (ttyp4)

login: dengConnection closed by foreign host.
npsws1 74: telnet freebie
Trying...
Connected to freebie.
Escape character is '^]'.
Local flow control on
Telnet TERMINAL-SPEED option ON

FreeBSD (freebie) (ttyp4)

login: deng
PLEASE NOTE:

Your account has been suspended.  Please call the system
administrators to reactivate it.


Connection closed by foreign host.
npsws1 75: 

----- END OF LOG

Thanks!

DISCLAIMER: Nothing in this post is an official position of my employer.  All
opinions/statements are mine alone.




--
Seth Bromberger