Project

General

Profile

Actions

Bug #2245

closed

User permissions for shell access are not clear/complete

Added by Stilez y over 13 years ago. Updated almost 11 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
02/29/2012
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.0.1
Affected Architecture:

Description

I wanted to rename the main "admin" account to avoid easy login guesses. The default account cannot be renamed within pfsense so I created a new account in user manager, gave it the same group membership as the existing one (member of "admins") and disabled the existing "admin".

Bug - the new account was blocked from accessing the vga console while the inbuilt one was able to. When the new account logs in on the vga console it's dumped into a crippled/permission-limited shell and can't be used for administration or emergency recovery functions (for example, basic commands such as pfctl -d get "permission denied" errors).

It's important to have a way to avoid the default login username but this bug makes it impossible as only the default account can get into the normal VGA console.

Screenshot available, reproducible even after full clean reinstall.

Actions

Also available in: Atom PDF