|
Bugzilla – Full Text Bug Listing |
| Summary: | sudo commands being permitted without password prompt when user kerberos account expired | ||
|---|---|---|---|
| Product: | Sudo | Reporter: | Mick <mbarry> |
| Component: | Sudo | Assignee: | Todd C. Miller <Todd.Miller> |
| Status: | ASSIGNED --- | ||
| Severity: | normal | ||
| Priority: | low | ||
| Version: | 1.8.23 | ||
| Hardware: | All | ||
| OS: | Linux | ||
|
Description
Mick
2019-03-12 06:22:37 MDT
The timestamp is updated before the PAM session functions are called which is why you see this behavior. Changing that is somewhat complicated since the session code runs much later. It may be possible to reorganize things such that the timestamp record is not updated until after the session checks. (In reply to Todd C. Miller from comment #1) > The timestamp is updated before the PAM session functions are called > which is why you see this behavior. Changing that is somewhat > complicated since the session code runs much later. It may be > possible to reorganize things such that the timestamp record is not > updated until after the session checks. Todd, We're going to do some further testing here. In our scenario, the method used to change the password requires you to use an rsa or yubikey device to change your password. So in order for someone to take advantage of this scenario in our company, we are replacing one auth method (kerb password) with another (rsa/yubikey). So that person still has to be 'that person'. I'm not sure if you guys feel this is a bug, or just a quirk of the behaviour. We will probably pass this off to our Security Assurance team who will review it, after we've done some further testing and make our own decision as to whether this behaviour constitutes an actual risk or not. Would appreciate your thoughts on this all the same, is this something you feel needs rectification or not? Thanks This doesn't really seem like a security issue since the user has successfully verified their identity with sudo. I don't think it is significantly different from a user authenticating with sudo and then changing their password manually. Sudo will not prompt for a password even though the user's password has changed. |