I want a specific group of users to be able to use the su command as a specific user.
example)
| Group | User |
|---|---|
allowsu_aa |
aa |
allowsu_bb |
bb |
allowsu_cc |
cc |
So I added the below to /etc/pam.d/su file.
auth [success=2 default=ignore] pam_succeed_if.so user = aa
auth [success=2 default=ignore] pam_succeed_if.so user = bb
auth [success=2 default=3] pam_succeed_if.so user = cc
auth [success=done new_authtok_reqd=done default=2] pam_succeed_if.so use_uid user ingroup allowsu_aa
auth [success=done new_authtok_reqd=done default=1] pam_succeed_if.so use_uid user ingroup allowsu_bb
auth [success=done new_authtok_reqd=done default=ignore] pam_succeed_if.so use_uid user ingroup allowsu_cc
But it didn't work as I wanted.
How should I fix it?