diff --git a/debian/frr.pam b/debian/frr.pam index 2b106d43bc59..737b88953b59 100644 --- a/debian/frr.pam +++ b/debian/frr.pam @@ -1,3 +1,4 @@ # Any user may call vtysh but only those belonging to the group frrvty can # actually connect to the socket and use the program. auth sufficient pam_permit.so +account sufficient pam_rootok.so diff --git a/redhat/frr.pam b/redhat/frr.pam index 5cef5d9d746e..17a62f1999c8 100644 --- a/redhat/frr.pam +++ b/redhat/frr.pam @@ -5,6 +5,7 @@ # Only allow root (and possibly wheel) to use this because enable access # is unrestricted. auth sufficient pam_rootok.so +account sufficient pam_rootok.so # Uncomment the following line to implicitly trust users in the "wheel" group. #auth sufficient pam_wheel.so trust use_uid