CentOS Telnet 权限问题排查与修复
一 服务与端口就绪
service telnet
{
disable = no
flags = REUSE
socket_type = stream
protocol = tcp
wait = no
user = root
server = /usr/sbin/in.telnetd
log_on_failure += USERID
}
二 常见权限问题与修复
三 精细访问控制
sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port protocol="tcp" port="23" accept'
sudo firewall-cmd --reload
# /etc/pam.d/telnet
auth required pam_listfile.so item=user sense=allow file=/etc/telnet.allow onerr=succeed
auth required pam_listfile.so item=user sense=deny file=/etc/telnet.deny onerr=succeed
四 验证与回退