You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

误修改/etc/pam.d/common-password致sudo出现PAM认证错误,root禁用如何修复?

修复PAM配置错误导致的sudo故障

方法1:利用当前登录会话修复(无需重启)

如果你还保持登录状态,可以通过以下方式绕过sudo修改错误的/etc/pam.d/common-password:

  1. 先获取当前shell的进程ID:
    echo $$
    
  2. 用cat将默认的common-password配置写入文件(以Debian/Ubuntu为例,可根据你的系统替换对应默认配置):
    cat > /proc/$(echo $$)/root/etc/pam.d/common-password << 'EOF'
    #
    # /etc/pam.d/common-password - password-related modules common to all services
    #
    # This file is included from other service-specific PAM config files,
    # and should contain a list of modules that define the services to be
    # used to change user passwords.  The default is pam_unix.
    #
    
    # Explanation of pam_unix options:
    #
    # The "sha512" option enables salted SHA512 passwords.  Without this option,
    # the default is Unix crypt.  Prior releases used the option "md5".
    #
    # The "obscure" option replaces the old `OBSCURE_CHECKS_ENAB' option in
    # login.defs.
    #
    # See the pam_unix manpage for other options.
    
    # As of pam 1.0.1-6, this file is managed by pam-auth-update by default.
    # To take advantage of this, it is recommended that you configure any
    # local modules either before or after the default block, and use
    # pam-auth-update to manage selection of other modules.  See
    # pam-auth-update(8) for details.
    
    # here are the per-package modules (the "Primary" block)
    password	[success=1 default=ignore]	pam_unix.so obscure sha512
    # here's the fallback if no module succeeds
    password	requisite			pam_deny.so
    # prime the stack with a positive return value if there isn't one already;
    # this avoids us returning an error just because nothing sets a success code
    # since the modules above will each just jump around
    password	required			pam_permit.so
    # and here are more per-package modules (the "Additional" block)
    password	optional	pam_gnome_keyring.so
    password	optional	pam_kwallet5.so
    EOF
    
  3. 执行完后,测试sudo ls验证是否恢复正常。

方法2:进入单用户模式修复

如果当前会话无法操作,可通过单用户模式修改配置:

  1. 重启系统,在GRUB启动菜单(Ubuntu/Debian按住Shift,RHEL/CentOS按e键)编辑启动项
  2. 找到以linux开头的行,在末尾添加init=/bin/bash
  3. 按Ctrl+X或F10启动,进入单用户环境
  4. 将根目录重新挂载为读写模式:
    mount -o remount,rw /
    
  5. 编辑/etc/pam.d/common-password恢复正确配置:
    vi /etc/pam.d/common-password
    
  6. 修复完成后,执行exec /sbin/init重启系统。

方法3:Live CD/USB修复

若单用户模式无法进入,用对应系统的Live USB启动:

  1. 启动Live系统后,用lsblk找到你的系统分区(如/dev/sda1)
  2. 挂载系统分区:
    mount /dev/sda1 /mnt
    
  3. 编辑挂载目录下的配置文件:
    vi /mnt/etc/pam.d/common-password
    
  4. 保存后卸载分区:
    umount /mnt
    
  5. 重启系统即可。

注:你遇到的vi /etc/pam.d/sudo提示密码错误,是因为sudo的PAM配置依赖common-password,修复该文件后所有sudo验证问题都会解决。

内容的提问来源于stack exchange,提问作者Eve

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 04:18:19