误修改/etc/pam.d/common-password致sudo出现PAM认证错误,root禁用如何修复?
修复PAM配置错误导致的sudo故障
方法1:利用当前登录会话修复(无需重启)
如果你还保持登录状态,可以通过以下方式绕过sudo修改错误的/etc/pam.d/common-password:
- 先获取当前shell的进程ID:
echo $$ - 用
cat将默认的common-password配置写入文件(以Debian/Ubuntu为例,可根据你的系统替换对应默认配置):cat > /proc/$(echo $$)/root/etc/pam.d/common-password << 'EOF' # # /etc/pam.d/common-password - password-related modules common to all services # # This file is included from other service-specific PAM config files, # and should contain a list of modules that define the services to be # used to change user passwords. The default is pam_unix. # # Explanation of pam_unix options: # # The "sha512" option enables salted SHA512 passwords. Without this option, # the default is Unix crypt. Prior releases used the option "md5". # # The "obscure" option replaces the old `OBSCURE_CHECKS_ENAB' option in # login.defs. # # See the pam_unix manpage for other options. # As of pam 1.0.1-6, this file is managed by pam-auth-update by default. # To take advantage of this, it is recommended that you configure any # local modules either before or after the default block, and use # pam-auth-update to manage selection of other modules. See # pam-auth-update(8) for details. # here are the per-package modules (the "Primary" block) password [success=1 default=ignore] pam_unix.so obscure sha512 # here's the fallback if no module succeeds password requisite pam_deny.so # prime the stack with a positive return value if there isn't one already; # this avoids us returning an error just because nothing sets a success code # since the modules above will each just jump around password required pam_permit.so # and here are more per-package modules (the "Additional" block) password optional pam_gnome_keyring.so password optional pam_kwallet5.so EOF - 执行完后,测试
sudo ls验证是否恢复正常。
方法2:进入单用户模式修复
如果当前会话无法操作,可通过单用户模式修改配置:
- 重启系统,在GRUB启动菜单(Ubuntu/Debian按住Shift,RHEL/CentOS按
e键)编辑启动项 - 找到以
linux开头的行,在末尾添加init=/bin/bash - 按
Ctrl+X或F10启动,进入单用户环境 - 将根目录重新挂载为读写模式:
mount -o remount,rw / - 编辑
/etc/pam.d/common-password恢复正确配置:vi /etc/pam.d/common-password - 修复完成后,执行
exec /sbin/init重启系统。
方法3:Live CD/USB修复
若单用户模式无法进入,用对应系统的Live USB启动:
- 启动Live系统后,用
lsblk找到你的系统分区(如/dev/sda1) - 挂载系统分区:
mount /dev/sda1 /mnt - 编辑挂载目录下的配置文件:
vi /mnt/etc/pam.d/common-password - 保存后卸载分区:
umount /mnt - 重启系统即可。
注:你遇到的
vi /etc/pam.d/sudo提示密码错误,是因为sudo的PAM配置依赖common-password,修复该文件后所有sudo验证问题都会解决。
内容的提问来源于stack exchange,提问作者Eve
相关产品推荐
相关产品推荐

