diff --git a/debian/security-misc.postinst b/debian/security-misc.postinst index bda8dbb..f0ebbf2 100644 --- a/debian/security-misc.postinst +++ b/debian/security-misc.postinst @@ -39,15 +39,15 @@ addgroup root sudo ## Related to Console Lockdown. ## /usr/share/pam-configs/console-lockdown-security-misc ## /etc/security/access-security-misc.conf +addgroup --system console +addgroup --system console-unrestricted +addgroup --system ssh ## This has no effect since by default this package also ships and an ## /etc/securetty configuration file that contains nothing but comments, i.e. ## an "empty" /etc/securetty. ## In case a system administrator edits /etc/securetty, there is no need to ## block for this to be still blocked by console lockdown. See also: ## https://www.whonix.org/wiki/Root#Root_Login -addgroup --system console -addgroup --system console-unrestricted -addgroup --system ssh addgroup root console pam-auth-update --package