admin locked out

Asked by pierre

Hi Guys, I am the admin of a home multiuser system (Ubuntu 10.04). Timekpr is installed since a long time already and works absolutely great!
Yesterday I wanted to lock the account for one of my kids, unfortunately I've locked my own account, and as I am the only one with root rights, I am not able to change the settings with any other user account. How can I change this again, is there any workaround via the terminal or with a liveCD or via ssh from a remote computer?
Thanks in advance, pierre

Question information

Language:
English Edit question
Status:
Solved
For:
timekpr Edit question
Assignee:
No assignee Edit question
Solved by:
pierre
Solved:
Last query:
Last reply:
Revision history for this message
Savvas Radevic (medigeek) said :
#1

>
> Yesterday I wanted to lock the account for one of my kids, unfortunately
> I've locked my own account,
>

That's weird, because the admin / current user is hidden from the user drop
down menu. How did you manage to lock yourself? :)

Revision history for this message
pierre (ursup) said :
#2

Good question, :(, no clue! Whenever I try to logg on, it tells me "Berechtigung verweigert", same message as if access is denied by timekpr. Actually, the user account I wanted to lock, is locked as selected and comes up with the same message when I try to logg on.
I have been playing around on SATURDAY with userid's for another problem I had with a partition, but that was on Saturday, and I still could logg on yesterday morning, and yesterday evening. In yesterday's evening session, we (my wife and me) decided, that for disciplinary measurement one of our kids will get banned from computer usage for one week, so one of my last actions yesterday evening was to select "account sperren" for this specific user, and I am sure, I selected him correctly from the drop down menu. As you mentioned already, the user with root privileges is normally not even listed in the drop down menu.
So, I am a bit lost right now.....................
pierre

Revision history for this message
pierre (ursup) said :
#3

I think a I have a clue.........................., rethinking of Staurday's session, I think I realized what happened.
I have created partitions for each user, and I wanted to have each partition mounted automatically with the assigned user. So I assigned myself as a member to each usergroup, to make sure, that I always have admin privileges for their partitions. So, momentarily I am not only user 1000, I am also member of user 1001, 1002, 1003. User ID 1003 is the account I have locked, as I am a member of this usergroup, I have locked myself out as well.
Great!, how the hell do I get into system with root privileges in order to clean up this mess...............................

Revision history for this message
pierre (ursup) said :
#4

Got it. Recovery mode, root shell, sudo deluser <user> <group>.
Back again, thanx anyhow,
Pierre

Revision history for this message
Savvas Radevic (medigeek) said :
#5

Sorry it took me so much time to reply. Just in case it happens again, please try to remember how it happened.

The files in question are:
/etc/security/access.conf
/etc/security/time.conf

Probably access.conf had your username listed to be blocked.

Revision history for this message
Savvas Radevic (medigeek) said :
#6

Oh, sorry, I just read the user group part. I must admit, that's a weird way to assign yourself admin rights. :)
I have to look into this though, I thought userid and groupid are unique..

Revision history for this message
pierre (ursup) said :
#7

-----Ursprüngliche Nachricht-----
Von: "Savvas Radevic" <email address hidden>
Gesendet: 27.09.2010 20:29:31
An: <email address hidden>
Betreff: Re: [Question #126999]: admin locked out

Your question #126999 on timekpr changed:
https://answers.edge.launchpad.net/timekpr/+question/126999

Savvas Radevic posted a new comment:
Oh, sorry, I just read the user group part. I must admit, that's a weird way to assign yourself admin rights. :)
I have to look into this though, I thought userid and groupid are unique..

--
You received this question notification because you are a direct
subscriber of the question.

Revision history for this message
pierre (ursup) said :
#8

Hi Savvas,

that's how I understood the ID's as well, obviously its not right (at least not in terms of timekpr), or, also possible with my limited linux knowledge, I've screwed something up, wouldn't be the first time..........;-)

Pierre

-----Ursprüngliche Nachricht-----
Von: "Savvas Radevic" <email address hidden>
Gesendet: 27.09.2010 20:29:31
An: <email address hidden>
Betreff: Re: [Question #126999]: admin locked out

Your question #126999 on timekpr changed:
https://answers.edge.launchpad.net/timekpr/+question/126999

Savvas Radevic posted a new comment:
Oh, sorry, I just read the user group part. I must admit, that's a weird way to assign yourself admin rights. :)
I have to look into this though, I thought userid and groupid are unique..

--
You received this question notification because you are a direct
subscriber of the question.

Revision history for this message
Savvas Radevic (medigeek) said :
#9

Can you post the two files above if it's not a problem?

/etc/security/access.conf
/etc/security/time.conf

Revision history for this message
pierre (ursup) said :
#10

The out commented parts are deleted, only the relevants are left.

-----Ursprüngliche Nachricht-----
Von: "Savvas Radevic" <email address hidden>
Gesendet: 27.09.2010 20:50:07
An: <email address hidden>
Betreff: Re: [Question #126999]: admin locked out

Your question #126999 on timekpr changed:
https://answers.edge.launchpad.net/timekpr/+question/126999

Savvas Radevic posted a new comment:
Can you post the two files above if it's not a problem?

/etc/security/access.conf
/etc/security/time.conf

--
You received this question notification because you are a direct
subscriber of the question.

Revision history for this message
Savvas Radevic (medigeek) said :
#11

Unfortunately, launchpad does not support email (or any) attachments for the
"answers" section.
Can you use plain text? Sorry for the trouble. :)

Revision history for this message
pierre (ursup) said :
#12

Jeah, just realized too late..........

Access conf:

# All other users should be denied to get access from all sources.
#- : ALL : ALL
## TIMEKPR START
-:nicolas:ALL
## TIMEKPR END

time conf:
## TIMEKPR START
*;*;michele;Al1100-2200
*;*;gast;Al0700-2300
*;*;nicolas;Su1100-2200 | Mo1100-2200 | Tu1100-2200 | We1100-2200 | Th1100-2200 | Fr1100-2300 | Sa1100-2300
## TIMEKPR END