You are about to take a server down for maintenance and want ordinary users refused at login for the next hour, with an explanatory message, while root can still get in. On a system using PAM's pam_nologin, creating which file achieves this?
LPIC-1 Exam 102-500, objective 110. Security medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct /etc/securetty
Wrong. /etc/securetty lists the terminals on which root is permitted to log in directly, enforced by pam_securetty. It restricts root, not ordinary users, and where it is still shipped it already exists (several current distributions have dropped the file and the module entirely).
Correct /etc/nologin
Correct. While this file exists, pam_nologin refuses logins from every account except root, and the file's contents are displayed to the rejected user, which is where you put the maintenance notice. Deleting the file restores normal logins.
Not correct /etc/shells
Wrong. /etc/shells is the list of shells considered valid login shells. chsh refuses to set a shell that is not listed, and some FTP daemons check it, but its presence blocks nobody.
Not correct /sbin/nologin
Wrong. That is an executable, not a flag file, and it already exists. Setting it as a specific account's login shell in /etc/passwd makes that one account unable to get a shell; it is per-account and permanent, not a system-wide temporary block.
Why
/etc/nologin is a flag file: its mere existence blocks non-root logins, and its text is shown to the user who was turned away. It is the standard way to close a machine for maintenance because undoing it is a single rm. Note the deliberate similarity to /sbin/nologin (also seen as /usr/sbin/nologin), a program you set as a service account's shell so that the account can own files and run services but can never log in interactively.
Where this comes from
- Cited
- LPI exam objective 110.1
- What it says
- Use /etc/nologin to prevent user logins temporarily.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.
More questions on this objective
- During an audit you must list every file under /usr that has the set-user-ID bit set, regardless of what its other permission bits are. Which command does that? machine-checked
- You locked the password of the account `intern` and confirmed that its hash in /etc/shadow now begins with an exclamation mark. The intern nevertheless still reaches a shell on the host over SSH, without being prompted for anything. What is going on, and what actually stops it? machine-checked
- You have just been added to a sudo rule on a host and want sudo itself to report which commands you are allowed to run there, without running any of them. Type the complete command. machine-checked
- A daemon started from your bash session keeps hitting a 'too many open files' error. Which command raises the limit on open file descriptors for the current shell and the processes it starts to 4096? machine-checked
- Which two commands report the users who are logged in right now, rather than a history of past logins? (Choose two.) machine-checked
- Using the iproute2 socket utility, list only listening TCP sockets, with ports and addresses left as numbers rather than resolved to service and host names. Type the complete command, using short options only. machine-checked