You are about to take a server down for maintenance and want ordinary users refused at login for the next hour, with an explanatory message, while root can still get in. On a system using PAM's pam_nologin, creating which file achieves this?

LPIC-1 Exam 102-500, objective 110. Security medium

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Not correct /etc/securetty

Wrong. /etc/securetty lists the terminals on which root is permitted to log in directly, enforced by pam_securetty. It restricts root, not ordinary users, and where it is still shipped it already exists (several current distributions have dropped the file and the module entirely).

Correct /etc/nologin

Correct. While this file exists, pam_nologin refuses logins from every account except root, and the file's contents are displayed to the rejected user, which is where you put the maintenance notice. Deleting the file restores normal logins.

Not correct /etc/shells

Wrong. /etc/shells is the list of shells considered valid login shells. chsh refuses to set a shell that is not listed, and some FTP daemons check it, but its presence blocks nobody.

Not correct /sbin/nologin

Wrong. That is an executable, not a flag file, and it already exists. Setting it as a specific account's login shell in /etc/passwd makes that one account unable to get a shell; it is per-account and permanent, not a system-wide temporary block.

Why

/etc/nologin is a flag file: its mere existence blocks non-root logins, and its text is shown to the user who was turned away. It is the standard way to close a machine for maintenance because undoing it is a single rm. Note the deliberate similarity to /sbin/nologin (also seen as /usr/sbin/nologin), a program you set as a service account's shell so that the account can own files and run services but can never log in interactively.

Where this comes from

Cited
LPI exam objective 110.1
What it says
Use /etc/nologin to prevent user logins temporarily.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500