diff --git a/debian/security-misc.postinst b/debian/security-misc.postinst index 55995a0..bda8dbb 100644 --- a/debian/security-misc.postinst +++ b/debian/security-misc.postinst @@ -31,9 +31,6 @@ esac addgroup --system sysfs addgroup --system cpuinfo -addgroup --system console -addgroup --system console-unrestricted -addgroup --system ssh ## group 'sudo' membership required to use 'su' ## /usr/share/pam-configs/wheel-security-misc @@ -48,6 +45,9 @@ addgroup root sudo ## In case a system administrator edits /etc/securetty, there is no need to ## block for this to be still blocked by console lockdown. See also: ## https://www.whonix.org/wiki/Root#Root_Login +addgroup --system console +addgroup --system console-unrestricted +addgroup --system ssh addgroup root console pam-auth-update --package