{
    "mode": "man",
    "parameter": "pam_rootok",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/pam_rootok/8/json",
    "generated": "2026-10-08T03:20:55Z",
    "synopsis": "pamrootok.so [debug]",
    "sections": {
        "NAME": {
            "content": "pamrootok - Gain only root access\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "pamrootok.so [debug]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "pamrootok is a PAM module that authenticates the user if their UID is 0. Applications that\nare created setuid-root generally retain the UID of the user but run with the authority of an\nenhanced effective-UID. It is the real UID that is checked.\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "debug\nPrint debug information.\n",
            "subsections": []
        },
        "MODULE TYPES PROVIDED": {
            "content": "The auth, account and password module types are provided.\n",
            "subsections": []
        },
        "RETURN VALUES": {
            "content": "PAMSUCCESS\nThe UID is 0.\n\nPAMAUTHERR\nThe UID is not 0.\n",
            "subsections": []
        },
        "EXAMPLES": {
            "content": "In the case of the su(1) application the historical usage is to permit the superuser to adopt\nthe identity of a lesser user without the use of a password. To obtain this behavior with PAM\nthe following pair of lines are needed for the corresponding entry in the /etc/pam.d/su\nconfiguration file:\n\n# su authentication. Root is granted access by default.\nauth  sufficient   pamrootok.so\nauth  required     pamunix.so\n\n\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "su(1), pam.conf(5), pam.d(5), pam(7)\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "pamrootok was written by Andrew G. Morgan, <morgan@kernel.org>.\n\nLinux-PAM                                    05/07/2023                                PAMROOTOK(8)",
            "subsections": []
        }
    },
    "summary": "pamrootok - Gain only root access",
    "flags": [],
    "examples": [
        "In the case of the su(1) application the historical usage is to permit the superuser to adopt",
        "the identity of a lesser user without the use of a password. To obtain this behavior with PAM",
        "the following pair of lines are needed for the corresponding entry in the /etc/pam.d/su",
        "configuration file:",
        "# su authentication. Root is granted access by default.",
        "auth  sufficient   pamrootok.so",
        "auth  required     pamunix.so"
    ],
    "see_also": [
        {
            "name": "su",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/su/1/json"
        },
        {
            "name": "pam.conf",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/pam.conf/5/json"
        },
        {
            "name": "pam.d",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/pam.d/5/json"
        },
        {
            "name": "pam",
            "section": "7",
            "url": "https://www.chedong.com/phpMan.php/man/pam/7/json"
        }
    ]
}