My original question:

>Sun Managers,
>Under SunOS 4.x, I could restrict root login at the main console
>by editing /etc/ttytab's line:
>console "/usr/etc/getty cons8" sun on local secure
>console "/usr/etc/getty cons8" sun on local
>This would force someone logging in from the console to login as an
>actual user (other than root) and then they could "su root". The
>advantage to this is that you have a log of who logged in as root,
>either from the network or from the console.
>Under Solaris 2.x, I can't find a way to do this. If I edit the
>/etc/default/login file and include the line:
>this does not disable root login from the console.

The bottom line:

> This file's CONSOLE entry can actually be used in a variety of ways:
> 1) CONSOLE=/dev/console (default) - direct root logins only on console
> 2) CONSOLE=/dev/ttya - direct root logins only on /dev/ttya
> 3) CONSOLE= - direct root logins disallowed everywhere
> 4) #CONSOLE (or delete the line) - root logins allowed everywhere

