I suppose there _might_ be some way to configure it through PAM, but I found a simpler way. As it turns out, I just had to add a couple of lines to /etc/security/console.perms - one to define the group in question: <com>=/dev/ttyS? and one to say "grant root access to the com ports to the person logged in locally: <xconsole> 0600 <com> 0600 root Calvin