[Bug 771189] New: allow unprivileged users to install updates
https://bugzilla.novell.com/show_bug.cgi?id=771189 https://bugzilla.novell.com/show_bug.cgi?id=771189#c0 Summary: allow unprivileged users to install updates Classification: openSUSE Product: openSUSE 12.2 Version: Factory Platform: Other OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security AssignedTo: security-team@suse.de ReportedBy: lnussel@suse.com QAContact: qa-bugs@suse.de Found By: --- Blocker: --- unprivileged users should be allowed to install online updates without authentication (org.freedesktop.packagekit.system-update). The danger of not installing e.g. a Firefox or flash update is likely bigger than the risk to the system. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=771189 https://bugzilla.novell.com/show_bug.cgi?id=771189#c1 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|security-team@suse.de |meissner@suse.com --- Comment #1 from Marcus Meissner <meissner@suse.com> 2012-07-12 14:46:17 UTC --- I thought this is the case already ... i will be changing it to auth_admin_keep_always:auth_admin_keep_always:yes -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=771189 https://bugzilla.novell.com/show_bug.cgi?id=771189#c2 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |FIXED --- Comment #2 from Marcus Meissner <meissner@suse.com> 2012-07-12 17:49:26 UTC --- sred -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=771189 https://bugzilla.novell.com/show_bug.cgi?id=771189#c3 --- Comment #3 from Bernhard Wiedemann <bwiedemann@suse.com> 2012-07-13 11:00:12 CEST --- This is an autogenerated message for OBS integration: This bug (771189) was mentioned in https://build.opensuse.org/request/show/127810 Factory / polkit-default-privs -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=771189 https://bugzilla.novell.com/show_bug.cgi?id=771189#c4 George Baltz <GeoBaltz@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |GeoBaltz@gmail.com --- Comment #4 from George Baltz <GeoBaltz@gmail.com> 2012-07-24 12:11:39 UTC --- No. No. NO. This is a major change to openSUSE security policy, and should get much more discussion than a couple of comments on a minor buglet(which should have been in openFATE). This >might< be okay on a system with only one novice user, but for a machine with a designated admin, this is a disaster waiting to happen. I certainly would not like to have my wife or sons installing ANYTHING without my knowledge, even patches. Since I have to fix anything that goes wrong, I want to know when something changes, else I'd be wasting my time trying to fix what changed. And using Flash as an example argues more against this change than for it; given the number of broken updates they've put out in the last few months, anybody who isn't out on the bleeding edge wouldn't install a Flash update until he's waited a few days, checked the forums, and maybe tried it in a VM before adding it to a stable system. Don't even >think< of pushing this to SLED/SLES. Every sysadmin in the world would be after your head. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=771189 https://bugzilla.novell.com/show_bug.cgi?id=771189#c5 George Baltz <GeoBaltz@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |REOPENED Resolution|FIXED | --- Comment #5 from George Baltz <GeoBaltz@gmail.com> 2012-07-24 12:16:11 UTC --- And did you even consider making this configurable - if you are determined to do it, I certainly will have to turn it off. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=771189 https://bugzilla.novell.com/show_bug.cgi?id=771189#c6 Ludwig Nussel <lnussel@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |RESOLVED Resolution| |FIXED --- Comment #6 from Ludwig Nussel <lnussel@suse.com> 2012-07-30 10:03:03 CEST --- You can set the profile to 'restrictive' via POLKIT_DEFAULT_PRIVS in /etc/sysconfig/security or tune individual settings via /etc/polkit-default-privs.local or even more elaborate via pklocalauthority(8) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=771189 https://bugzilla.novell.com/show_bug.cgi?id=771189#c7 George Baltz <GeoBaltz@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |REOPENED Resolution|FIXED | --- Comment #7 from George Baltz <GeoBaltz@gmail.com> 2012-09-02 12:23:19 UTC --- Again: NO! This makes vanilla openSUSE unusable anywhere there are corporate (e.g., ISO-900x) and/or legal (Sarbanes-Oxley is USA) requirements for Configuration Management. You'd better be sure that's well known before someone gets biten. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com