[Bug 1174944] Default sudoers configuration is confusing/error prone
http://bugzilla.opensuse.org/show_bug.cgi?id=1174944 http://bugzilla.opensuse.org/show_bug.cgi?id=1174944#c1 Neil Rickert <nwr10cst-oslnx@yahoo.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |nwr10cst-oslnx@yahoo.com --- Comment #1 from Neil Rickert <nwr10cst-oslnx@yahoo.com> --- I mostly disagree with this. I have never found "sudo" to be confusing or misleading. I'll note that I rarely use it. My preference is to use "su" rather than "sudo".
This configuration is uncommon and surprising.
As far as I know, "openSUSE" is using "sudo" as originally intended. The idea was that the system administrator would use "su". The intended use of "sudo" was to provide the ability of selected users to have limited root access only for running specific commands. One of the reasons that I prefer openSUSE to Ubuntu, is that I really dislike the way at Ubuntu mucked up the adminstrative use of the system and changed the way "sudo" worked. And now you seem to want to Ubuntu-ize openSUSE. The day that openSUSE becomes Ubuntu will be the day that I go looking for another distro. Yes, many distros now follow the Ubuntu way of doing this. But that's no reason that openSUSE should do the same.
This means the expectation of most people is that the password for sudo *is* the password of the source account (rather than the target account which SUSE configures by default).
When I use "sudo" (mostly only for testing), it explicitly says that it is asking for the root password. I don't see how there could be confusion when the command is quite explicit that it wants the root password (unless configured otherwise).
This is especially risky especially given that we allow root password ssh by default.
I explicitly disallow that. If you want to make a separate bug report about "ssh" defaults, I might agree with you on that. Perhaps there could be a separate package with Ubuntu-style configuration for "sudo". People who prefer to do it that way could install that package. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com