http://bugzilla.suse.com/show_bug.cgi?id=1017977 Bug ID: 1017977 Summary: Display manager does not require root password for shutdown or reboot Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.2 Hardware: 64bit OS: openSUSE 42.2 Status: NEW Severity: Major Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: dgolden@golden-consulting.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- Display manager does not require root password for shutdown/reboot. I have specified root in Desktop->Display manager->DISPLAYMANAGER_SHUTDOWN and it never asks for the root password for shutdown or reboot. I have changed from sddm to kdm and it makes no difference. This has worked up through leap 42.1. Worse yet, it doesn't require anyone to be logged in. It will allow shutdown from the login screen. This is a show stopper for my servers. -- You are receiving this mail because: You are on the CC list for the bug.