#816 security policy: root password needed when it shouldn't be
Closed None Opened 12 years ago by mmaslano.

= phenomenon =
security policy: root password needed when it shouldn't be

= background analysis =
The long thread on fedora-devel mailing list.

= implementation recommendation =
https://bugzilla.redhat.com/show_bug.cgi?id=799988


This was deferred to next week at the 2012-03-05 FESCo meeting.b

Is there anything specific for FESCo to do or discuss?

IMO, we should have a clearly defined policy for writing polkit policy. If it's left up to individual packagers, we're bound to have dissonance in the settings.

Note that the list of screenshots referenced above doesn't have anything wrong with "polkit policy". The polkit dialogs correctly/permissively requested user's own (not root's) password [it's just that there are too many of them, not that the policy is too strict], and the last dialog is not governed by polkit.

Reviving https://fedoraproject.org/wiki/User:Adamwill/Draft_Fedora_privilege_escalation_policy might be useful nevertheless.

Closing on behalf of the reporter of the original problem (Scott Doty). Actually the problem is not in the policy or that there would be disagreement between policy and individual maintainers but rather subtle bugs that caused the spurious root password dialog. So I do not think there is currently anything for FESCo to discuss. Of course I agree that reviving the draft of the privilege escalation policy and make it an official would be nice.

What do you know, it seems that it already is official: https://fedoraproject.org/wiki/Privilege_escalation_policy . But given that it took us almost a week to even notice that, it's probably not referred to too often, I'm afraid.

Well I have to say that I did not look whether it is already official or not at all. I remembered that it was discussed but I didn't remember whether it passed formal approval or not.

Login to comment on this ticket.

Metadata