Local users get to play root?

Jon Ciesla limb at jcomserv.net
Wed Nov 18 18:01:28 UTC 2009


Seth Vidal wrote:
>
>
> On Wed, 18 Nov 2009, Jon Ciesla wrote:
>
>> nodata wrote:
>>> Am 2009-11-18 18:08, schrieb nodata:
>>>> Yikes! When was it decided that non-root users get to play root?
>>>>
>>>> Ref:
>>>> https://bugzilla.redhat.com/show_bug.cgi?id=534047
>>>>
>>>> This is horrible!
>>>>
>>>
>>> Just to elaborate:
>>>
>>> A local user is allowed to install software on the machine without 
>>> being prompted for the root password.
>>>
>>> This is a recipe for disaster in my opinion.
>>>
>> So much for granting shell access on my servers. . .
>
> You have PackageKit installed on servers? really?
>
>
> -sv
>
I do if it's in the default DVD install, or was pulled in in an 
upgrade.  I've never intentionally installed it, and yes I do.  Never 
imagined it would be a problem.  I'll remove it.

-- 
in your fear, seek only peace
in your fear, seek only love

-d. bowie




More information about the devel mailing list