Hi Todd,

on Fri, Feb 22, 2008 at 13:00:08 -0500, you wrote:

> In message <20080222002715.GA6231@libra>
>       so spake Justin Pryzby (justinpryzby):
> 
> > retitle   306919 sudo -k with tty_tickets set doesn't revoke all/any of the 
> > t
> > imestamps
> 
> It wasn't really my intent to remove all timestamps via -k/-K when
> tty_tickets are enabled.  I can see how that might be useful, though
> I worry that there may be people relying on the current behavior.
> I'll have to think about it some more.

With sudo 1.7.4 changing to default to enable tty_tickets by default,
people that so far relied on -k/-K preventing further usage of sudo
without specifying the password, will be surprised.

On Debian, where the bug report originated from, an upgrade from lenny
to squeeze will bring in this suprise. So there should at leat be a
NEWS.Debian file entry mentioning the changed default for tty_tickets
and warning about the implications for -k/-K.

elmar

-- 

 .'"`.                                                            /"\
| :' :   Elmar Hoffmann <e...@elho.net>    ASCII Ribbon Campaign  \ /
`. `'    GPG key available via pgp.net        against HTML email   X
  `-                                                    & vCards  / \



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to