root password considered harmful, and other security policies. (was Re: Torvalds:requiring root password for mundane things is moronic

2012-03-07 Thread Scott Doty
On 03/05/2012 07:13 AM, Scott Doty wrote: On 03/02/2012 04:16 AM, Tim Waugh wrote: Yes, it's a policy. Also see this bug which I filed nearly two years ago on just this subject: https://bugzilla.redhat.com/show_bug.cgi?id=596711 Tim. */ New bug report filed: security policy: root

Re: Torvalds:requiring root password for mundane things is moronic

2012-03-05 Thread Scott Doty
On 03/02/2012 04:16 AM, Tim Waugh wrote: Yes, it's a policy. Also see this bug which I filed nearly two years ago on just this subject: https://bugzilla.redhat.com/show_bug.cgi?id=596711 Tim. */ New bug report filed: security policy: root password needed when it shouldn't be.

Re: Draft schedule for today's FESCo meeting (5 March 2012)

2012-03-05 Thread Scott Doty
On 03/05/2012 06:44 AM, Bill Nottingham wrote: If you would like to add something to this agenda, you can reply to this e-mail, file a new ticket at https://fedorahosted.org/fesco, e-mail me directly, or bring it up at the end of the meeting, during the open floor topic. Note that added topics

Re: Torvalds:requiring root password for mundane things is moronic

2012-03-04 Thread Scott Doty
On 03/03/2012 03:32 PM, Scott Doty wrote: On 03/02/2012 04:16 AM, Tim Waugh wrote: Yes, it's a policy. Also see this bug which I filed nearly two years ago on just this subject: https://bugzilla.redhat.com/show_bug.cgi?id=596711 Tim. */ They closed it as an upstream bug. Then upstream

Re: Torvalds:requiring root password for mundane things is moronic

2012-03-03 Thread Scott Doty
On 03/02/2012 03:21 AM, Conan Kudo (ニール・ゴンパ) wrote: For printers, currently installing printers does not require superuser privileges, but managing those printers installed by that user does. Is it possible to make it so that printers installed by that user can be managed by the user

Re: Torvalds:requiring root password for mundane things is moronic

2012-03-03 Thread Scott Doty
On 03/03/2012 02:19 PM, Miloslav Trmač wrote: On Sat, Mar 3, 2012 at 11:10 PM, Chris Murphyli...@colorremedies.com wrote: On Mar 3, 2012, at 1:00 PM, Neal Becker wrote: - Don't ask for re-auth for an action that isn't really potentially harmful (e.g., adding a printer) Depends. What if

Re: Torvalds:requiring root password for mundane things is moronic

2012-03-03 Thread Scott Doty
On 03/02/2012 04:16 AM, Tim Waugh wrote: On Fri, 2012-03-02 at 05:21 -0600, Conan Kudo (ニール・ゴンパ) wrote: For printers, currently installing printers does not require superuser privileges, but managing those printers installed by that user does. Is it possible to make it so that printers

Re: Torvalds:requiring root password for mundane things is moronic

2012-03-03 Thread Scott Doty
On 03/03/2012 03:22 PM, Miloslav Trmač wrote: On Sun, Mar 4, 2012 at 12:03 AM, Scott Dotysc...@ponzo.net wrote: How about allowing all printer management of local printers (including adding a network printer, as Linus his daughter were dealing with) with two factors: 1) user password 2)

Re: Torvalds:requiring root password for mundane things is moronic

2012-03-03 Thread Scott Doty
On 03/03/2012 11:07 AM, David Zeuthen wrote: Hi, - Original Message - On Fri, 2012-03-02 at 08:42 -0600, Greg Swift wrote: This sounds pretty straightforwardly like a bug probably in PolicyKit, to me. It's obviously more correct to use the current user's authorization if it's

Re: Torvalds:requiring root password for mundane things is moronic

2012-02-29 Thread Scott Doty
On 02/29/2012 08:46 AM, David Malcolm wrote: On Wed, 2012-02-29 at 07:02 -0500, Neal Becker wrote: I think he's got a point http://www.osnews.com/story/25659/Torvalds_requiring_root_password_for_mundane_things_is_quot_moronic_quot_ http://fedoraproject.org/wiki/Releases/FeaturePolicyKit in

Re: /usrmove? - about the future

2012-02-10 Thread Scott Doty
On 02/10/2012 10:05 AM, Adam Williamson wrote: You're not supposed to be running Fedora on production servers. That is not what it's for. Sez who? http://fedoraproject.org/wiki/SIGs/Server -Scott -- devel mailing list devel@lists.fedoraproject.org

Re: /usrmove? - about the future

2012-02-10 Thread Scott Doty
On 02/10/2012 10:44 AM, Jef Spaleta wrote: On Fri, Feb 10, 2012 at 9:39 AM, Scott Doty sc...@ponzo.net wrote: Sez who? http://fedoraproject.org/wiki/SIGs/Server I don't see the word production on that page. I can imagine the existence of non-production servers which would not invalidate

Re: /usrmove? - about the future

2012-02-10 Thread Scott Doty
On 02/10/2012 10:57 AM, Adam Williamson wrote: On Fri, 2012-02-10 at 10:39 -0800, Scott Doty wrote: On 02/10/2012 10:05 AM, Adam Williamson wrote: You're not supposed to be running Fedora on production servers. That is not what it's for. Sez who? http://fedoraproject.org/wiki/SIGs/Server

Re: /usrmove? - about the future

2012-02-10 Thread Scott Doty
On 02/10/2012 11:08 AM, Adam Williamson wrote: On Fri, 2012-02-10 at 11:02 -0800, Scott Doty wrote: On 02/10/2012 10:57 AM, Adam Williamson wrote: On Fri, 2012-02-10 at 10:39 -0800, Scott Doty wrote: On 02/10/2012 10:05 AM, Adam Williamson wrote: You're not supposed to be running Fedora