rfc: news item for changed polkit default group
On 01/30/2012 03:05 PM, Ulrich Mueller wrote:
On Mon, 30 Jan 2012, Samuli Suominen wrote:
was asked about this at IRC today, so I suppose we should convey this
information better to users
Title: Default value of AdminIdentities changed to group wheel in PolicyKit
Too long, GLEP 42 allows a maximum of 44 characters (excluding "Title: ").
Author: Samuli Suominen<firstname.lastname@example.org>
The default value of AdminIdentities changed to group wheel by upstream
since version 0.103.
Maybe the package name sys-auth/polkit should appear somewhere in the
item's body text?
This means users in group wheel are allowed to execute commands like
"pkexec bash" to gain root shell.
You can change the default value at:
# $EDITOR /etc/polkit-1/localauthority.conf.d/50-localauthority.conf
... this is no longer relevant as I've just pushed 0.104-r1 for fast
stabilization within security bug restoring the old behavior as per
recommendation of the gentoo security team (a3li mostly ;-)