Hello On 2005-04-29 sean finney wrote: > On Fri, Apr 29, 2005 at 09:36:00AM +0200, Christian Hammers wrote: > > That was correct in the past where this user really only had the RELOAD > > and SHUTDOWN privileges but nowadays it also serves as a more general user > > for e.g. packages that ask the user if they may create a database during > > installation and the script that runs when starting the mysql server and > > does a CHECK TABLES which also requires additional privileges. > > i think after sarge is out we should revist this and see about stripping > away those extra privileges. hopefully by then my dbconfig-common > project will be catching on and everyone using the debian-sys-maint > account for package installation can be pointed at something easier.
Using an abstraction layer instead of directly communicating with the mysql admin tools might be a good idea - but, uhm, how does your dbconfig-common package access mysql if not via something like the full privileged debian-sys-maint account? bye, -christian-
pgp2W5NkbXP4R.pgp
Description: PGP signature