Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-20 Thread Christian PERRIER
Quoting Steve Langasek (vor...@debian.org): On the other hand, is it really necessary a new group? Can't adm or operator be overloaded with this new functionality? (think Ockham's razor). No. Both of those groups also have other meanings. How about the root group? signature.asc

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-20 Thread Vincent Danjean
[reply-to set to d-d only] On 20/10/2010 07:12, Christian PERRIER wrote: Quoting Steve Langasek (vor...@debian.org): On the other hand, is it really necessary a new group? Can't adm or operator be overloaded with this new functionality? (think Ockham's razor). No. Both of those groups

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-20 Thread Petter Reinholdtsen
[Michael Biebl] One suggestion is to use group admin. Ubuntu has been using that group for exactly the purpose what we are going for and I think it is a pretty adequate name. The Ubuntu use of the group 'admin' have caused some problems here at the university where I work on integrating Ubuntu

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-20 Thread Mehdi Dogguy
On 20/10/2010 11:18, Petter Reinholdtsen wrote: So I would suggest to use a name that is more likely to be unique. unique wrt. what? admin seems unique since not used in Debian yet. Happy hacking, -- Mehdi Dogguy مهدي الدڤي http://dogguy.org/ -- To UNSUBSCRIBE, email to

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-20 Thread Otavio Salvador
Maybe god ;-) On Wed, Oct 20, 2010 at 8:16 AM, Mehdi Dogguy me...@dogguy.org wrote: On 20/10/2010 11:18, Petter Reinholdtsen wrote: So I would suggest to use a name that is more likely to be unique. unique wrt. what? admin seems unique since not used in Debian yet. Happy hacking, --

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Josselin Mouette
Le mardi 19 octobre 2010 à 00:38 +0200, Michael Biebl a écrit : 1/ The sudo group in previous Debian releases had a different meaning: Members of groups sudo could run sudo without needing a password. Did it exist in previous releases? I don’t recall seeing it in sudoers. 2/ Using the name

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Ben Finney
Josselin Mouette j...@debian.org writes: Le mardi 19 octobre 2010 à 00:38 +0200, Michael Biebl a écrit : 1/ The sudo group in previous Debian releases had a different meaning: Members of groups sudo could run sudo without needing a password. Did it exist in previous releases? I don’t

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Michael Biebl
On 19.10.2010 08:15, Josselin Mouette wrote: Le mardi 19 octobre 2010 à 00:38 +0200, Michael Biebl a écrit : 1/ The sudo group in previous Debian releases had a different meaning: Members of groups sudo could run sudo without needing a password. Did it exist in previous releases? I don’t

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Bjoern Meier
hi, 2010/10/19 Michael Biebl bi...@debian.org: Hi, Bdale went ahead and added the following to /etc/sudoers: # Allow members of group sudo to not need a password # (Note that later entries override this, so you might need to move # it further down) %sudo ALL=(ALL) ALL First of all: YES!

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Jesús M. Navarro
Hi, Josselin: On Tuesday 19 October 2010 08:15:56 Josselin Mouette wrote: [...] Le mardi 19 octobre 2010 à 02:12 +0200, Jesús M. Navarro a écrit : What about the old-fashioned wheel group[1]? This would be an even worse disaster than “admin”, for similar reasons. Users of the “wheel” group

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Josselin Mouette
Le mardi 19 octobre 2010 à 09:58 +0100, Philip Hands a écrit : For PolicyKit, I can now simply ship a file, say /etc/polkit-1/localauthority.conf.d/51-debian-sudo.conf which contains: [Configuration] AdminIdentities=unix-group:sudo I would object to 'sudo' being a group of people

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Philip Hands
On Tue, 19 Oct 2010 00:38:41 +0200, Michael Biebl bi...@debian.org wrote: Bdale went ahead and added the following to /etc/sudoers: # Allow members of group sudo to not need a password # (Note that later entries override this, so you might need to move # it further down) %sudo ALL=(ALL)

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Olaf Mandel
Am Dienstag, den 19.10.2010, 08:15 +0200 schrieb Josselin Mouette: Le mardi 19 octobre 2010 à 00:38 +0200, Michael Biebl a écrit : -Snipp- So, I'm wondering if we shouldn't pick a more neutral name without a previous history in Debian. One suggestion is to use group admin. Ubuntu has

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread Steve Langasek
On Tue, Oct 19, 2010 at 09:48:58AM +0200, Jesús M. Navarro wrote: On Tuesday 19 October 2010 08:15:56 Josselin Mouette wrote: [...] Le mardi 19 octobre 2010 à 02:12 +0200, Jesús M. Navarro a écrit : What about the old-fashioned wheel group[1]? This would be an even worse disaster than

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-19 Thread The Fungi
On Tue, Oct 19, 2010 at 09:48:58AM +0200, Jesús M. Navarro wrote: [...] On the other hand, is it really necessary a new group? Can't adm or operator be overloaded with this new functionality? (think Ockham's razor). Maybe similarly overloaded, but I've used the built-in staff group for this

[RFC] disabled root account / distinct group for users with administrative privileges

2010-10-18 Thread Michael Biebl
Hi, as some of you might know, the debian installer allows to install a system with a disabled root account, i.e. there is no root password set for root. In lenny, iirc, this was done via d-i pre-seeding, in squeeze it is as simple as leaving the root password prompt empty. The lenny installer

Re: [RFC] disabled root account / distinct group for users with administrative privileges

2010-10-18 Thread Jesús M. Navarro
Hi, Michael: On Tuesday 19 October 2010 00:38:41 Michael Biebl wrote: Hi, [...] The idea is, to have a distinct group. Members of that group have administrative privileges using sudo and PolicKit. [...] While I think the idea of using a distinct group for users with administrative