Control auto update from non authorized user Why justification

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



There are times when it is OK to allow an automatic update. But there are also times when only the administrator account should be allowed to do it.  I can control this by eliminating that entry from the non-authorized user menu, and still keep it for the authorized user (I decide who is authorized).

But one can, via terminal mode, go around the imposed security. The only true circumvention then is to change ownership or groups for the application.

Why not allow new file inserts due to a system update?  Because I need to know before hand if that insert is going to break an already existing application.  It has happened to me on CENTOS5.6 and it almost happened to me on F14 and F15.

 
On 7 May 2011 13:22, Leslie S Satenstein <lsatenstein@xxxxxxxxx> wrote:
> I think that allowing dependency files may be a potential security breach.

Why?

Richard.


 ************************************
-- 
test mailing list
test@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe: 
https://admin.fedoraproject.org/mailman/listinfo/test

[Index of Archives]     [Fedora Desktop]     [Fedora SELinux]     [Photo Sharing]     [Yosemite Forum]     [KDE Users]

  Powered by Linux