Usermode request: add patch enabling group membership to control auth user

Matthew Miller mattdm at mattdm.org
Fri Apr 16 14:03:59 UTC 2004


On Fri, Apr 16, 2004 at 09:56:41AM -0400, Will Backman wrote:
> Would it ever be possible to give someone rights to manage certain
> accounts but not others?  If you can change the root password, you are
> as good as root.

A reasonable request but separate from my patch. :)

system-config-users needs something like the command-line 'gpasswd' tool --
the ability to delegate group management to certain users. And as you
suggest, that could be extended to delegation of complete control over
certain classes of users.

But that's a project for later sometime. I'd like my little patch to go in
now if at all possible.

While the SELinux things may not be all worked out, it doesn't do anything
relevant to that that the unpatched version doesn't. And it's incredibly
useful and well-tested in the non-SELinux universe (where I think a lot of
people are going to continue to exist for a while).

-- 
Matthew Miller           mattdm at mattdm.org        <http://www.mattdm.org/>
Boston University Linux      ------>                <http://linux.bu.edu/>





More information about the fedora-test-list mailing list