Posted Nov 15, 2007 12:54 UTC (Thu) by TRS-80
In reply to: /etc/group
Parent article: Centralizing policy rules with PolicyKit
The primary advantage of PolicyKit is that it allows conditions like "only the console user can change the networking", and being able to deal with fast user switching through integration with gdm, which pam_console is unable to do. This is better than groups and setgid processes, because it means someone can't log in over ssh and mess with another user at the console.
to post comments)