Fedora 12 to remove unprivileged package installation
Posted Nov 20, 2009 11:09 UTC (Fri) by
drag (subscriber, #31333)
In reply to:
Fedora 12 to remove unprivileged package installation by SiB
Parent article:
Fedora 12 to remove unprivileged package installation
Wheel alone is only able to meet 2 use cases. Having a central mechanism
like Packagekit means that a user/admin is able to configure their system
in a sane manner for a much wider set of requirements.
Hell on my Debian box I have my main user belong to no less then 14
different groups, each of which give different privileges to different
aspects of the system. A couple I had to create myself in order to avoid
using 'sudo' all the time. (and I can tell you right now that requiring the
user to run root code under their account won't fly in the majority of
organizations) I can tell you that having a central way to
manage user permissions like packagekit is vastly simpler and easier to get
right then having to create my own groups, touch a half a dozen different
configuration files all over my system and setting up special file system
configurations for usbfs and directories in /var in order to avoid using
'sudo'. Half of it was educated guess work.. playing around with different
settings until I got things to work properly. I tried to get it right, but
I really have no way to properly test it.
Now imagine having to manage a mess of desktops. Dozens or Hundreds or even
thousands of desktops. And you have to take into account a many different
types of users from different departments with different policies and
different requirements. The ability to set 'group policy' is a killer
feature for managed desktops. It's to the point now were it's a hard
requirement.. unless your OS is able to provide that sort of mechanisms it
simply won't be considered.
Even simple single-computer use cases like setting up a guest account or
koisk in order to
put the system into a secure-enough mode to allow children or untrusted
people to use the desktop can be surprisingly difficult to get right,
unless your distro has already gone through a lot of effort to pre-
configure it for you.
(
Log in to post comments)