Martin Pitt martin.pitt at ubuntu.com
Thu Nov 24 14:38:19 CST 2005


Hi!

Martin Pitt [2005-11-24 21:26 +0100]:
> That would be wrong. Adding the group is fine, and giving it sudo
> privileges *if it did not exist before* is fine, too, but putting
> users into new groups is wrong.

... This can lead to unexpected privilege escalation, and also would
probably break horribly when using a centralized authentication
database (NIS, LDAP, etc).

Martin

-- 
Martin Pitt        http://www.piware.de
Ubuntu Developer   http://www.ubuntu.com
Debian Developer   http://www.debian.org

In a world without walls and fences, who needs Windows and Gates?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.ubuntu.com/archives/ubuntu-devel/attachments/20051124/5c20390a/attachment.pgp


More information about the ubuntu-devel mailing list