After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 149911 - actions on logout are insecure
actions on logout are insecure
Status: RESOLVED WONTFIX
Product: gdm
Classification: Core
Component: general
2.6.0.x
Other Linux
: High major
: ---
Assigned To: GDM maintainers
GDM maintainers
: 309627 (view as bug list)
Depends on:
Blocks:
 
 
Reported: 2004-08-11 14:41 UTC by Timo Aaltonen
Modified: 2005-07-06 19:55 UTC
See Also:
GNOME target: ---
GNOME version: 2.5/2.6



Description Timo Aaltonen 2004-08-11 14:41:11 UTC
Reboot and shutdown -actions on logout don't ask the root password even if it is
configured to do so.
Comment 1 George Lebl 2004-08-18 19:15:06 UTC
It is never configured to do so, gdm doesn't ask for a root password (there is
no gdm configuration for this).  PAM and userhelper may, but gdm won't.  I think
it's overly anal to ask for a password for reboot or shutdown on a local console
as the user could just unplug the machine with much worse consequences.  If it's
some sort of kiosk, then I'd recommend not having the actions menu.
Comment 2 Timo Aaltonen 2004-08-18 19:41:09 UTC
# The Actions in the Actions menu require the root password
SecureSystemMenu=true

but the logout-prompt on gnome does not ("restart" and "shutdown"). AIUI the
options are from gdm..
Comment 3 Timo Aaltonen 2004-08-18 20:54:25 UTC
I admit that if the actions-menu is visible then it probably is on a local
console and the direct reboot/shutdown is convenient. But, they shouldn't be
visible on the logout-prompt if SystemMenu=false, but that is bug #149910
Comment 4 Timo Aaltonen 2004-08-31 14:28:53 UTC
oh, f*ck.. This is a Debian-specific change, just that it isn't made properly.
Comment 5 Loïc Minier 2005-07-06 19:55:59 UTC
*** Bug 309627 has been marked as a duplicate of this bug. ***