Bug 1017977 - Display manager does not require root password for shutdown or reboot
Summary: Display manager does not require root password for shutdown or reboot
Status: RESOLVED DUPLICATE of bug 960306
Alias: None
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 42.2
Hardware: 64bit openSUSE 42.2
: P5 - None : Major (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-01-04 00:51 UTC by Dennis Golden
Modified: 2017-01-04 09:41 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dennis Golden 2017-01-04 00:51:06 UTC
Display manager does not require root password for shutdown/reboot. I have specified root in Desktop->Display manager->DISPLAYMANAGER_SHUTDOWN and it never asks for the root password for shutdown or reboot. I have changed from sddm to kdm and it makes no difference. 

This has worked up through leap 42.1.

Worse yet, it doesn't require anyone to be logged in. It will allow shutdown from the login screen.

This is a show stopper for my servers.
Comment 1 Andreas Stieger 2017-01-04 08:33:06 UTC
Wolfgang, is this a duplicate of bug 960306?
Comment 2 Ludwig Nussel 2017-01-04 09:41:40 UTC
looks like it. DISPLAYMANAGER_SHUTDON should have been removed from xdm when the feature in kdm was dropped ... filed bug 1018045

*** This bug has been marked as a duplicate of bug 960306 ***