From <IMAP4.psuedo.sims> Tue May 20 19:28:01 2008
Date: Tue, 20 May 2008 19:28:01 -0700 (PDT)
From: Postmaster
Subject: Message from mail server       
Content-Length: 94
Mime-Version: 1.0
Status: RO
X-IMAP: 1211230672 55

Delete.
This is a system message.                                













--END+PSEUDO--

From gww@sac.sfbay.sun.com Tue May 13 15:01:01 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4DM11aZ008358
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 13 May 2008 15:01:01 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4DM10H2017235;
	Tue, 13 May 2008 15:01:01 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0T00M03UHO3600@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 13 May 2008 15:01:00 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0T00666UHNUW90@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 13 May 2008 15:01:00 -0700 (PDT)
Received: from sac.sfbay.sun.com (new-sac.SFBay.Sun.COM [129.146.175.65])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m4DM0xoa016017; Tue, 13 May 2008 15:00:59 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4DM0v2V008330; Tue,
 13 May 2008 15:00:57 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id m4DM0vIr008326; Tue, 13 May 2008 15:00:57 -0700 (PDT)
Date: Tue, 13 May 2008 15:00:57 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
To: psarc-ext@sun.com
Cc: james.hughes@sun.com
Message-id: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Content-Length: 2910
Status: RO
X-Status: $$$$
X-UID: 0000000001

I'm sponsoring this Fast Track for Jim Hughes.
It requests a Patch release binding for the mechanisms and technology
and a Major release binding for default activation.  The interface
taxonomies remain unchanged.
The timer is set for 20 May, 2008

Gary..
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Background:
==========
Since SunOS 5.8, Solaris has had the ability, through rbac(5), to
administer the system without a "root" user login.
Historically, the "root" user exists as an "owner" of system objects.
(It would be possible to have system objects "owned" by different system
users.  There may be marginal value in doing so.  This project does not
propose changing system object ownership.)

Historically, running with euid of 0 granted full system access.
Since SunOS 5.10 Solaris has had the ability, through privileges(5),
to administer the system without requiring full system access.
The "root" (system) user can be controlled by making "root" a role.
If a site doesn't grant the role to any user, no user can become "root".
Alternatively, it was suggested that in other OS distros, "root" is,
by default, not an account that can ever be directly used.  In SunOS
5.10 terms that would be a no login account (see passwd(1) -N).

It has been suggested that Solaris should permit "root" to be a no login
account.

Problem:
========
Making "root" a no login account means that "root" neither can be granted
as a role, nor can the system be booted to system maintenance mode
(single user).

Proposal:
========
Add a "solaris.system.maintenance" authorization.  Modify sulogin(1M) to
prompt for a username and password.  If the username entered is
authenticated by the password and has the "solaris.system.maintenance"
authorization, enter system maintenance mode.  If not, as before this
project, deny access.

Notes:
======
This proposal allows for administrators to grant users system maintenance
mode access without giving them the knowledge of the "root" password.

This proposal does not ensure that the authenticated username is not
a role.

The "root" user is, by default, granted all authorizations.  So, there
is no regression if "root" is not made a no login account.

A no login account ("root" or otherwise) can still run cron jobs.
The solaris.jobs.admin authorization permits a user to manage all cron jobs.

Non-"root" users may be granted Rights Profiles or roles that permit
the users to administer the entire system.

The current authorizations in solaris.system space are:
	solaris.system.:::Machine Administration::help=SysHeader.html
	solaris.system.date:::Set Date & Time::help=SysDate.html
	solaris.system.shutdown:::Shutdown the System::help=SysShutdown.html

This project enables a policy where "root" can never be used directly by
administrators as an account providing full system access.
In a Major release this policy may be made the default.

From bart.smaalders@sun.com Tue May 13 16:50:31 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4DNoVXH013098
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 13 May 2008 16:50:31 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4DNoVjW013308;
	Tue, 13 May 2008 16:50:31 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0T00301ZK5R300@nwk-avmta-2.sfbay.sun.com>; Tue,
 13 May 2008 16:50:29 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0T00J7CZK5QK80@nwk-avmta-2.sfbay.sun.com>; Tue,
 13 May 2008 16:50:29 -0700 (PDT)
Received: from [129.146.228.109] (cyber.SFBay.Sun.COM [129.146.228.109])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4DNoSS5729534; Tue, 13 May 2008 16:50:28 -0700 (PDT)
Date: Tue, 13 May 2008 16:50:28 -0700
From: Bart Smaalders <bart.smaalders@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: psarc-ext@sun.com, james.hughes@sun.com
Message-id: <482A2944.2030305@Sun.COM>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.12 (X11/20080310)
Content-Length: 3550
Status: RO
X-Status: $$$$
X-UID: 0000000002

Gary Winiger wrote:
> I'm sponsoring this Fast Track for Jim Hughes.
> It requests a Patch release binding for the mechanisms and technology
> and a Major release binding for default activation.  The interface
> taxonomies remain unchanged.
> The timer is set for 20 May, 2008
> 
> Gary..
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> Background:
> ==========
> Since SunOS 5.8, Solaris has had the ability, through rbac(5), to
> administer the system without a "root" user login.
> Historically, the "root" user exists as an "owner" of system objects.
> (It would be possible to have system objects "owned" by different system
> users.  There may be marginal value in doing so.  This project does not
> propose changing system object ownership.)
> 
> Historically, running with euid of 0 granted full system access.
> Since SunOS 5.10 Solaris has had the ability, through privileges(5),
> to administer the system without requiring full system access.
> The "root" (system) user can be controlled by making "root" a role.
> If a site doesn't grant the role to any user, no user can become "root".
> Alternatively, it was suggested that in other OS distros, "root" is,
> by default, not an account that can ever be directly used.  In SunOS
> 5.10 terms that would be a no login account (see passwd(1) -N).
> 
> It has been suggested that Solaris should permit "root" to be a no login
> account.
> 
> Problem:
> ========
> Making "root" a no login account means that "root" neither can be granted
> as a role, nor can the system be booted to system maintenance mode
> (single user).
> 
> Proposal:
> ========
> Add a "solaris.system.maintenance" authorization.  Modify sulogin(1M) to
> prompt for a username and password.  If the username entered is
> authenticated by the password and has the "solaris.system.maintenance"
> authorization, enter system maintenance mode.  If not, as before this
> project, deny access.
> 
> Notes:
> ======
> This proposal allows for administrators to grant users system maintenance
> mode access without giving them the knowledge of the "root" password.
> 
> This proposal does not ensure that the authenticated username is not
> a role.
> 
> The "root" user is, by default, granted all authorizations.  So, there
> is no regression if "root" is not made a no login account.
> 
> A no login account ("root" or otherwise) can still run cron jobs.
> The solaris.jobs.admin authorization permits a user to manage all cron jobs.
> 
> Non-"root" users may be granted Rights Profiles or roles that permit
> the users to administer the entire system.
> 
> The current authorizations in solaris.system space are:
> 	solaris.system.:::Machine Administration::help=SysHeader.html
> 	solaris.system.date:::Set Date & Time::help=SysDate.html
> 	solaris.system.shutdown:::Shutdown the System::help=SysShutdown.html
> 
> This project enables a policy where "root" can never be used directly by
> administrators as an account providing full system access.
> In a Major release this policy may be made the default.

How do I log into and configure a blank system image?  Is a default
account created that has this privilege, or does the lack of such
an account mean that the system must be repaired by booting
from alternate media?

How will we insure that there are real administrative users present
in the password file?

-= Bart


-- 
Bart Smaalders			Solaris Kernel Performance
barts@cyber.eng.sun.com		http://blogs.sun.com/barts
"You will contribute more with mercurial than with thunderbird."

From jek3@sun.com Tue May 13 17:55:25 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4E0tOaf015232
	for <psarc-ext@sac.sfbay.Sun.COM>; Tue, 13 May 2008 17:55:25 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4E0tClJ010432;
	Wed, 14 May 2008 08:55:20 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U0061R2K0J300@nwk-avmta-2.sfbay.sun.com>; Tue,
 13 May 2008 17:55:12 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U00JA32JZQLE0@nwk-avmta-2.sfbay.sun.com>; Tue,
 13 May 2008 17:55:11 -0700 (PDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4E0tAaN736560; Tue, 13 May 2008 17:55:11 -0700 (PDT)
Date: Tue, 13 May 2008 14:56:43 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A2944.2030305@Sun.COM>
To: Bart Smaalders <bart.smaalders@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Message-id: <482A38CB.8000908@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 445
Status: RO
X-Status: $$$$
X-UID: 0000000003

Bart Smaalders wrote:
> How will we insure that there are real administrative users present
> in the password file?
Are you asserting that installation must create a administrative user
(as with Ubuntu, Debian, others) or something else?  If its "something 
else",
could you elaborate?

If an administrative user deletes all administrative users from the passwd
file,... well those are the breaks.  He got exactly what he wanted. :-)

- jek3




From Torrey.McMahon@sun.com Tue May 13 18:00:42 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4E10g80015348
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 13 May 2008 18:00:42 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4E10fvv043658
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 13 May 2008 19:00:42 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U00J0H2T44G00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 13 May 2008 18:00:40 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U00CAV2T3W080@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 13 May 2008 18:00:39 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m4E10d6W003213	for
 <psarc-ext@sun.com>; Wed, 14 May 2008 01:00:39 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0U003012OTJL00@mail-amer.sun.com>
 (original mail from Torrey.McMahon@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 13 May 2008 19:00:39 -0600 (MDT)
Received: from [192.168.0.199] ([69.143.4.246])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K0U009WT2T1QQ60@mail-amer.sun.com>; Tue,
 13 May 2008 19:00:39 -0600 (MDT)
Date: Tue, 13 May 2008 21:00:38 -0400
From: Torrey McMahon <Torrey.McMahon@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A38CB.8000908@sun.com>
Sender: Torrey.McMahon@sun.com
To: Joseph Kowalski <jek3@sun.com>
Cc: Bart Smaalders <bart.smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Message-id: <482A39B6.7030402@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
User-Agent: Thunderbird 2.0.0.14 (Windows/20080421)
Content-Length: 625
Status: RO
X-Status: $$$$
X-UID: 0000000004

Joseph Kowalski wrote:
> Bart Smaalders wrote:
>> How will we insure that there are real administrative users present
>> in the password file?
> Are you asserting that installation must create a administrative user
> (as with Ubuntu, Debian, others) or something else?  If its "something 
> else",
> could you elaborate?
>
> If an administrative user deletes all administrative users from the 
> passwd
> file,... well those are the breaks.  He got exactly what he wanted. :-)

Boot off the live CD, mount the image, etc. I guess we should add 
something pretty bulletproof to the docs. Perhaps a "fix root access" 
utility?

From jek3@sun.com Tue May 13 18:26:56 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4E1QtLO015531
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 13 May 2008 18:26:56 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4E1QptS015469;
	Wed, 14 May 2008 02:26:51 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U0080140Q1R00@nwk-avmta-2.sfbay.sun.com>; Tue,
 13 May 2008 18:26:50 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U00J5040QQDE0@nwk-avmta-2.sfbay.sun.com>; Tue,
 13 May 2008 18:26:50 -0700 (PDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4E1QnUc740568; Tue, 13 May 2008 18:26:49 -0700 (PDT)
Date: Tue, 13 May 2008 15:28:22 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A39B6.7030402@sun.com>
To: Torrey McMahon <Torrey.McMahon@sun.com>
Cc: Bart Smaalders <Bart.Smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        james.hughes@sun.com
Message-id: <482A4036.7010404@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
 <482A39B6.7030402@sun.com>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 1049
Status: RO
X-Status: $$$$
X-UID: 0000000005

Torrey McMahon wrote:
> Joseph Kowalski wrote:
>> Bart Smaalders wrote:
>>> How will we insure that there are real administrative users present
>>> in the password file?
>> Are you asserting that installation must create a administrative user
>> (as with Ubuntu, Debian, others) or something else?  If its 
>> "something else",
>> could you elaborate?
>>
>> If an administrative user deletes all administrative users from the 
>> passwd
>> file,... well those are the breaks.  He got exactly what he wanted. :-)
>
> Boot off the live CD, mount the image, etc.
Sounds pretty insecure, but we have this issue already.
> I guess we should add something pretty bulletproof to the docs.
Agreed.  My contact in Ubuntu (who no longer works there) told
me that lots of folk we confused by the "no login" root.  It wasn't
really a problem, but it there was a major "what the ****" response.

It will probably be easier for us as others have already been the
pioneers.

> Perhaps a "fix root access" utility?
:-)

(I hope the smiley is appropriate!)

- jek3


From bart.smaalders@sun.com Tue May 13 18:49:29 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4E1nSg3015816
	for <psarc-ext@sac.sfbay.Sun.COM>; Tue, 13 May 2008 18:49:29 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4E1nFWj001758;
	Wed, 14 May 2008 09:49:21 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U00E01526S900@brm-avmta-1.central.sun.com>; Tue,
 13 May 2008 19:49:18 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U0046H5260B60@brm-avmta-1.central.sun.com>; Tue,
 13 May 2008 19:49:18 -0600 (MDT)
Received: from [129.146.228.109] (cyber.SFBay.Sun.COM [129.146.228.109])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4E1nHKU742676; Tue, 13 May 2008 18:49:17 -0700 (PDT)
Date: Tue, 13 May 2008 18:49:17 -0700
From: Bart Smaalders <bart.smaalders@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A39B6.7030402@sun.com>
To: Torrey McMahon <Torrey.McMahon@sun.com>
Cc: Joseph Kowalski <jek3@sun.com>, Gary Winiger <gww@sac.sfbay.sun.com>,
        psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <482A451D.7030905@Sun.COM>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
 <482A39B6.7030402@sun.com>
User-Agent: Thunderbird 2.0.0.12 (X11/20080310)
Content-Length: 1967
Status: RO
X-Status: $$$$
X-UID: 0000000006

Torrey McMahon wrote:
> Joseph Kowalski wrote:
>> Bart Smaalders wrote:
>>> How will we insure that there are real administrative users present
>>> in the password file?
>> Are you asserting that installation must create a administrative user
>> (as with Ubuntu, Debian, others) or something else?  If its "something 
>> else",
>> could you elaborate?
>>
>> If an administrative user deletes all administrative users from the 
>> passwd
>> file,... well those are the breaks.  He got exactly what he wanted. :-)
> 
> Boot off the live CD, mount the image, etc. I guess we should add 
> something pretty bulletproof to the docs. Perhaps a "fix root access" 
> utility?


In the case of a single user system, the current architecture
suffices, perhaps modulo a missing "sudo" :-).

What I'm trying to point out is that the actual problem is that
we want to know who did what on the system, which a single root
account shared by multiple users thwarts since that account has
a single username/password.

The proposed replacement is the creation of multiple accounts
which have the privilege to become root-like; each belonging to
a different administrator so that their actions are clearly attributable.
This leverages the current pam modules and provides appropriate
logging to see just who was root when the bad thing happened.

The result of this, however, is that the same requirements that
we make on the root account (local password entry, local home
directory, no dependency on network services, etc) now extend
to the potentially privileged accounts if they are to be used
to repair broken/mis-configured systems.

Are there other alternatives to be considered that maintain
knowledge of who become root w/o requiring completely
separate accounts on each system for each administrator?

- Bart



-- 
Bart Smaalders			Solaris Kernel Performance
barts@cyber.eng.sun.com		http://blogs.sun.com/barts
"You will contribute more with mercurial than with thunderbird."

From jek3@sun.com Tue May 13 19:27:12 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4E2RBiP017164
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 13 May 2008 19:27:12 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4E2R3ms006945;
	Wed, 14 May 2008 03:27:07 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U006096T53X00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 13 May 2008 19:27:05 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U000R16T5SN20@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 13 May 2008 19:27:05 -0700 (PDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4E2R42r745423; Tue, 13 May 2008 19:27:04 -0700 (PDT)
Date: Tue, 13 May 2008 16:28:37 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A451D.7030905@Sun.COM>
To: Bart Smaalders <bart.smaalders@sun.com>
Cc: Torrey McMahon <Torrey.McMahon@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Message-id: <482A4E55.8020601@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
 <482A39B6.7030402@sun.com> <482A451D.7030905@Sun.COM>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 2081
Status: RO
X-Status: $$$$
X-UID: 0000000007


Ah, auditing.

I now understand your concern and agree that it is a important concern.

Unfortunately, I don't have an answer, so I look forward to future 
discussion
about this.

- jek3

Bart Smaalders wrote:
> Torrey McMahon wrote:
>> Joseph Kowalski wrote:
>>> Bart Smaalders wrote:
>>>> How will we insure that there are real administrative users present
>>>> in the password file?
>>> Are you asserting that installation must create a administrative user
>>> (as with Ubuntu, Debian, others) or something else?  If its 
>>> "something else",
>>> could you elaborate?
>>>
>>> If an administrative user deletes all administrative users from the 
>>> passwd
>>> file,... well those are the breaks.  He got exactly what he wanted. :-)
>>
>> Boot off the live CD, mount the image, etc. I guess we should add 
>> something pretty bulletproof to the docs. Perhaps a "fix root access" 
>> utility?
>
>
> In the case of a single user system, the current architecture
> suffices, perhaps modulo a missing "sudo" :-).
>
> What I'm trying to point out is that the actual problem is that
> we want to know who did what on the system, which a single root
> account shared by multiple users thwarts since that account has
> a single username/password.
>
> The proposed replacement is the creation of multiple accounts
> which have the privilege to become root-like; each belonging to
> a different administrator so that their actions are clearly attributable.
> This leverages the current pam modules and provides appropriate
> logging to see just who was root when the bad thing happened.
>
> The result of this, however, is that the same requirements that
> we make on the root account (local password entry, local home
> directory, no dependency on network services, etc) now extend
> to the potentially privileged accounts if they are to be used
> to repair broken/mis-configured systems.
>
> Are there other alternatives to be considered that maintain
> knowledge of who become root w/o requiring completely
> separate accounts on each system for each administrator?
>
> - Bart
>
>
>


From Nicolas.Williams@sun.com Tue May 13 21:05:44 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4E45h7Q019079
	for <psarc-ext@sac.sfbay.Sun.COM>; Tue, 13 May 2008 21:05:44 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4E45UJZ018381;
	Wed, 14 May 2008 12:05:39 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U00H01BDDEJ00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 13 May 2008 21:05:37 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U0003GBDDSO80@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 13 May 2008 21:05:37 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m4E45aq7026177;
 Tue, 13 May 2008 23:05:36 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m4E45aC6026176; Tue,
 13 May 2008 23:05:36 -0500 (CDT)
Date: Tue, 13 May 2008 23:05:36 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A38CB.8000908@sun.com>
To: Joseph Kowalski <jek3@sun.com>
Cc: Bart Smaalders <Bart.Smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Mail-followup-to: Joseph Kowalski <jek3@sun.com>,
 Bart Smaalders <Bart.Smaalders@sun.com>, Gary Winiger <gww@sac.sfbay.sun.com>,
 psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <20080514040536.GW13552@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Content-Length: 674
Status: RO
X-Status: $$$$
X-UID: 0000000008

On Tue, May 13, 2008 at 02:56:43PM -1000, Joseph Kowalski wrote:
> Bart Smaalders wrote:
> >How will we insure that there are real administrative users present
> >in the password file?
> Are you asserting that installation must create a administrative user
> (as with Ubuntu, Debian, others) or something else?  If its "something 
> else",
> could you elaborate?
> 
> If an administrative user deletes all administrative users from the passwd
> file,... well those are the breaks.  He got exactly what he wanted. :-)

IIRC sulogin simply execs a root shell if /etc/passwd and /etc/shadow
are missing/damaged.  Presumably this would still be true (or false, if
it is false).

From MAILER-DAEMON Wed May 14 02:09:41 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4E99eKO025026
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 14 May 2008 02:09:41 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4E99Qg6005317;
	Wed, 14 May 2008 17:09:38 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U00501PFZUY00@nwk-avmta-2.sfbay.sun.com>; Wed,
 14 May 2008 02:09:35 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U005LCPFYGJ00@nwk-avmta-2.sfbay.sun.com>; Wed,
 14 May 2008 02:09:34 -0700 (PDT)
Received: from snowdog (snowdog.SFBay.Sun.COM [129.146.228.213])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4E99Y8R770380; Wed, 14 May 2008 02:09:34 -0700 (PDT)
Date: Wed, 14 May 2008 02:13:15 -0700
From: Dan Price <dp@eng.sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: psarc-ext@sun.com, james.hughes@sun.com
Message-id: <20080514091315.GA10512@eng.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
User-Agent: Mutt/1.4.2.1i
Content-Length: 1540
Status: RO
X-Status: $$$$
X-UID: 0000000009

On Tue 13 May 2008 at 03:00PM, Gary Winiger wrote:
> This project enables a policy where "root" can never be used directly by
> administrators as an account providing full system access.
> In a Major release this policy may be made the default.

How will sysidtool work in the face of this?  Today, it asks for a root
password for the system and basically provisions root as a non-role
account.  While sysidtool is not terribly important for the global zone
for OpenSolaris 2008.05, it is critically important for zone first-boot,
when the system is effectively blank.  It seems to me that in order
to make this a default behavior, sysidtool would need to be aware of this
policy and provision accordingly.

If that isn't what is meant by default-- then, please further clarify the
meaning.  Perhaps I'm just confused-- if so, please help me to not be.

Would changes to sys-unconfig also be required?  Would it be sensible
to strip privileges and/or passwords from highly privileged users on
an unconfig in the same way that we currently strip out the root password?

To be clear: I'm agnostic about the goodness of this idea; I'm concerned
that the defintion of "default" is not clear, and that the zones case
has not been fully explored here.  In a sense, a zone is the "most pure"
version of this problem, since it doesn't get much provisioned by an
installer, really--  it just gets laid out on the system, and lets
sysidtool do the rest.

        -dp

-- 
Daniel Price - Solaris Kernel Engineering - dp@eng.sun.com - blogs.sun.com/dp

From Joerg.Schilling@fokus.fraunhofer.de Wed May 14 03:15:09 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4EAF9tH025838
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 14 May 2008 03:15:09 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4EAF2pB001889;
	Wed, 14 May 2008 03:15:08 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U00505SH6FN00@brm-avmta-1.central.sun.com>; Wed,
 14 May 2008 04:15:06 -0600 (MDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U00MK1SH5R180@brm-avmta-1.central.sun.com>; Wed,
 14 May 2008 04:15:05 -0600 (MDT)
Received: from relay15i.sun.com
 (ip125.net129179-4.block1.us.syntegra.com [129.179.4.125])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m4EADbHV019047; Wed,
 14 May 2008 10:15:05 +0000 (GMT)
Received: from mmp13es.sun.com ([160.41.209.23] [160.41.209.23])
 by relay15i.sun.com with ESMTP id BT-MMP-79890; Wed,
 14 May 2008 10:15:05 +0000 (Z)
Received: from relay11i.sun.com (relay11i.sun.com [129.179.4.121])
 by mmp13es.sun.com with ESMTP id BT-MMP-86722; Wed,
 14 May 2008 10:15:04 +0000 (Z)
Received: from mailgw1.fraunhofer.de ([153.96.1.17] [153.96.1.17])
 by relay1ib.sun.com with ESMTP id BT-MMP-954064; Wed,
 14 May 2008 10:15:04 +0000 (Z)
Received: from mailgw1.fraunhofer.de (localhost [127.0.0.1])
	by mailgw1.fraunhofer.de[host mailgw24] (8.14.2+/8.14.2)
 with ESMTP id m4EA3M2h026351; Wed, 14 May 2008 12:03:22 +0200 (CEST)
Received: from pluto.fokus.fraunhofer.de
 (pluto.fokus.fraunhofer.de [195.37.77.164])
	by mailgw1.fraunhofer.de (8.14.2+/8.14.2) with ESMTP id m4EA3Mxg026342
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Wed,
 14 May 2008 12:03:22 +0200 (CEST)
Received: from EXCHSRV.fokus.fraunhofer.de (bohr [10.147.9.231])
	by pluto.fokus.fraunhofer.de (8.13.7/8.13.7) with SMTP id m4EA3LR7006403; Wed,
 14 May 2008 12:03:22 +0200 (MEST)
Received: from rigel ([10.147.65.195]) by EXCHSRV.fokus.fraunhofer.de with
 Microsoft SMTPSVC(6.0.3790.3959); Wed, 14 May 2008 12:03:22 +0200
Date: Wed, 14 May 2008 12:03:21 +0200
From: Joerg.Schilling@fokus.fraunhofer.de (Joerg Schilling)
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A4036.7010404@sun.com>
To: Torrey.McMahon@sun.com, jek3@sun.com
Cc: psarc-ext@sun.com, james.hughes@sun.com, gww@sac.sfbay.sun.com,
        Bart.Smaalders@sun.com
Message-id: <482ab8e9.KuoebWRWYaEMT7qr%Joerg.Schilling@fokus.fraunhofer.de>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Fraunhofer-Email-Policy: accepted
X-Antispam: No, score=0.0/5.0, scanned in 0.182sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
 <482A39B6.7030402@sun.com> <482A4036.7010404@sun.com>
User-Agent: nail 11.22 3/20/05
X-OriginalArrivalTime: 14 May 2008 10:03:22.0262 (UTC)
 FILETIME=[BE0C0B60:01C8B5A9]
Content-Length: 1158
Status: RO
X-Status: $$$$
X-UID: 0000000010

Joseph Kowalski <jek3@sun.com> wrote:

> > Boot off the live CD, mount the image, etc.
> Sounds pretty insecure, but we have this issue already.
> > I guess we should add something pretty bulletproof to the docs.
> Agreed.  My contact in Ubuntu (who no longer works there) told
> me that lots of folk we confused by the "no login" root.  It wasn't
> really a problem, but it there was a major "what the ****" response.
>
> It will probably be easier for us as others have already been the
> pioneers.
>
> > Perhaps a "fix root access" utility?

A good idea would be to allow /sbin/sulogin to log you in as root if the
system does not have a "root role" enabled user (would this make sulogin huge?).

The other question would be how to find out "root role" enabled user if you 
don't know him?

How about allowing root "loging" in single user mode by default?

Jörg

-- 
 EMail:joerg@schily.isdn.cs.tu-berlin.de (home) Jörg Schilling D-13353 Berlin
       js@cs.tu-berlin.de                (uni)  
       schilling@fokus.fraunhofer.de     (work) Blog: http://schily.blogspot.com/
 URL:  http://cdrecord.berlios.de/old/private/ ftp://ftp.berlios.de/pub/schily

From Darren.Moffat@sun.com Wed May 14 04:25:28 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4EBPSPD026502
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 14 May 2008 04:25:28 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4EBPRaI020615
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 14 May 2008 04:25:28 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U00A1XVQF7R00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 14 May 2008 05:25:27 -0600 (MDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U00MYGVQBR2D0@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 05:25:24 -0600 (MDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe2.eu.sun.com [192.18.6.11])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4EBPNVn005964	for
 <psarc-ext@sun.com>; Wed, 14 May 2008 11:25:23 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0U00C01VIGSD00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 12:25:23 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K0U00F7UVPFU310@fe-emea-10.sun.com>; Wed,
 14 May 2008 12:24:53 +0100 (BST)
Date: Wed, 14 May 2008 12:24:51 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
Sender: Darren.Moffat@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <482ACC03.8080409@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.12 (X11/20080326)
Content-Length: 1587
Status: RO
X-Status: $$$$
X-UID: 0000000011

Based on the comments of others I think there is some confusion as to 
what this case is actually proposing the notes part is supporting 
information not actual change.  I think it is simply this:

Instead of being asked for the root password when sulogin runs it now 
asks for a username and password.  If the username provided is not root 
then the user must have been granted the solaris.system.maintenance 
authorisations.  However it will still be "root" that is logged in via 
sulogin not the user.

In a default configuration with the current Solaris legacy installer the 
only change is that the word "root" needs to be entered before the root 
password (because root has all solaris.* authorisations explicitly 
granted in root's user_attr(4) entry).

This case basically just names a new authorisation that can be given to 
users.  It doesn't change the behaviour of the root account, it doesn't 
require that the installer or sysidroot (or any other part of sysid) be 
changed.

The case *suggests* a possible future case for a possible Major release 
binding where this new policy is used as part of a bigger future change 
to restricted root from logins completely.

The one part of the notes that I think is critical is "This proposal 
does not ensure that the authenticated username is not
a role."  In particular it ensures that this case is compatible with the 
legacy Solaris installer and the root as a role behaviour that 
OpenSolaris 2008.05 (Caiman) uses when a local account *is* created at 
install time.


Is that a correct interpretation ?

--
Darren J Moffat


From ceri@submonkey.net Wed May 14 04:37:34 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4EBbYcE026615
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 14 May 2008 04:37:34 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4EBbRAw010468;
	Wed, 14 May 2008 12:37:30 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U00A1VWAGVU00@brm-avmta-1.central.sun.com>; Wed,
 14 May 2008 05:37:28 -0600 (MDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U00A7CWAENG00@brm-avmta-1.central.sun.com>; Wed,
 14 May 2008 05:37:27 -0600 (MDT)
Received: from relay12i.sun.com
 (ip122.net129179-4.block1.us.syntegra.com [129.179.4.122])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m4EBWq8w029081; Wed,
 14 May 2008 11:37:26 +0000 (GMT)
Received: from mmp13es.sun.com ([160.41.209.23] [160.41.209.23])
 by relay12i.sun.com with ESMTP id BT-MMP-81230; Wed,
 14 May 2008 11:37:26 +0000 (Z)
Received: from relay11i.sun.com (relay11i.sun.com [129.179.4.121])
 by mmp13es.sun.com with ESMTP id BT-MMP-185681; Wed,
 14 May 2008 11:37:26 +0000 (Z)
Received: from shrike.submonkey.net ([82.15.31.38] [82.15.31.38])
 by relay1i.sun.com with ESMTP id BT-MMP-1056856; Wed,
 14 May 2008 11:37:25 +0000 (Z)
Received: from ceri by shrike.submonkey.net with local (Exim 4.69 (FreeBSD))
	(envelope-from <ceri@submonkey.net>)	id 1JwFIO-000AY8-GY; Wed,
 14 May 2008 12:37:20 +0100
Date: Wed, 14 May 2008 12:37:20 +0100
From: Ceri Davies <ceri@submonkey.net>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482ab8e9.KuoebWRWYaEMT7qr%Joerg.Schilling@fokus.fraunhofer.de>
Sender: Ceri Davies <ceri@submonkey.net>
To: Joerg Schilling <Joerg.Schilling@fokus.fraunhofer.de>
Cc: Torrey.McMahon@sun.com, jek3@sun.com, psarc-ext@sun.com,
        Bart.Smaalders@sun.com, james.hughes@sun.com, gww@sac.sfbay.sun.com
Message-id: <20080514113720.GA95450@submonkey.net>
MIME-version: 1.0
Content-type: multipart/signed; micalg=pgp-sha1;
 protocol="application/pgp-signature"; boundary=ReaqsoxgOBHFXBhH
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-PGP: finger ceri@FreeBSD.org
X-Antispam: No, score=0.0/5.0, scanned in 0.064sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
 <482A39B6.7030402@sun.com> <482A4036.7010404@sun.com>
 <482ab8e9.KuoebWRWYaEMT7qr%Joerg.Schilling@fokus.fraunhofer.de>
User-Agent: Mutt/1.5.17 (2007-11-01)
Content-Length: 1693
Status: RO
X-Status: $$$$
X-UID: 0000000012


--ReaqsoxgOBHFXBhH
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, May 14, 2008 at 12:03:21PM +0200, Joerg Schilling wrote:
> Joseph Kowalski <jek3@sun.com> wrote:
>=20
> > > Boot off the live CD, mount the image, etc.
> > Sounds pretty insecure, but we have this issue already.
> > > I guess we should add something pretty bulletproof to the docs.
> > Agreed.  My contact in Ubuntu (who no longer works there) told
> > me that lots of folk we confused by the "no login" root.  It wasn't
> > really a problem, but it there was a major "what the ****" response.
> >
> > It will probably be easier for us as others have already been the
> > pioneers.
> >
> > > Perhaps a "fix root access" utility?
>=20
> A good idea would be to allow /sbin/sulogin to log you in as root if the
> system does not have a "root role" enabled user (would this make sulogin =
huge?).

The suggestion is that a root password wouldn't exist, so that would be
hard to justify anyway.

> The other question would be how to find out "root role" enabled user if y=
ou=20
> don't know him?

Hopefully, such a mechanism wouldn't exist unless you were already
logged in, or it would represent a worrying information leak.

Ceri
--=20
That must be wonderful!  I don't understand it at all.
                                                  -- Moliere

--ReaqsoxgOBHFXBhH
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (FreeBSD)

iD8DBQFIKs7wocfcwTS3JF8RAokrAJ4/OrxoEH2lVFRiqqlkAjoVKZqOIgCdFwCQ
/Uy2gqh55mrlsBHRV/igO4o=
=9pew
-----END PGP SIGNATURE-----

--ReaqsoxgOBHFXBhH--

From ceri@submonkey.net Wed May 14 04:39:53 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4EBdrhk026665
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 14 May 2008 04:39:53 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4EBdrBd024604
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 14 May 2008 04:39:53 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0U00M03WEHB100@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 14 May 2008 04:39:53 -0700 (PDT)
Received: from sca-ea-mail-3.sun.com ([192.18.43.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0U006A4WEF7YD0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 04:39:51 -0700 (PDT)
Received: from relay17i.sun.com
 (ip127.net129179-4.block1.us.syntegra.com [129.179.4.127])
	by sca-ea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m4EBZwYq028132	for
 <psarc-ext@sun.com>; Wed, 14 May 2008 11:39:51 +0000 (GMT)
Received: from mmp14es.sun.com ([160.41.209.24] [160.41.209.24])
 by relay17i.sun.com with ESMTP id BT-MMP-85769 for psarc-ext@sun.com; Wed,
 14 May 2008 11:39:50 +0000 (Z)
Received: from relay15i.sun.com (relay15i.sun.com [129.179.4.125])
 by mmp14es.sun.com with ESMTP id BT-MMP-186066 for psarc-ext@sun.com; Wed,
 14 May 2008 11:39:50 +0000 (Z)
Received: from shrike.submonkey.net ([82.15.31.38] [82.15.31.38])
 by relay1i.sun.com with ESMTP id BT-MMP-1060251 for psarc-ext@sun.com; Wed,
 14 May 2008 11:39:50 +0000 (Z)
Received: from ceri by shrike.submonkey.net with local (Exim 4.69 (FreeBSD))
	(envelope-from <ceri@submonkey.net>)	id 1JwFKm-0008Gm-NN; Wed,
 14 May 2008 12:39:48 +0100
Date: Wed, 14 May 2008 12:39:48 +0100
From: Ceri Davies <ceri@submonkey.net>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <20080514040536.GW13552@Sun.COM>
Sender: Ceri Davies <ceri@submonkey.net>
To: Joseph Kowalski <jek3@sun.com>, Bart Smaalders <Bart.Smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Message-id: <20080514113948.GB95450@submonkey.net>
MIME-version: 1.0
Content-type: multipart/signed; micalg=pgp-sha1;
 protocol="application/pgp-signature"; boundary=H+4ONPRPur6+Ovig
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-PGP: finger ceri@FreeBSD.org
X-Antispam: No, score=0.0/5.0, scanned in 0.059sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
 <20080514040536.GW13552@Sun.COM>
User-Agent: Mutt/1.5.17 (2007-11-01)
Content-Length: 1479
Status: RO
X-Status: $$$$
X-UID: 0000000013


--H+4ONPRPur6+Ovig
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Tue, May 13, 2008 at 11:05:36PM -0500, Nicolas Williams wrote:
> On Tue, May 13, 2008 at 02:56:43PM -1000, Joseph Kowalski wrote:
> > Bart Smaalders wrote:
> > >How will we insure that there are real administrative users present
> > >in the password file?
> > Are you asserting that installation must create a administrative user
> > (as with Ubuntu, Debian, others) or something else?  If its "something=
=20
> > else",
> > could you elaborate?
> >=20
> > If an administrative user deletes all administrative users from the pas=
swd
> > file,... well those are the breaks.  He got exactly what he wanted. :-)
>=20
> IIRC sulogin simply execs a root shell if /etc/passwd and /etc/shadow
> are missing/damaged.  Presumably this would still be true (or false, if
> it is false).

I'd suggest it would be a lot harder to interpret "there are no
administrative users" as "this password file is broken, so come on in".

Ceri
--=20
That must be wonderful!  I don't understand it at all.
                                                  -- Moliere

--H+4ONPRPur6+Ovig
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (FreeBSD)

iD8DBQFIKs+EocfcwTS3JF8RAvN7AKCtUQFgWwCuwBT9f67MQpQn1s6JZQCgmqWc
PkwuoYCHcYMe4IH1lkJwNIc=
=GEg1
-----END PGP SIGNATURE-----

--H+4ONPRPur6+Ovig--

From Torrey.McMahon@sun.com Wed May 14 06:48:57 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4EDmuIC001565
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 14 May 2008 06:48:56 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4EDme38029230
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 14 May 2008 21:48:55 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0V00I032DHQD00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 14 May 2008 07:48:53 -0600 (MDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0V00A7Q2DGNQ90@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 07:48:52 -0600 (MDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m4EDmqU6028897	for
 <psarc-ext@sun.com>; Wed, 14 May 2008 13:48:52 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0V00G012C24000@mail-amer.sun.com>
 (original mail from Torrey.McMahon@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 07:48:52 -0600 (MDT)
Received: from [192.168.0.199] ([69.143.4.246])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K0V003OA2DDFM20@mail-amer.sun.com>; Wed,
 14 May 2008 07:48:51 -0600 (MDT)
Date: Wed, 14 May 2008 09:48:51 -0400
From: Torrey McMahon <Torrey.McMahon@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A4036.7010404@sun.com>
Sender: Torrey.McMahon@sun.com
To: Joseph Kowalski <jek3@sun.com>
Cc: Bart Smaalders <Bart.Smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Message-id: <482AEDC3.7030007@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <482A38CB.8000908@sun.com>
 <482A39B6.7030402@sun.com> <482A4036.7010404@sun.com>
User-Agent: Thunderbird 2.0.0.14 (Windows/20080421)
Content-Length: 1348
Status: RO
X-Status: $$$$
X-UID: 0000000014

Joseph Kowalski wrote:
> Torrey McMahon wrote:
>> Joseph Kowalski wrote:
>>> Bart Smaalders wrote:
>>>> How will we insure that there are real administrative users present
>>>> in the password file?
>>> Are you asserting that installation must create a administrative user
>>> (as with Ubuntu, Debian, others) or something else?  If its 
>>> "something else",
>>> could you elaborate?
>>>
>>> If an administrative user deletes all administrative users from the 
>>> passwd
>>> file,... well those are the breaks.  He got exactly what he wanted. :-)
>>
>> Boot off the live CD, mount the image, etc.
> Sounds pretty insecure, but we have this issue already.
>> I guess we should add something pretty bulletproof to the docs.
> Agreed.  My contact in Ubuntu (who no longer works there) told
> me that lots of folk we confused by the "no login" root.  It wasn't
> really a problem, but it there was a major "what the ****" response.
>
> It will probably be easier for us as others have already been the
> pioneers.
>
>> Perhaps a "fix root access" utility?
> :-)
>
> (I hope the smiley is appropriate!)

After I hit send I went, "Hmmm....maybe I should have phrased that 
differently?" Famous last words, right?

What I really meant was something like "Provide system management 
authorization for a user" and then you pick a user, hit apply, etc.




From James.Hughes@sun.com Wed May 14 08:37:39 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4EFbd7X004289
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 14 May 2008 08:37:39 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4EFbcwj012976
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 14 May 2008 08:37:39 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0V003077EQ0700@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 14 May 2008 09:37:38 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0V000NC7EQ8230@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 09:37:38 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4EFbcko023700	for
 <psarc-ext@sun.com>; Wed, 14 May 2008 08:37:38 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0V00E01789VP00@fe-sfbay-10.sun.com>
 (original mail from James.Hughes@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 08:37:38 -0700 (PDT)
Received: from [10.0.1.222] (c-67-161-47-18.hsd1.ca.comcast.net [67.161.47.18])
 by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K0V00GR47EORY10@fe-sfbay-10.sun.com>; Wed,
 14 May 2008 08:37:36 -0700 (PDT)
Date: Wed, 14 May 2008 08:37:35 -0700
From: james hughes <James.Hughes@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482A2944.2030305@Sun.COM>
Sender: James.Hughes@sun.com
To: Bart Smaalders <Bart.Smaalders@sun.com>
Cc: james hughes <James.Hughes@sun.com>, Gary Winiger <gww@sac.sfbay.sun.com>,
        psarc-ext@sun.com
Message-id: <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
MIME-version: 1.0
X-Mailer: Apple Mail (2.919.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM>
Content-Length: 2426
Status: RO
X-Status: $$$$
X-UID: 0000000015


On May 13, 2008, at 4:50 PM, Bart Smaalders wrote:
>
> How do I log into and configure a blank system image?  Is a default
> account created that has this privilege, or does the lack of such
> an account mean that the system must be repaired by booting
> from alternate media?

Loosing or breaking the administrator's account is identical to  
loosing root password.

> How will we insure that there are real administrative users present
> in the password file?

The real administrative users present in the password file because the  
initial installation put it there.

This is not about the elimination of root as a much as it is the  
ability to create a machine that has a no root password. Previous  
methods of having root have a password are still possible. In 2008.05,  
it is possible for the initial user to type "pfexec passwd -N root"  
and continue on their way simply typing "pfexec bash" instead of "su"/ 
password combination. My motivation was that asking for the password  
at installation was a needless step because of the above. The bug was  
that if you eliminated the root password and wanted to get single  
user, it was not possible, hence the case.

If the target market is Linux web 2.0 developer. The application  
developers I know of (personal experience included) rely heavily on  
sudo.  In addition to other OSs like Ubuntu, Mac OS X also runs  
without the root password. (People that are developing the Linux  
kernel typically run as root and are not the target IMO.)

With this change web 2.0 admins can do "pfexec bash", "sudo bash" or  
add a password to root. (IMO, we do need at least a redirect of people  
typing sudo to pfexec and a longer term plan around sudo, and we  
should think about doing this in general. I believe Ubuntu has the  
ability to suggest packages when unknown commands are typed in.)

Longer term, it is another password that the developer does not need  
to remember, change and manage.

Enterprise admins have more issues as Bart suggests, but they are more  
motivated to eliminate the management of shared root passwords and  
their human processes. This change does not eliminate how enterprises  
are doing it now.

Bottom line is that it results in simpler installation, simpler  
management and similar administration (to Ubuntu and Mac OS X) and  
does not break the existing paradigm. For we RHEL developers this  
hurdle is not significant.

Jim


From James.Hughes@sun.com Wed May 14 08:43:00 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4EFh0Hq004412
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 14 May 2008 08:43:00 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4EFgxYD012357
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 14 May 2008 09:43:00 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0V0030D7NNBY00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 14 May 2008 09:42:59 -0600 (MDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0V000897NM8430@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 09:42:59 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4EFgwXT029723	for
 <psarc-ext@sun.com>; Wed, 14 May 2008 08:42:58 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0V002017KC1700@fe-sfbay-10.sun.com>
 (original mail from James.Hughes@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 14 May 2008 08:42:58 -0700 (PDT)
Received: from [10.0.1.222] (c-67-161-47-18.hsd1.ca.comcast.net [67.161.47.18])
 by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K0V00GS97NMRY10@fe-sfbay-10.sun.com>; Wed,
 14 May 2008 08:42:58 -0700 (PDT)
Date: Wed, 14 May 2008 08:42:57 -0700
From: james hughes <James.Hughes@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <20080514091315.GA10512@eng.sun.com>
Sender: James.Hughes@sun.com
To: Dan Price <dp@eng.sun.com>
Cc: james hughes <James.Hughes@sun.com>, Gary Winiger <gww@sac.sfbay.sun.com>,
        psarc-ext@sun.com
Message-id: <7B4D2677-FB7B-4ADF-B40B-5A981BF1886B@Sun.COM>
MIME-version: 1.0
X-Mailer: Apple Mail (2.919.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <20080514091315.GA10512@eng.sun.com>
Content-Length: 1044
Status: RO
X-Status: $$$$
X-UID: 0000000016


On May 14, 2008, at 2:13 AM, Dan Price wrote:

> On Tue 13 May 2008 at 03:00PM, Gary Winiger wrote:
>> This project enables a policy where "root" can never be used  
>> directly by
>> administrators as an account providing full system access.
>> In a Major release this policy may be made the default.
>
> To be clear: I'm agnostic about the goodness of this idea; I'm  
> concerned
> that the defintion of "default" is not clear, and that the zones case
> has not been fully explored here.

I hope the previous message helps with this...

> In a sense, a zone is the "most pure"
> version of this problem, since it doesn't get much provisioned by an
> installer, really--  it just gets laid out on the system, and lets
> sysidtool do the rest.

Agreed that the zone issue has not been fully explored and we should  
do this before approving this case. I did create a zone on DP1 and ran  
into this bug, and I seem to remember using "zlogin -S" or something  
like that to get around the lack of a root password. Fixing this is  
mandatory.


From MAILER-DAEMON Wed May 14 13:05:37 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4EK5aCP021997
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 14 May 2008 13:05:36 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4EK5Qjf001643;
	Thu, 15 May 2008 04:05:33 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0V0040FJT8E900@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 14 May 2008 13:05:32 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0V00GD7JT8F660@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 14 May 2008 13:05:32 -0700 (PDT)
Received: from snowdog (snowdog.SFBay.Sun.COM [129.146.228.213])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4EK5VxD857451; Wed, 14 May 2008 13:05:31 -0700 (PDT)
Date: Wed, 14 May 2008 13:09:16 -0700
From: Dan Price <dp@eng.sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <7B4D2677-FB7B-4ADF-B40B-5A981BF1886B@Sun.COM>
To: james hughes <James.Hughes@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com
Message-id: <20080514200916.GA10908@eng.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <20080514091315.GA10512@eng.sun.com>
 <7B4D2677-FB7B-4ADF-B40B-5A981BF1886B@Sun.COM>
User-Agent: Mutt/1.4.2.1i
Content-Length: 3126
Status: RO
X-Status: $$$$
X-UID: 0000000017

On Wed 14 May 2008 at 08:42AM, james hughes wrote:
> 
> On May 14, 2008, at 2:13 AM, Dan Price wrote:
> 
> >On Tue 13 May 2008 at 03:00PM, Gary Winiger wrote:
> >>This project enables a policy where "root" can never be used  
> >>directly by
> >>administrators as an account providing full system access.
> >>In a Major release this policy may be made the default.
> >
> >To be clear: I'm agnostic about the goodness of this idea; I'm  
> >concerned that the defintion of "default" is not clear, and that the
> >zones case has not been fully explored here.
> 
> I hope the previous message helps with this...

Well it does in the sense that it provides the motivation and
context.  I was really trying to point out something different, but wasn't
clear.  It also doesn't answer my questions about sys-unconfig.
To back up slightly to my confusion: The text of the case says:

> In a Major release this policy may be made the default.

This statement is vague-- if this case is approved, does that mean
that a team working on a major release may make this the default
without further review?

Or does it mean that in the event of a major release, PSARC would
see another case which effects this change?

If the latter, then please rewrite:

"This case does not set this policy as the default for the system.  A
future major release could adopt this policy as the default, although
further architectural change will be required in order to support
non-global zones and to alter existing installation technologies
(if supported) to properly provision non-root users.  Future cases
will address this."

There is a new requirement being placed on the installation
technologies here-- when this policy is active, then delivering
/etc/passwd from packages is no longer enough to provision the system--
and so when this policy is the default, wider changes are going to
be needed.  And that is what I think needs resolution here.  There should
be a clear specification of what an installer should do-- otherwise,
you'll see all sorts of bizarre stuff happening with packages and
install-time provisioning (as we saw in DP1 and DP2).

> >In a sense, a zone is the "most pure"
> >version of this problem, since it doesn't get much provisioned by an
> >installer, really--  it just gets laid out on the system, and lets
> >sysidtool do the rest.
> 
> Agreed that the zone issue has not been fully explored and we should  
> do this before approving this case. I did create a zone on DP1 and ran  
> into this bug, and I seem to remember using "zlogin -S" or something  
> like that to get around the lack of a root password. Fixing this is  
> mandatory.

Great!

As an aside, DP1 zones support (and 2008.05 zones support for that matter)
isn't really representative of anything other than a hack and slash
attempt to get *something* working in the allotted time.  It should not be
regarded as architecture.

For further background on how this issue has impacted zones,
you may wish to review:

http://defect.opensolaris.org/bz/show_bug.cgi?id=681

	-dp

-- 
Daniel Price - Solaris Kernel Engineering - dp@eng.sun.com - blogs.sun.com/dp

From scott.rotondo@sun.com Wed May 14 23:05:32 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4F65Vv9006053
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 14 May 2008 23:05:32 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4F65NMG025841;
	Thu, 15 May 2008 14:05:29 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0W00F03BL49X00@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 00:05:28 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0W00CDFBL3NO10@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 00:05:27 -0600 (MDT)
Received: from viaggio.local (punchin-rotondo.SFBay.Sun.COM [10.7.251.213])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4F65RWQ920141; Wed, 14 May 2008 23:05:27 -0700 (PDT)
Date: Wed, 14 May 2008 23:06:28 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
To: james hughes <James.Hughes@sun.com>
Cc: psarc-ext@sun.com
Message-id: <482BD2E4.7050804@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (Macintosh/20080421)
Content-Length: 3388
Status: RO
X-Status: $$$$
X-UID: 0000000018

james hughes wrote:
> 
> This is not about the elimination of root as a much as it is the ability 
> to create a machine that has a no root password. Previous methods of 
> having root have a password are still possible. In 2008.05, it is 
> possible for the initial user to type "pfexec passwd -N root" and 
> continue on their way simply typing "pfexec bash" instead of 
> "su"/password combination. My motivation was that asking for the 
> password at installation was a needless step because of the above. The 
> bug was that if you eliminated the root password and wanted to get 
> single user, it was not possible, hence the case.
> 
> If the target market is Linux web 2.0 developer. The application 
> developers I know of (personal experience included) rely heavily on 
> sudo.  In addition to other OSs like Ubuntu, Mac OS X also runs without 
> the root password. (People that are developing the Linux kernel 
> typically run as root and are not the target IMO.)
> 
> With this change web 2.0 admins can do "pfexec bash", "sudo bash" or add 
> a password to root. (IMO, we do need at least a redirect of people 
> typing sudo to pfexec and a longer term plan around sudo, and we should 
> think about doing this in general. I believe Ubuntu has the ability to 
> suggest packages when unknown commands are typed in.)
> 
> Longer term, it is another password that the developer does not need to 
> remember, change and manage.
> 
> Enterprise admins have more issues as Bart suggests, but they are more 
> motivated to eliminate the management of shared root passwords and their 
> human processes. This change does not eliminate how enterprises are 
> doing it now.
> 
> Bottom line is that it results in simpler installation, simpler 
> management and similar administration (to Ubuntu and Mac OS X) and does 
> not break the existing paradigm. For we RHEL developers this hurdle is 
> not significant.

There's another way you might solve the same problem and achieve some 
other benefits simultaneously.

1. It would be a lot simpler and more convenient if role accounts didn't 
require passwords at all. The only reason they have passwords is that we 
needed the role accounts to be able to act as NIS+ principals, and that 
requires a credential that is generated from the account login password. 
If we could find an alternative way to generate that credential (or 
declare that the ability to act as a NIS+ principal just doesn't matter 
any more for a role account), we could make it more convenient to assume 
*any* role and reap the attendant benefit of managing fewer passwords.

2. It still makes sense to have the root account be a role, so that 
direct logins are disallowed and it is always possible to attribute 
actions performed as root to an individual user. For single-user login, 
however, you don't really need a new authorization. Instead, sulogin 
could allow single-user access if the user authenticates and is allowed 
to assume the root role. [I'd recommend this modification to the 
existing proposal in any case; the ability to assume the root role 
should be a valid substitute for the solaris.system.maintenance 
authorization.]

Adopting both of the suggestions above means that
* root actions can always be attributed to a real user
* assuming a role is more convenient for users
* fewer passwords need to be remembered, updated, etc.

	Scott


From sommerfeld@sun.com Thu May 15 07:08:00 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FE7xmY015053
	for <psarc-ext@sac.sfbay.Sun.COM>; Thu, 15 May 2008 07:08:00 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4FE7o2f005862;
	Thu, 15 May 2008 22:07:55 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0W0050FXX6EA00@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 08:07:54 -0600 (MDT)
Received: from localhost.east.sun.com ([129.148.19.3])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0W004VGXX4X900@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 08:07:53 -0600 (MDT)
Received: from localhost.east.sun.com (localhost [127.0.0.1])
	by localhost.east.sun.com (8.14.2+Sun/8.14.2) with ESMTP id m4FE7qjZ002398;
 Thu, 15 May 2008 07:07:52 -0700 (PDT)
Received: (from sommerfeld@localhost)	by localhost.east.sun.com
 (8.14.2+Sun/8.14.2/Submit) id m4FE7p5t002397; Thu,
 15 May 2008 10:07:51 -0400 (EDT)
Date: Thu, 15 May 2008 10:07:51 -0400
From: Bill Sommerfeld <sommerfeld@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482BD2E4.7050804@sun.com>
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: james hughes <James.Hughes@sun.com>, psarc-ext@sun.com
Message-id: <1210860471.2170.11.camel@localhost>
MIME-version: 1.0
X-Mailer: Evolution 2.12.2
Content-type: text/plain
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482BD2E4.7050804@sun.com>
X-Authentication-warning: localhost.east.sun.com: sommerfeld set sender to
 sommerfeld@sun.com using -f
Content-Length: 1417
Status: RO
X-Status: $$$$
X-UID: 0000000019


On Wed, 2008-05-14 at 23:06 -0700, Scott Rotondo wrote:
> The only reason they have passwords is that we 
> needed the role accounts to be able to act as NIS+ principals, and that 
> requires a credential that is generated from the account login password. 
> If we could find an alternative way to generate that credential (or 
> declare that the ability to act as a NIS+ principal just doesn't matter 
> any more for a role account), 

folks interested in solving this may want to look more closely at the
Kerberos "ksu" scheme invented at Project Athena; rather than having a
shared password, people who have administrative roles are issued one or
more secondary principals, each with independent passwords (via the
kerberos "instance" naming convention).  Rather than one shared password
on the role account, each user gets their own "root instance" password.
Actions taken as a "root instance" are attributable to an individual
person, while the regular user account and password are only as powerful
(and thus only as sensitive) than an account without special powers.

> Adopting both of the suggestions above means that
> * root actions can always be attributed to a real user
> * assuming a role is more convenient for users
> * fewer passwords need to be remembered, updated, etc.

IMHO the biggest benefit is one you failed to mention:
* password sharing between people is never necessary

						- Bill




From paul@clubi.ie Thu May 15 08:13:22 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FFDLkl015812
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 08:13:22 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4FFCwd5015019;
	Thu, 15 May 2008 16:13:18 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00F0B0Y3QM00@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 15 May 2008 08:13:15 -0700 (PDT)
Received: from sca-ea-mail-1.sun.com ([192.18.43.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X0089Z0Y3AE70@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 15 May 2008 08:13:15 -0700 (PDT)
Received: from relay42i.sun.com ([192.5.209.72])
	by sca-ea-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4FFBTGZ020224;
 Thu, 15 May 2008 15:13:15 +0000 (GMT)
Received: from mms48es.mms.us.syntegra.com ([160.41.221.230] [160.41.221.230])
 by relay42i.sun.com with ESMTP id BT-MMP-109751; Thu,
 15 May 2008 15:13:10 +0000 (Z)
Received: from relay44i.sun.com (relay44i.sun.com [192.5.209.118])
 by mms48es.sun.com with ESMTP id BT-MMP-40901499; Thu,
 15 May 2008 15:13:10 +0000 (Z)
Received: from hibernia.jakma.org ([212.17.55.49] [212.17.55.49])
 by relay4i.sun.com with ESMTP id BT-MMP-3947226; Thu,
 15 May 2008 15:13:09 +0000 (Z)
Received: from melandri.gla.jakma.org (melandri.jakma.org [81.168.24.37])
	(authenticated bits=0)	by hibernia.jakma.org (8.14.2/8.14.2)
 with ESMTP id m4FFCx7s013823
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu,
 15 May 2008 16:13:05 +0100
Date: Thu, 15 May 2008 16:12:59 +0100 (BST)
From: Paul Jakma <paul@clubi.ie>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
X-X-Sender: paul@localhost.localdomain
To: james hughes <James.Hughes@sun.com>
Cc: Bart Smaalders <Bart.Smaalders@sun.com>, psarc-ext@sun.com,
        Gary Winiger <gww@sac.sfbay.sun.com>
Mail-followup-to: paul@jakma.org
Message-id: <alpine.LFD.1.10.0805151603130.715@localhost.localdomain>
MIME-version: 1.0
Content-type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
Mail-Copies-To: paul@jakma.org
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-NSA: al aqsar fluffy jihad cute musharef kittens jet-A1 ear avgas wax
 ammonium bad qran dog inshallah allah al-akbar martyr iraq hammas hisballah
 rabin ayatollah korea revolt pelvix mustard gas x-ray british airways
 washington peroxide cool
X-Greylist: Sender succeeded SMTP AUTH,
 not delayed by milter-greylist-4.0rc1 (hibernia.jakma.org [212.17.55.49]);
 Thu, 15 May 2008 16:13:07 +0100 (IST)
X-Virus-Scanned: ClamAV 0.92.1/7128/Thu May 15 10:45:41 2008 on
 hibernia.jakma.org
X-Virus-Status: Clean
X-Antispam: No, score=0.0/5.0, scanned in 0.587sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
User-Agent: Alpine 1.10 (LFD 962 2008-03-14)
Content-Length: 500
Status: RO
X-Status: $$$$
X-UID: 0000000020

On Wed, 14 May 2008, james hughes wrote:

> If the target market is Linux web 2.0 developer. The application
> developers I know of (personal experience included) rely heavily on
> sudo.

The likes of Ubuntu don't really target integration with network 
authentication though...

regards,
-- 
Paul Jakma	paul@clubi.ie	paul@jakma.org	Key ID: 64A2FF6A
Fortune:
In any world menu, Canada must be considered the vichyssoise of nations --
it's cold, half-French, and difficult to stir.
 		-- Stuart Keate

From Nicolas.Williams@sun.com Thu May 15 08:45:02 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FFj2ZL016183
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 08:45:02 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FFiw9u001638;
	Thu, 15 May 2008 09:45:00 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00I052F0KR00@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 15 May 2008 08:45:00 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X008YL2EZAE90@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 15 May 2008 08:45:00 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m4FFiu4m027013;
 Thu, 15 May 2008 10:44:56 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m4FFiu0K027012; Thu,
 15 May 2008 10:44:56 -0500 (CDT)
Date: Thu, 15 May 2008 10:44:56 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <1210860471.2170.11.camel@localhost>
To: Bill Sommerfeld <sommerfeld@sun.com>
Cc: Scott Rotondo <Scott.Rotondo@sun.com>, james hughes <James.Hughes@sun.com>,
        psarc-ext@sun.com
Mail-followup-to: Bill Sommerfeld <sommerfeld@sun.com>,
 Scott Rotondo <Scott.Rotondo@sun.com>, james hughes <James.Hughes@sun.com>,
 psarc-ext@sun.com
Message-id: <20080515154456.GN26388@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482BD2E4.7050804@sun.com> <1210860471.2170.11.camel@localhost>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Content-Length: 1165
Status: RO
X-Status: $$$$
X-UID: 0000000021

On Thu, May 15, 2008 at 10:07:51AM -0400, Bill Sommerfeld wrote:
> folks interested in solving this may want to look more closely at the
> Kerberos "ksu" scheme invented at Project Athena; rather than having a
> shared password, people who have administrative roles are issued one or
> more secondary principals, each with independent passwords (via the
> kerberos "instance" naming convention).  Rather than one shared password
> on the role account, each user gets their own "root instance" password.
> Actions taken as a "root instance" are attributable to an individual
> person, while the regular user account and password are only as powerful
> (and thus only as sensitive) than an account without special powers.

But note that there's no need for us to use ksu to get the same result.

We've previously discussed, more than once too, a user_attr for roles
that says that users assuming the role use not the role's shared
password but their own (or an alternate per-user password).  There's no
reason we shouldn't do that.

> IMHO the biggest benefit is one you failed to mention:
> * password sharing between people is never necessary

Hear hear.

Nico
-- 

From Nicolas.Williams@sun.com Thu May 15 08:50:15 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FFoEeE016214
	for <psarc-ext@sac.sfbay.Sun.COM>; Thu, 15 May 2008 08:50:14 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4FFlNMq015313;
	Thu, 15 May 2008 23:50:09 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00A0J2MYCS00@nwk-avmta-2.sfbay.sun.com>; Thu,
 15 May 2008 08:49:46 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X008VE2MXIT40@nwk-avmta-2.sfbay.sun.com>; Thu,
 15 May 2008 08:49:45 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m4FFnjvX027022;
 Thu, 15 May 2008 10:49:45 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m4FFnj31027021; Thu,
 15 May 2008 10:49:45 -0500 (CDT)
Date: Thu, 15 May 2008 10:49:45 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482BD2E4.7050804@sun.com>
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: james hughes <James.Hughes@sun.com>, psarc-ext@sun.com
Mail-followup-to: Scott Rotondo <Scott.Rotondo@Sun.COM>,
 james hughes <James.Hughes@sun.com>, psarc-ext@sun.com
Message-id: <20080515154944.GO26388@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482BD2E4.7050804@sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Content-Length: 874
Status: RO
X-Status: $$$$
X-UID: 0000000022

On Wed, May 14, 2008 at 11:06:28PM -0700, Scott Rotondo wrote:
> There's another way you might solve the same problem and achieve some 
> other benefits simultaneously.

Also, provided that root can only log in on console and console access 
authorization is checked and audited by an external system, then you can 
still tie audit records to an actual user.  The system in question had 
randomized root passwords that would be changed within some time of 
their being "checked out," and, as indicated above, those passwords 
could only be used on the console.

I helped deploy such a console access system years ago, so I know people 
do it.  With ILOMs it gets a bit more interesting, but not all that much 
harder.

The problem with this approach is that there's a necessary software 
component not delivered by us or as part of OpenSolaris, not today
anyways.

Nico
-- 

From scott.rotondo@sun.com Thu May 15 08:57:54 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FFvr8j016650
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 08:57:54 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4FFvVZs007311
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 16:57:52 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00A0N30EL700@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 08:57:50 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X008Z330EIW40@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 08:57:50 -0700 (PDT)
Received: from viaggio.local (punchin-rotondo.SFBay.Sun.COM [10.7.251.213])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4FFvoDT976292	for <psarc-ext@sun.com>; Thu,
 15 May 2008 08:57:50 -0700 (PDT)
Date: Thu, 15 May 2008 08:58:52 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <20080515154456.GN26388@Sun.COM>
To: psarc-ext@sun.com
Message-id: <482C5DBC.4030404@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482BD2E4.7050804@sun.com> <1210860471.2170.11.camel@localhost>
 <20080515154456.GN26388@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (Macintosh/20080421)
Content-Length: 2094
Status: RO
X-Status: $$$$
X-UID: 0000000023

Nicolas Williams wrote:
> On Thu, May 15, 2008 at 10:07:51AM -0400, Bill Sommerfeld wrote:
>> folks interested in solving this may want to look more closely at the
>> Kerberos "ksu" scheme invented at Project Athena; rather than having a
>> shared password, people who have administrative roles are issued one or
>> more secondary principals, each with independent passwords (via the
>> kerberos "instance" naming convention).  Rather than one shared password
>> on the role account, each user gets their own "root instance" password.
>> Actions taken as a "root instance" are attributable to an individual
>> person, while the regular user account and password are only as powerful
>> (and thus only as sensitive) than an account without special powers.
> 
> But note that there's no need for us to use ksu to get the same result.
> 
> We've previously discussed, more than once too, a user_attr for roles
> that says that users assuming the role use not the role's shared
> password but their own (or an alternate per-user password).  There's no
> reason we shouldn't do that.

Having users assume a role using their own login password is ideal since 
there are no additional passwords to remember. We didn't do it that way 
10 years ago because we needed to generate the role's NIS+ credential 
using a different password (but the same one for anyone who assumes the 
role).

I'm thinking that one of the following is probably true now:

1. We no longer care about roles acting as NIS+ principals [NIS+? What's 
that?] and we have no other situation where a credential is generated 
from the login password.

2. If #1 is not true, we can store the role's credential (in the role's 
home directory, for example) so that it can be accessed only by the role 
account. In general, this solution doesn't work for NIS+ credentials 
because superuser access on a client machine would override file 
permissions. Of course, one could administratively arrange for the file 
containing the credential to be NFS-mounted from a server that does not 
grant superuser access to remote clients.

	Scott




From scott.rotondo@sun.com Thu May 15 09:00:11 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FG0AlZ016757
	for <psarc-ext@sac.sfbay.Sun.COM>; Thu, 15 May 2008 09:00:11 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4FFxkje019996;
	Fri, 16 May 2008 00:00:08 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00A0J346O200@nwk-avmta-2.sfbay.sun.com>; Thu,
 15 May 2008 09:00:06 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X008A2345J250@nwk-avmta-2.sfbay.sun.com>; Thu,
 15 May 2008 09:00:05 -0700 (PDT)
Received: from viaggio.local (punchin-rotondo.SFBay.Sun.COM [10.7.251.213])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4FG05xw976731; Thu, 15 May 2008 09:00:05 -0700 (PDT)
Date: Thu, 15 May 2008 09:01:07 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <1210860471.2170.11.camel@localhost>
To: Bill Sommerfeld <sommerfeld@sun.com>
Cc: james hughes <James.Hughes@sun.com>, psarc-ext@sun.com
Message-id: <482C5E43.4020601@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482BD2E4.7050804@sun.com> <1210860471.2170.11.camel@localhost>
User-Agent: Thunderbird 2.0.0.14 (Macintosh/20080421)
Content-Length: 468
Status: RO
X-Status: $$$$
X-UID: 0000000024

Bill Sommerfeld wrote:
>> Adopting both of the suggestions above means that
>> * root actions can always be attributed to a real user
>> * assuming a role is more convenient for users
>> * fewer passwords need to be remembered, updated, etc.
> 
> IMHO the biggest benefit is one you failed to mention:
> * password sharing between people is never necessary
> 

In my mind, that was implied by the first bullet, but I should have 
explicitly listed it. Thanks.

	Scott

From Nicolas.Williams@sun.com Thu May 15 10:04:52 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FH4pag018919
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 10:04:51 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4FH4ks6010603;
	Thu, 15 May 2008 18:04:49 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00H0J63ZFN00@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 11:04:48 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00EF963Z9J20@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 11:04:47 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m4FH4lMc027048;
 Thu, 15 May 2008 12:04:47 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m4FH4l2L027047; Thu,
 15 May 2008 12:04:47 -0500 (CDT)
Date: Thu, 15 May 2008 12:04:47 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482C5DBC.4030404@sun.com>
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: psarc-ext@sun.com
Mail-followup-to: Scott Rotondo <Scott.Rotondo@Sun.COM>, psarc-ext@sun.com
Message-id: <20080515170446.GP26388@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482BD2E4.7050804@sun.com> <1210860471.2170.11.camel@localhost>
 <20080515154456.GN26388@Sun.COM> <482C5DBC.4030404@sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Content-Length: 1226
Status: RO
X-Status: $$$$
X-UID: 0000000025

On Thu, May 15, 2008 at 08:58:52AM -0700, Scott Rotondo wrote:
> I'm thinking that one of the following is probably true now:
> 
> 1. We no longer care about roles acting as NIS+ principals [NIS+? What's 
> that?] and we have no other situation where a credential is generated 
> from the login password.

Well, no, because the same consideration applies to Kerberos V as did to
DH credentials (speaking of which, when NIS+ goes away we'll still have
mech_dh to kick around).

> 2. If #1 is not true, we can store the role's credential (in the role's 
> home directory, for example) so that it can be accessed only by the role 

Yes.  In krb5 speak we'd keep them in a keytab, but not in a home
directory since it might not be local and might require those self-same
credentials to access.

> account. In general, this solution doesn't work for NIS+ credentials 
> because superuser access on a client machine would override file 
> permissions. Of course, one could administratively arrange for the file 
> containing the credential to be NFS-mounted from a server that does not 
> grant superuser access to remote clients.

Roles that need network authentication credentials will need
per-{role,host} credentials.

Nico
-- 

From sommerfeld@Sun.com Thu May 15 10:15:50 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FHFosF019311
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 10:15:50 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FHFnQE024567;
	Thu, 15 May 2008 10:15:49 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00I076MC8X00@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 11:15:48 -0600 (MDT)
Received: from localhost.east.sun.com ([129.148.19.3])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00EBQ6MB9S30@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 11:15:48 -0600 (MDT)
Received: from localhost.east.sun.com (localhost [127.0.0.1])
	by localhost.east.sun.com (8.14.2+Sun/8.14.2) with ESMTP id m4FHFluZ002563;
 Thu, 15 May 2008 10:15:47 -0700 (PDT)
Received: (from sommerfeld@localhost)	by localhost.east.sun.com
 (8.14.2+Sun/8.14.2/Submit) id m4FHFlvU002562; Thu,
 15 May 2008 13:15:47 -0400 (EDT)
Date: Thu, 15 May 2008 13:15:47 -0400
From: Bill Sommerfeld <sommerfeld@Sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482C5DBC.4030404@sun.com>
To: Scott Rotondo <Scott.Rotondo@Sun.com>
Cc: psarc-ext@Sun.com
Message-id: <1210871747.2170.19.camel@localhost>
MIME-version: 1.0
X-Mailer: Evolution 2.12.2
Content-type: text/plain
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482BD2E4.7050804@sun.com> <1210860471.2170.11.camel@localhost>
 <20080515154456.GN26388@Sun.COM> <482C5DBC.4030404@sun.com>
X-Authentication-warning: localhost.east.sun.com: sommerfeld set sender to
 sommerfeld@sun.com using -f
Content-Length: 903
Status: RO
X-Status: $$$$
X-UID: 0000000026


On Thu, 2008-05-15 at 08:58 -0700, Scott Rotondo wrote:
> 1. We no longer care about roles acting as NIS+ principals [NIS+? What's 
> that?] and we have no other situation where a credential is generated 
> from the login password.

The latter half of #1 is false; kerberos uses the login password as part
of acquiring network credentials.

> 2. If #1 is not true, we can store the role's credential (in the role's 
> home directory, for example) so that it can be accessed only by the role 
> account. In general, this solution doesn't work for NIS+ credentials 
> because superuser access on a client machine would override file 
> permissions. Of course, one could administratively arrange for the file 
> containing the credential to be NFS-mounted from a server that does not 
> grant superuser access to remote clients.

This doesn't work for kerberos because its credentials are perishable.  



From John.Plocher@sun.com Thu May 15 11:57:44 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FIviSK022459
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 11:57:44 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4FIvZQw028963
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 19:57:43 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X0020BBC5KD00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 12:57:41 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00EFZBC59O80@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 12:57:41 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4FIvfVn011695	for
 <psarc-ext@sun.com>; Thu, 15 May 2008 11:57:41 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0X00301B5MZ500@fe-sfbay-10.sun.com>
 (original mail from John.Plocher@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 11:57:41 -0700 (PDT)
Received: from wp668.SFBay.Sun.COM ([129.146.226.219])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K0X005PZBC1TX10@fe-sfbay-10.sun.com>; Thu,
 15 May 2008 11:57:37 -0700 (PDT)
Date: Thu, 15 May 2008 11:57:36 -0700
From: John Plocher <John.Plocher@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
Sender: John.Plocher@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <482C87A0.5040504@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.14 (Macintosh/20080421)
Content-Length: 1239
Status: RO
X-Status: $$$$
X-UID: 0000000027

Gary Winiger wrote:
> I'm sponsoring this Fast Track for Jim Hughes.

Can you clear up a usage-model confusion for me?

In "sudo land", I'm used to a model where

    I'm just "me" until I wish to increase my abilities, at
    which point I sudo to enable my superpowers.  When I'm
    done playing god, (and stop using sudo) those powers go
    away.

in "RBAC land", the model seems to be

    I'm never just me, I always have some set of superpowers
    that I can never turn off, so I always need to be more
    careful about consequences and side effects.

Am I misunderstanding things? If so, you can probably ignore
the rest (except maybe for humor value).

Just as someone invented sheaths for knives, because people
don't always need to walk around armed to the teeth, the
"sudo world" doesn't require everyone to walk around with
a loaded "rm *" command :-)

This proposal, if applied to my home system, would seem to
effectively make logging in as "plocher" be the same as
logging in as "root" - and is something I'm not sure I want.

What I do want is to be able, as "plocher", to say "I want
to explicitly do `foo` now, but not necessarily at any other
time without additional future confirmation being required".

   -John



From Nicolas.Williams@sun.com Thu May 15 12:15:38 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FJFbOc023025
	for <psarc-ext@sac.sfbay.Sun.COM>; Thu, 15 May 2008 12:15:38 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4FJFYmH011161;
	Fri, 16 May 2008 03:15:35 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00H01C5Y8O00@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 15 May 2008 12:15:34 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X004QXC5XHZ60@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 15 May 2008 12:15:34 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m4FJFXqZ027105;
 Thu, 15 May 2008 14:15:33 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m4FJFTsI027104; Thu,
 15 May 2008 14:15:29 -0500 (CDT)
Date: Thu, 15 May 2008 14:15:29 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482C87A0.5040504@Sun.Com>
To: John Plocher <John.Plocher@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Mail-followup-to: John Plocher <John.Plocher@Sun.COM>,
 Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <20080515191529.GT26388@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482C87A0.5040504@Sun.Com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Content-Length: 1277
Status: RO
X-Status: $$$$
X-UID: 0000000028

On Thu, May 15, 2008 at 11:57:36AM -0700, John Plocher wrote:
> In "sudo land", I'm used to a model where
> 
>    I'm just "me" until I wish to increase my abilities, at
>    which point I sudo to enable my superpowers.  When I'm
>    done playing god, (and stop using sudo) those powers go
>    away.
> 
> in "RBAC land", the model seems to be
> 
>    I'm never just me, I always have some set of superpowers
>    that I can never turn off, so I always need to be more
>    careful about consequences and side effects.
> 
> Am I misunderstanding things? If so, you can probably ignore
> the rest (except maybe for humor value).

You did misunderstand RBAC.

In RBAC land pfexec is the equivalent of sudo.

IF you use a pf*sh THEN you have what you described above.  And one
could just as easily write sudo*sh too.  These shells are like normal
shells that prepend pfexec (or SUDO, if there were sudo*sh shells) to
every non-built-in command-line.

The only differences between SUDO and RBAC are:

 - how the authorization DB is represented (sudoers vs. prof_attr +
   auth_attr + exec_attr + user_attr)

 - minor feature differences (like SUDO can let you reference all
   executables in a directory, use the not operator, specify argument
   pattern matching, ...)

Nico
-- 

From ceri@submonkey.net Thu May 15 12:18:26 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FJIPLb023164
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 12:18:26 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4FJIIEu007729
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 20:18:24 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00417CAN0V00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 13:18:23 -0600 (MDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00EIKCAM9JA0@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 13:18:22 -0600 (MDT)
Received: from relay21.sun.com
 (relay21.sun.com [192.12.251.24] (may be forged))	by sca-ea-mail-2.sun.com
 (8.13.7+Sun/8.12.9) with ESMTP id m4FJAHoQ014345	for <psarc-ext@sun.com>; Thu,
 15 May 2008 19:18:21 +0000 (GMT)
Received: from mms23es.sun.com ([150.143.232.54] [150.143.232.54])
 by relay21i.sun.com with ESMTP id BT-MMP-210670 for psarc-ext@sun.com; Thu,
 15 May 2008 19:18:17 +0000 (Z)
Received: from relay21.sun.com (relay21.sun.com [192.12.251.24])
 by mms23es.sun.com with ESMTP id BT-MMP-32893 for psarc-ext@sun.com; Thu,
 15 May 2008 19:18:17 +0000 (Z)
Received: from shrike.submonkey.net ([82.15.31.38] [82.15.31.38])
 by relay21i.sun.com with ESMTP id BT-MMP-7431495 for psarc-ext@sun.com; Thu,
 15 May 2008 19:18:16 +0000 (Z)
Received: from ceri by shrike.submonkey.net with local (Exim 4.69 (FreeBSD))
	(envelope-from <ceri@submonkey.net>)	id 1Jwixx-000PJj-K6; Thu,
 15 May 2008 20:18:13 +0100
Date: Thu, 15 May 2008 20:18:13 +0100
From: Ceri Davies <ceri@submonkey.net>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482C87A0.5040504@Sun.Com>
Sender: Ceri Davies <ceri@submonkey.net>
To: John Plocher <john.plocher@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Message-id: <20080515191813.GF40990@submonkey.net>
MIME-version: 1.0
Content-type: multipart/signed; micalg=pgp-sha1;
 protocol="application/pgp-signature"; boundary="Fig2xvG2VGoz8o/s"
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-PGP: finger ceri@FreeBSD.org
X-Antispam: No, score=0.0/5.0, scanned in 0.213sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482C87A0.5040504@Sun.Com>
User-Agent: Mutt/1.5.17 (2007-11-01)
Content-Length: 2146
Status: RO
X-Status: $$$$
X-UID: 0000000029


--Fig2xvG2VGoz8o/s
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, May 15, 2008 at 11:57:36AM -0700, John Plocher wrote:
> Gary Winiger wrote:
> > I'm sponsoring this Fast Track for Jim Hughes.
>=20
> Can you clear up a usage-model confusion for me?
>=20
> In "sudo land", I'm used to a model where
>=20
>     I'm just "me" until I wish to increase my abilities, at
>     which point I sudo to enable my superpowers.  When I'm
>     done playing god, (and stop using sudo) those powers go
>     away.
>=20
> in "RBAC land", the model seems to be
>=20
>     I'm never just me, I always have some set of superpowers
>     that I can never turn off, so I always need to be more
>     careful about consequences and side effects.
>=20
> Am I misunderstanding things? If so, you can probably ignore
> the rest (except maybe for humor value).
>=20
> Just as someone invented sheaths for knives, because people
> don't always need to walk around armed to the teeth, the
> "sudo world" doesn't require everyone to walk around with
> a loaded "rm *" command :-)
>=20
> This proposal, if applied to my home system, would seem to
> effectively make logging in as "plocher" be the same as
> logging in as "root" - and is something I'm not sure I want.

No, that would require assigning the account plocher to the Primary
Administrator profile and assigning it a profile shell.

> What I do want is to be able, as "plocher", to say "I want
> to explicitly do `foo` now, but not necessarily at any other
> time without additional future confirmation being required".

Don't use a profile shell, then use pfexec when you want to assert
escalated privilege.

Ceri

--=20
That must be wonderful!  I don't understand it at all.
                                                  -- Moliere

--Fig2xvG2VGoz8o/s
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (FreeBSD)

iD8DBQFILIx1ocfcwTS3JF8RAtHDAJ9IeenoKnQl2xIjafNXp1yz87pSDACbBTjq
aYbW7TkskUqHLNzf3QezsTs=
=igSm
-----END PGP SIGNATURE-----

--Fig2xvG2VGoz8o/s--

From gww@eng.sun.com Thu May 15 12:29:25 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FJTOJC023390
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 12:29:25 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4FJTHZX011906
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 20:29:24 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00407CSZTW00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 13:29:23 -0600 (MDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00E34CSY9SB0@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 13:29:23 -0600 (MDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m4FJTMGe037706; Thu, 15 May 2008 12:29:22 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id m4FJTgPg022565; Thu,
 15 May 2008 12:29:42 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id m4FJTgxl022564; Thu,
 15 May 2008 12:29:42 -0700 (PDT)
Date: Thu, 15 May 2008 12:29:42 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
To: John.Plocher@sun.com, gww@sac.sfbay.sun.com
Cc: James.Hughes@sun.com, psarc-ext@sun.com
Message-id: <200805151929.m4FJTgxl022564@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Content-Length: 983
Status: RO
X-Status: $$$$
X-UID: 0000000030

	The discussion seems to have wandered off from what the case proposes.
Many comments are interesting, don't appear to be this case, and could be
interesting other cases for some other project team to pursue.

	The project proposed by this case is to
		1) maintain compatibility with existing Solaris Roles,
		   Rights Profiles and related mechanisms.
		2) permit an administrator to configure root to be a
		   no login (passwd -N) account should they wish to
		   do so.  A side effect, even without making root a
		   no login account, is the ability to grant users the
		   ability to boot single without the need to share the
		   root password.
		3) ask permission to make the root account a nologin
		   account in a future Major release.  As has been
		   pointed out, there are various other projects that
		   making the root account a nologin account is dependent
		   upon.

	The project team will update the spec to make this clear when the
case has converged.

Gary..

From peter.tribble@gmail.com Thu May 15 12:42:37 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FJgb1k023523
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 12:42:37 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FJgaiU014244
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 13:42:37 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00K03DF04P00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 12:42:36 -0700 (PDT)
Received: from sca-ea-mail-1.sun.com ([192.18.43.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X004F8DF0I1A0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 12:42:36 -0700 (PDT)
Received: from relay23.sun.com
 (relay23.sun.com [192.12.251.54] (may be forged))	by sca-ea-mail-1.sun.com
 (8.13.7+Sun/8.12.9) with ESMTP id m4FJfsqC005219	for <psarc-ext@sun.com>; Thu,
 15 May 2008 19:42:36 +0000 (GMT)
Received: from mms24es.sun.com ([150.143.232.74] [150.143.232.74])
 by relay23i.sun.com with ESMTP id BT-MMP-207088 for psarc-ext@sun.com; Thu,
 15 May 2008 19:42:36 +0000 (Z)
Received: from relay23.sun.com (relay23.sun.com [192.12.251.54])
 by mms24es.sun.com with ESMTP id BT-MMP-74054 for psarc-ext@sun.com; Thu,
 15 May 2008 19:42:35 +0000 (Z)
Received: from rv-out-0708.google.com ([209.85.198.251] [209.85.198.251])
 by relay23i.sun.com with ESMTP id BT-MMP-7517617 for psarc-ext@sun.com; Thu,
 15 May 2008 19:42:35 +0000 (Z)
Received: by rv-out-0708.google.com with SMTP id k29so679505rvb.8 for
 <psarc-ext@sun.com>; Thu, 15 May 2008 12:41:45 -0700 (PDT)
Received: by 10.140.251.1 with SMTP id y1mr1294842rvh.292.1210880504794; Thu,
 15 May 2008 12:41:44 -0700 (PDT)
Received: by 10.140.132.2 with HTTP; Thu, 15 May 2008 12:41:44 -0700 (PDT)
Date: Thu, 15 May 2008 20:41:44 +0100
From: Peter Tribble <peter.tribble@gmail.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: psarc-ext@sun.com, james.hughes@sun.com
Message-id: <df1347730805151241n18ba5bc8x37b2f4902c422efc@mail.gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
Content-disposition: inline
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma;
 h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references;
 bh=pBIzx9F5ee9W0b93XsbKhY9HtEVqe+K4meJx/t+iFu8=;
 b=d4Ofy0W4+S25boAltaqi54fq5Ow12/JF8/Edc9wFchJ/beYKDjq5QRph3ACIAsF8rLMTjmNL1KkVld4qUShZEVKaqPD8gz9fMwwpPjxSY3UXntDseaRIbp7HhP5hDEKiw/ayTbn4xZ+BTUf/u/IDUs7pYDx6+cq3YqaMfxCGso4=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references;
 b=MV56egUuYdTInMziOpOShy85qx10ZenlzDx2eIP4AMUOalR2A/Li2T3UuSsCE4H2SbognHRxBBlm2VIFF3LY0PrLtp0nzJZJIDoV1ZuCS2U/KECn5805E+PBYTBSsYyI7uFGpiyFf0R85D3vJt4INJs2UQUcYqh9z9x236rxRo0=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=0.0/5.0, scanned in 0.399sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
Content-Length: 394
Status: RO
X-Status: $$$$
X-UID: 0000000031

> This project enables a policy where "root" can never be used directly by
> administrators as an account providing full system access.
> In a Major release this policy may be made the default.

And presumably that default could be overridden (simply, one would hope)
in order to provide traditional behaviour?

-- 
-Peter Tribble
http://www.petertribble.co.uk/ - http://ptribble.blogspot.com/

From gww@eng.sun.com Thu May 15 12:57:17 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FJvH8M023958
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 12:57:17 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FJvGbb021030
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 13:57:17 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00J0NE3GKU00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 12:57:16 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00H1EE3EOP50@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 12:57:15 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m4FJvEVi059688; Thu, 15 May 2008 12:57:14 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id m4FJvYUx022939; Thu,
 15 May 2008 12:57:34 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id m4FJvYEw022938; Thu,
 15 May 2008 12:57:34 -0700 (PDT)
Date: Thu, 15 May 2008 12:57:34 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
To: gww@sac.sfbay.sun.com, peter.tribble@gmail.com
Cc: psarc-ext@sun.com, james.hughes@sun.com
Message-id: <200805151957.m4FJvYEw022938@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Content-Length: 177
Status: RO
X-Status: $$$$
X-UID: 0000000032

> And presumably that default could be overridden (simply, one would hope)
> in order to provide traditional behaviour?

	Yes, see passwd(1).  Viz: passwd -r files root

Gary..

From John.Plocher@sun.com Thu May 15 13:06:50 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FK6o6d024286
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 13:06:50 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4FK6Z7u006848
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 21:06:49 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00J0JEJBXZ00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 13:06:47 -0700 (PDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00HDOEJAOT60@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 13:06:46 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4FK6kXm020452	for
 <psarc-ext@sun.com>; Thu, 15 May 2008 13:06:46 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0X00B01E5IL700@fe-sfbay-09.sun.com>
 (original mail from John.Plocher@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 13:06:46 -0700 (PDT)
Received: from wp668.SFBay.Sun.COM ([129.146.226.219])
 by fe-sfbay-09.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K0X00BAUEIWQR40@fe-sfbay-09.sun.com>; Thu,
 15 May 2008 13:06:32 -0700 (PDT)
Date: Thu, 15 May 2008 13:06:32 -0700
From: John Plocher <John.Plocher@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <20080515191529.GT26388@Sun.COM>
Sender: John.Plocher@sun.com
To: John Plocher <John.Plocher@sun.com>, Gary Winiger <gww@sac.sfbay.sun.com>,
        psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <482C97C8.8000707@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482C87A0.5040504@Sun.Com> <20080515191529.GT26388@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (Macintosh/20080421)
Content-Length: 1124
Status: RO
X-Status: $$$$
X-UID: 0000000033

Nicolas Williams wrote:
> You did misunderstand RBAC.
> In RBAC land pfexec is the equivalent of sudo.

 From Jim's mail, there seems to be an additional

    except for role-aware applications, for which you are
    always [an audited] god.

My fear is ending up in a world where more and more things
are role-aware and we set up the user environment [for the
first defined user?] such that they are forced to be a full
time demigod, rather than having to duck into a phone booth
first.

As Gary said, this topic is out of scope for this case,
though it may be for a hypothetical future "make root nologin"
case.

Since there is "more work to be done" to make root=nologin,
I question the advisability of granting the last point:

> 		3) ask permission to make the root account a nologin
> 		   account in a future Major release.  As has been
> 		   pointed out, there are various other projects that
> 		   making the root account a nologin account is dependent
> 		   upon.

I'd rather see a future case (umbrella?) that does this as a
simple explicit step that shows all the t's and i's dotted
and crossed.

   -John




From Nicolas.Williams@sun.com Thu May 15 13:09:11 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FK9BIa024314
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 13:09:11 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FK98bX024295;
	Thu, 15 May 2008 14:09:10 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X0070PEN9SM00@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 14:09:09 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00ESEEN89JD0@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 14:09:08 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m4FK942x027256;
 Thu, 15 May 2008 15:09:04 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m4FK94fh027255; Thu,
 15 May 2008 15:09:04 -0500 (CDT)
Date: Thu, 15 May 2008 15:09:04 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482C97C8.8000707@Sun.Com>
To: John Plocher <John.Plocher@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Mail-followup-to: John Plocher <John.Plocher@Sun.COM>,
 Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <20080515200904.GX26388@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482C87A0.5040504@Sun.Com> <20080515191529.GT26388@Sun.COM>
 <482C97C8.8000707@Sun.Com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Content-Length: 377
Status: RO
X-Status: $$$$
X-UID: 0000000034

On Thu, May 15, 2008 at 01:06:32PM -0700, John Plocher wrote:
> Nicolas Williams wrote:
> >You did misunderstand RBAC.
> >In RBAC land pfexec is the equivalent of sudo.
> 
> From Jim's mail, there seems to be an additional
> 
>    except for role-aware applications, for which you are
>    always [an audited] god.

Those tend to be in /usr/sbin though.  But, yes, good point.

From daleg@elemental.org Thu May 15 13:27:16 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FKRGFN024704
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 13:27:16 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FKRFcZ015559;
	Thu, 15 May 2008 13:27:15 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00K0BFHFS100@nwk-avmta-2.sfbay.sun.com>; Thu,
 15 May 2008 13:27:15 -0700 (PDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00H8DFHFOU70@nwk-avmta-2.sfbay.sun.com>; Thu,
 15 May 2008 13:27:15 -0700 (PDT)
Received: from relay44i.sun.com ([192.5.209.118])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4FKR69K003099;
 Thu, 15 May 2008 20:27:15 +0000 (GMT)
Received: from mms48es.mms.us.syntegra.com ([160.41.221.230] [160.41.221.230])
 by relay44i.sun.com with ESMTP id BT-MMP-124212; Thu,
 15 May 2008 20:27:06 +0000 (Z)
Received: from relay43i.sun.com (relay43i.sun.com [192.5.209.74])
 by mms48es.sun.com with ESMTP id BT-MMP-117393; Thu,
 15 May 2008 20:27:06 +0000 (Z)
Received: from mercury.elemental.org ([205.134.191.194] [205.134.191.194])
 by relay4i.sun.com with ESMTP id BT-MMP-4305316; Thu,
 15 May 2008 20:27:06 +0000 (Z)
Received: from [10.75.10.116] ([204.14.233.148])	(authenticated bits=0)
	by mercury.elemental.org (8.14.2/8.14.2/ELEMENTAL-4.0)
 with ESMTP id m4FKR5Lr003483
	(version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Thu,
 15 May 2008 16:27:05 -0400 (EDT)
Date: Thu, 15 May 2008 16:27:05 -0400
From: Dale Ghent <daleg@elemental.org>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: psarc-ext@sun.com, james.hughes@sun.com
Message-id: <5126C601-49CF-4539-BA04-9B68317EE723@elemental.org>
MIME-version: 1.0
X-Mailer: Apple Mail (2.919.2)
Content-type: text/plain; charset=US-ASCII; format=flowed; delsp=yes
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Greylist: Sender succeeded SMTP AUTH,
 not delayed by milter-greylist-4.0 (mercury.elemental.org [205.134.191.194]);
 Thu, 15 May 2008 16:27:05 -0400 (EDT)
X-Virus-Scanned: ClamAV 0.92/7130/Thu May 15 13:37:07 2008 on
 mercury.elemental.org
X-Virus-Status: Clean
X-Antispam: No, score=0.0/5.0, scanned in 0.055sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
Content-Length: 891
Status: RO
X-Status: $$$$
X-UID: 0000000035

On May 13, 2008, at 6:00 PM, Gary Winiger wrote:

> Proposal:
> ========
> Add a "solaris.system.maintenance" authorization.  Modify  
> sulogin(1M) to
> prompt for a username and password.  If the username entered is
> authenticated by the password and has the "solaris.system.maintenance"
> authorization, enter system maintenance mode.  If not, as before this
> project, deny access.

I haven't been able to follow every message in this busy thread, but  
please fill me on regarding one question I have:

At many sites, 'root' is the only local, non-locked account and all  
other users (aside from the standard system accounts such as  
daemon..nobody) are in NIS, LDAP, or the like and are auth'd via  
Kerberos.

Given that environment, what would happen in a situation where a box  
under this proposed scheme were to boot into single-user, with network  
access unavailable?

/dale

From jek3@sun.com Thu May 15 13:52:15 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FKqFhv025287
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 13:52:15 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FKqEo0026339;
	Thu, 15 May 2008 13:52:15 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00L0DGN0PE00@nwk-avmta-2.sfbay.sun.com>; Thu,
 15 May 2008 13:52:12 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00H5WGN0OP90@nwk-avmta-2.sfbay.sun.com>; Thu,
 15 May 2008 13:52:12 -0700 (PDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4FKqBim134562; Thu, 15 May 2008 13:52:11 -0700 (PDT)
Date: Thu, 15 May 2008 10:53:49 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805151929.m4FJTgxl022564@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>
Cc: John.Plocher@sun.com, gww@sac.sfbay.sun.com, James.Hughes@sun.com,
        psarc-ext@sun.com
Message-id: <482CA2DD.6040508@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805151929.m4FJTgxl022564@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 963
Status: RO
X-Status: $$$$
X-UID: 0000000036

Gary Winiger wrote:
> 	The project proposed by this case is to:
...
> 		3) ask permission to make the root account a nologin
> 		   account in a future Major release.  As has been
> 		   pointed out, there are various other projects that
> 		   making the root account a nologin account is dependent
> 		   upon.
>   
Since we now have clarification of the Major release issue and its 
underlying motivation/restriction around "developer familiarity", it 
seems misdirected to consider this for a potential Major release.

I'd request that this Binding of "default" to "Major release" be removed 
from this case.

I know PSARC is only one of several organizations which will need to 
"chime-in" to make this be the default, but it does no good to have 
PSARC "pre-approve" such a binding.

To be clear, if this Major binding clause isn't removed, I will derail 
this.  Having it makes this fast-track fail the "obvious and 
uncontroversial" requirement.

- jek3


From gdamore@sun.com Thu May 15 14:02:02 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FL21l3025799
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 14:02:01 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4FL1wO8002063
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 22:02:00 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X0050JH39FN00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 14:01:57 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X004RXH37HZD0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 14:01:55 -0700 (PDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4FL1tB8019242	for
 <psarc-ext@sun.com>; Thu, 15 May 2008 14:01:55 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0X00C01GGXCZ00@fe-sfbay-10.sun.com> (original mail from gdamore@sun.com)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 14:01:55 -0700 (PDT)
Received: from [192.168.251.106] ([76.174.83.55])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K0X00KG4H366G40@fe-sfbay-10.sun.com>; Thu,
 15 May 2008 14:01:55 -0700 (PDT)
Date: Thu, 15 May 2008 13:55:40 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482CA2DD.6040508@sun.com>
Sender: Garrett.Damore@sun.com
To: Joseph Kowalski <jek3@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, John.Plocher@sun.com,
        gww@sac.sfbay.sun.com, James.Hughes@sun.com, psarc-ext@sun.com
Message-id: <482CA34C.7030604@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805151929.m4FJTgxl022564@marduk.eng.sun.com>
 <482CA2DD.6040508@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071023)
Content-Length: 1094
Status: RO
X-Status: $$$$
X-UID: 0000000037

Joseph Kowalski wrote:
> Gary Winiger wrote:
>>     The project proposed by this case is to:
> ...
>>         3) ask permission to make the root account a nologin
>>            account in a future Major release.  As has been
>>            pointed out, there are various other projects that
>>            making the root account a nologin account is dependent
>>            upon.
>>   
> Since we now have clarification of the Major release issue and its 
> underlying motivation/restriction around "developer familiarity", it 
> seems misdirected to consider this for a potential Major release.
>
> I'd request that this Binding of "default" to "Major release" be 
> removed from this case.
>
> I know PSARC is only one of several organizations which will need to 
> "chime-in" to make this be the default, but it does no good to have 
> PSARC "pre-approve" such a binding.
>
> To be clear, if this Major binding clause isn't removed, I will derail 
> this.  Having it makes this fast-track fail the "obvious and 
> uncontroversial" requirement.

+1

Thanks Joe.

    -- Garrett

>
> - jek3
>


From johnsonnenschein@gmail.com Thu May 15 14:25:21 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FLPLah026228
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 14:25:21 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FLPKK6046843
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 15 May 2008 15:25:21 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00D0DI689J00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 15 May 2008 15:25:20 -0600 (MDT)
Received: from sca-ea-mail-4.sun.com ([192.18.43.22])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00BQLI67LK10@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 15 May 2008 15:25:19 -0600 (MDT)
Received: from relay42i.sun.com ([192.5.209.72])
	by sca-ea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m4FLPJmX027085	for
 <psarc-ext@sun.com>; Thu, 15 May 2008 21:25:19 +0000 (GMT)
Received: from mms49es.mms.us.syntegra.com ([160.41.221.232] [160.41.221.232])
 by relay42i.sun.com with ESMTP id BT-MMP-122488 for psarc-ext@sun.com; Thu,
 15 May 2008 21:25:18 +0000 (Z)
Received: from relay44i.sun.com (relay44i.sun.com [192.5.209.118])
 by mms49es.sun.com with ESMTP id BT-MMP-191324 for psarc-ext@sun.com; Thu,
 15 May 2008 21:25:18 +0000 (Z)
Received: from py-out-1112.google.com ([64.233.166.181] [64.233.166.181])
 by relay4i.sun.com with ESMTP id BT-MMP-4383862 for psarc-ext@sun.com; Thu,
 15 May 2008 21:25:18 +0000 (Z)
Received: by py-out-1112.google.com with SMTP id x79so564764pyg.5 for
 <psarc-ext@sun.com>; Thu, 15 May 2008 14:24:29 -0700 (PDT)
Received: by 10.115.22.14 with SMTP id z14mr2974179wai.138.1210886668900; Thu,
 15 May 2008 14:24:28 -0700 (PDT)
Received: by 10.114.150.11 with HTTP; Thu, 15 May 2008 14:24:28 -0700 (PDT)
Date: Thu, 15 May 2008 14:24:28 -0700
From: John Sonnenschein <johnsonnenschein@gmail.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482CA2DD.6040508@sun.com>
To: Joseph Kowalski <jek3@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, John.Plocher@sun.com, psarc-ext@sun.com,
        gww@sac.sfbay.sun.com, James.Hughes@sun.com
Message-id: <241540330805151424re473151p3969409106afb797@mail.gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
Content-disposition: inline
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma;
 h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references;
 bh=407hPHO/vzitqZxN+FitFKnWMTkDjmUNIH36JfSi88U=;
 b=vM4ITiFUyQJa2I97dBFUy5AGjaTHFiVN5BLaJPc6dXJmEzuAAIZNw1NT4kZ4FBkexBFV/VlESuU/whggPMqvEak+n+ZAhA7G3I7WFSK3H3R2YD+EzXJR3Ax3p6iQkXOZ05VYHqpRCcsfFJizykKdMc6xKUsGCiJjyw+DsumzGDQ=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references;
 b=gip/KcJYAjcchklAggtZQcRoJsIyA8IrjmGR3QdVUDbEMhD9KjFTPKDLMEAdsIl5m7i122kyp2wT12k9+ZTVGgGLCATGUP0UD16m9dnycE8NoGVmL+QMXx52KerRtdheLrTpFRHVYnaIv4x48DU9gkz9CevVwLICFA6VE77YpHc=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=0.0/5.0, scanned in 0.045sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805151929.m4FJTgxl022564@marduk.eng.sun.com>
 <482CA2DD.6040508@sun.com>
Content-Length: 279
Status: RO
X-Status: $$$$
X-UID: 0000000038

On Thu, May 15, 2008 at 1:53 PM, Joseph Kowalski <jek3@sun.com> wrote:

> Since we now have clarification of the Major release issue

We do? Anywhere outside the firewall so those of us in the cheap seats
can see it?

-- 
PGP Public Key 0x437AF1A1
Available on hkp://pgp.mit.edu

From jek3@sun.com Thu May 15 15:30:49 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4FMUnk4029112
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 May 2008 15:30:49 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4FMUmmd022447;
	Thu, 15 May 2008 15:30:49 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0X00I1EL7C7S00@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 16:30:48 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0X00BSEL7ALH50@brm-avmta-1.central.sun.com>; Thu,
 15 May 2008 16:30:47 -0600 (MDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4FMUjGJ155718; Thu, 15 May 2008 15:30:45 -0700 (PDT)
Date: Thu, 15 May 2008 12:32:23 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <241540330805151424re473151p3969409106afb797@mail.gmail.com>
To: John Sonnenschein <johnsonnenschein@gmail.com>
Cc: Gary Winiger <gww@eng.sun.com>, John.Plocher@sun.com, psarc-ext@sun.com,
        gww@sac.sfbay.sun.com, James.Hughes@sun.com
Message-id: <482CB9F7.8070802@sun.com>
MIME-version: 1.0
Content-type: multipart/alternative;
 boundary="Boundary_(ID_R/8Ae7x1/XxMoOVC4P8p8w)"
X-PMX-Version: 5.4.1.325704
References: <200805151929.m4FJTgxl022564@marduk.eng.sun.com>
 <482CA2DD.6040508@sun.com>
 <241540330805151424re473151p3969409106afb797@mail.gmail.com>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 3472
Status: RO
X-Status: $$$$
X-UID: 0000000039

This is a multi-part message in MIME format.

--Boundary_(ID_R/8Ae7x1/XxMoOVC4P8p8w)
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT

John Sonnenschein wrote:
> On Thu, May 15, 2008 at 1:53 PM, Joseph Kowalski <jek3@sun.com> wrote:
>
>   
>> Since we now have clarification of the Major release issue
>>     
>
> We do? Anywhere outside the firewall so those of us in the cheap seats
> can see it?
>   

You've probably read the discussions about this on OpenSolaris.org.  
These discussion have just filtered down to PSARC (or more exactly, 
PSARC members).  It may be surprising, but yea, we really do talk to 
each other.

The proposals on opensolaris.org  (which are just that) would center 
around "linux familiarity".   I don't know of any others which don't 
center on this - certainly no serious proposals which don't protect the ABI.

Other than that, your seats are as good as mine.  The inclusion above is 
just my pithy, one-liner (opps; ETOPITHY).  Don't read too much into 
this.  A less pithy wording (still mine) would be:

    *If there should* be a Major release, incompatible change would be 
restricted to "linux familiarity".

This particular case doesn't fit that restriction (IMHO), so we 
shouldn't be even discussing this, hence derail.

Also, remember that "derail" only means "not appropriate for e-mail 
(fast-track) discussion.

Clear(er)?

- jek3






--Boundary_(ID_R/8Ae7x1/XxMoOVC4P8p8w)
Content-type: text/html; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
John Sonnenschein wrote:
<blockquote
 cite="mid:241540330805151424re473151p3969409106afb797@mail.gmail.com"
 type="cite">
  <pre wrap="">On Thu, May 15, 2008 at 1:53 PM, Joseph Kowalski <a class="moz-txt-link-rfc2396E" href="mailto:jek3@sun.com">&lt;jek3@sun.com&gt;</a> wrote:

  </pre>
  <blockquote type="cite">
    <pre wrap="">Since we now have clarification of the Major release issue
    </pre>
  </blockquote>
  <pre wrap=""><!---->
We do? Anywhere outside the firewall so those of us in the cheap seats
can see it?
  </pre>
</blockquote>
<br>
You've probably read the discussions about this on OpenSolaris.org.&nbsp;
These discussion have just filtered down to PSARC (or more exactly,
PSARC members).&nbsp; It may be surprising, but yea, we really do talk to
each other.<br>
<br>
The proposals on opensolaris.org&nbsp; (which are just that) would center
around "linux familiarity".&nbsp;&nbsp; I don't know of any others which don't
center on this - certainly no serious proposals which don't protect the
ABI.<br>
<br>
Other than that, your seats are as good as mine.&nbsp; The inclusion above
is just my pithy, one-liner (opps; ETOPITHY).&nbsp; Don't read too much into
this.&nbsp; A less pithy wording (still mine) would be:<br>
<br>
&nbsp;&nbsp;&nbsp; <b><big>If there should</big></b> be a Major release, incompatible
change would be restricted to "linux familiarity".<br>
<br>
This particular case doesn't fit that restriction (IMHO), so we
shouldn't be even discussing this, hence derail.<br>
<br>
Also, remember that "derail" only means "not appropriate for e-mail
(fast-track) discussion.<br>
<br>
Clear(er)?<br>
<br>
- jek3<br>
<br>
<br>
<br>
<br>
<br>
</body>
</html>

--Boundary_(ID_R/8Ae7x1/XxMoOVC4P8p8w)--

From Darren.Moffat@sun.com Fri May 16 03:10:43 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4GAAgtD019978
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 16 May 2008 03:10:43 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4GAAaF0020457
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Fri, 16 May 2008 11:10:41 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0Y00C2FHLQ5O00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Fri, 16 May 2008 03:10:38 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0Y001KGHLM6190@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 16 May 2008 03:10:35 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4GAAYaE012690	for
 <psarc-ext@sun.com>; Fri, 16 May 2008 10:10:34 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0Y00L01H5PKB00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 16 May 2008 11:10:34 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K0Y00B6WHLHA810@fe-emea-10.sun.com>; Fri,
 16 May 2008 11:10:30 +0100 (BST)
Date: Fri, 16 May 2008 11:10:29 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482C97C8.8000707@Sun.Com>
Sender: Darren.Moffat@sun.com
To: John Plocher <John.Plocher@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        James.Hughes@sun.com
Message-id: <482D5D95.9010603@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482C87A0.5040504@Sun.Com> <20080515191529.GT26388@Sun.COM>
 <482C97C8.8000707@Sun.Com>
User-Agent: Thunderbird 2.0.0.12 (X11/20080326)
Content-Length: 1210
Status: RO
X-Status: $$$$
X-UID: 0000000040

John Plocher wrote:
> Nicolas Williams wrote:
>> You did misunderstand RBAC.
>> In RBAC land pfexec is the equivalent of sudo.
> 
>  From Jim's mail, there seems to be an additional
> 
>    except for role-aware applications, for which you are
>    always [an audited] god.
> 
> My fear is ending up in a world where more and more things
> are role-aware and we set up the user environment [for the
> first defined user?] such that they are forced to be a full
> time demigod, rather than having to duck into a phone booth
> first.

Your issue then is with the whole concept of how security in Solaris is 
done and with things like SMF.  Not this case so please lets not discuss 
it here.  This case doesn't actually change anything in that area anyway.

The 'pfexec svcadm' vs 'svcadm' case has nothing to do with RBAC roles 
and everything to do with how SMF uses RBAC Authorisations.  This is 
fundamental to how SMF works and is how it provides fine grained control 
over who can do what to service status and configuration.   There is no 
meaning full use of svcadm/svcfg if you don't have an authorisation to 
do the operation. on a service so there is no need to "prefix" it first.

-- 
Darren J Moffat

From Joerg.Schilling@fokus.fraunhofer.de Fri May 16 03:35:26 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4GAZQE4020604
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 16 May 2008 03:35:26 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4GAZPtF020446;
	Fri, 16 May 2008 04:35:25 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0Y00D0PIR1GP00@nwk-avmta-2.sfbay.sun.com>; Fri,
 16 May 2008 03:35:25 -0700 (PDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0Y0014YIQZ6LB0@nwk-avmta-2.sfbay.sun.com>; Fri,
 16 May 2008 03:35:24 -0700 (PDT)
Received: from relay21.sun.com
 (relay21.sun.com [192.12.251.24] (may be forged))	by sca-ea-mail-2.sun.com
 (8.13.7+Sun/8.12.9) with ESMTP id m4GAUwLU009783; Fri,
 16 May 2008 10:35:23 +0000 (GMT)
Received: from mms23es.sun.com ([150.143.232.54] [150.143.232.54])
 by relay21i.sun.com with ESMTP id BT-MMP-244591; Fri,
 16 May 2008 10:35:19 +0000 (Z)
Received: from relay23.sun.com (relay23.sun.com [192.12.251.54])
 by mms23es.sun.com with ESMTP id BT-MMP-1478269; Fri,
 16 May 2008 10:35:16 +0000 (Z)
Received: from mailgwb1.fraunhofer.de ([153.96.87.18] [153.96.87.18])
 by relay23i.sun.com with ESMTP id BT-MMP-8772808; Fri,
 16 May 2008 10:35:16 +0000 (Z)
Received: from mailgwb1.fraunhofer.de (localhost [127.0.0.1])
	by mailgwb1.fraunhofer.de[host mailgwb1] (8.14.2+/8.14.2)
 with ESMTP id m4GAQ4AB029349; Fri, 16 May 2008 12:26:04 +0200 (CEST)
Received: from pluto.fokus.fraunhofer.de
 (pluto.fokus.fraunhofer.de [195.37.77.164])	by mailgwb1.fraunhofer.de
 (8.14.2+/8.14.2) with ESMTP id m4GAQ3Pn029338
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Fri,
 16 May 2008 12:26:04 +0200 (CEST)
Received: from EXCHSRV.fokus.fraunhofer.de (bohr [10.147.9.231])
	by pluto.fokus.fraunhofer.de (8.13.7/8.13.7) with SMTP id m4GAQ3vZ015848; Fri,
 16 May 2008 12:26:03 +0200 (MEST)
Received: from rigel ([10.147.65.195]) by EXCHSRV.fokus.fraunhofer.de with
 Microsoft SMTPSVC(6.0.3790.3959); Fri, 16 May 2008 12:26:03 +0200
Date: Fri, 16 May 2008 12:26:03 +0200
From: Joerg.Schilling@fokus.fraunhofer.de (Joerg Schilling)
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482C87A0.5040504@Sun.Com>
To: John.Plocher@sun.com, gww@sac.sfbay.sun.com
Cc: psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <482d613b.bQ2RCW8gFBxQv2tK%Joerg.Schilling@fokus.fraunhofer.de>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Fraunhofer-Email-Policy: accepted
X-Antispam: No, score=0.0/5.0, scanned in 0.391sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482C87A0.5040504@Sun.Com>
User-Agent: nail 11.22 3/20/05
X-OriginalArrivalTime: 16 May 2008 10:26:03.0625 (UTC)
 FILETIME=[3E4F0D90:01C8B73F]
Content-Length: 1647
Status: RO
X-Status: $$$$
X-UID: 0000000041

John Plocher <John.Plocher@sun.com> wrote:

> Just as someone invented sheaths for knives, because people
> don't always need to walk around armed to the teeth, the
> "sudo world" doesn't require everyone to walk around with
> a loaded "rm *" command :-)
>
> This proposal, if applied to my home system, would seem to
> effectively make logging in as "plocher" be the same as
> logging in as "root" - and is something I'm not sure I want.
>
> What I do want is to be able, as "plocher", to say "I want
> to explicitly do `foo` now, but not necessarily at any other
> time without additional future confirmation being required".

I believe that the change needs to be well tested for a while to make sure 
that it does not miss hard to find problems.

If you e.g. (after the change) are expected to call "pfexec rm -rf /*", then
I see the problem that people who use a pf* shell would always work with
user user privilleges.

If there is a need to first aquire a role, things look different.

BTW: It was a good practice 20+ years ago already to disallow root logins
except for /dev/console. This changed after ssh came up. It may be a good idea 
to implement something similar now (allowing root logins on /dev/console on 
specific conditions) to make sure that there is no need to fetch an alternate 
boot medium in order to fix certain problems.

Jörg

-- 
 EMail:joerg@schily.isdn.cs.tu-berlin.de (home) Jörg Schilling D-13353 Berlin
       js@cs.tu-berlin.de                (uni)  
       schilling@fokus.fraunhofer.de     (work) Blog: http://schily.blogspot.com/
 URL:  http://cdrecord.berlios.de/old/private/ ftp://ftp.berlios.de/pub/schily

From Darren.Moffat@sun.com Fri May 16 03:48:47 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4GAmlDj020645
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 16 May 2008 03:48:47 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4GAmlEu024521
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Fri, 16 May 2008 04:48:47 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0Y00E03JDB1M00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Fri, 16 May 2008 03:48:47 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0Y0018VJD562B0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 16 May 2008 03:48:46 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4GAmfJe014811	for
 <psarc-ext@sun.com>; Fri, 16 May 2008 10:48:41 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0Y00K01JAO8C00@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 16 May 2008 11:48:40 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K0Y006DYJCPSY10@fe-emea-09.sun.com>; Fri,
 16 May 2008 11:48:26 +0100 (BST)
Date: Fri, 16 May 2008 11:48:25 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482d613b.bQ2RCW8gFBxQv2tK%Joerg.Schilling@fokus.fraunhofer.de>
Sender: Darren.Moffat@sun.com
To: Joerg Schilling <Joerg.Schilling@fokus.fraunhofer.de>
Cc: John.Plocher@sun.com, gww@sac.sfbay.sun.com, psarc-ext@sun.com,
        James.Hughes@sun.com
Message-id: <482D6679.20106@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482C87A0.5040504@Sun.Com>
 <482d613b.bQ2RCW8gFBxQv2tK%Joerg.Schilling@fokus.fraunhofer.de>
User-Agent: Thunderbird 2.0.0.12 (X11/20080326)
Content-Length: 2225
Status: RO
X-Status: $$$$
X-UID: 0000000042

Joerg Schilling wrote:
> John Plocher <John.Plocher@sun.com> wrote:
> 
>> Just as someone invented sheaths for knives, because people
>> don't always need to walk around armed to the teeth, the
>> "sudo world" doesn't require everyone to walk around with
>> a loaded "rm *" command :-)
>>
>> This proposal, if applied to my home system, would seem to
>> effectively make logging in as "plocher" be the same as
>> logging in as "root" - and is something I'm not sure I want.
>>
>> What I do want is to be able, as "plocher", to say "I want
>> to explicitly do `foo` now, but not necessarily at any other
>> time without additional future confirmation being required".
> 
> I believe that the change needs to be well tested for a while to make sure 
> that it does not miss hard to find problems.

What change ?

> If you e.g. (after the change) are expected to call "pfexec rm -rf /*", then
> I see the problem that people who use a pf* shell would always work with
> user user privilleges.


> If there is a need to first aquire a role, things look different.


I don't see how any of the above is relevant to what *this* case is 
proposing.  This case says NOTHING about pfexec or profile shells.  This 
case is about a change to /sbin/sulogin so that instead of always 
requireing the root password it will ask for a username/passwd and that 
the user has to have the solaris.system.maintenance authorisation. 
/sbin/sulogin will still start a uid=0 privs=all shell.

> BTW: It was a good practice 20+ years ago already to disallow root logins
> except for /dev/console. This changed after ssh came up. It may be a good idea 

Not on Solaris it didn't we have ALWAYS shipped our sshd configuration 
such that root can not login remotely by default.  This is different to 
the OpenSSH default.

> to implement something similar now (allowing root logins on /dev/console on 
> specific conditions) to make sure that there is no need to fetch an alternate 
> boot medium in order to fix certain problems.

I don't see how that is relevant to this case.

This case does NOT make root a role by default.
This case does NOT stop root from authenticting on /dev/console either 
during sulogin or /bin/login.


-- 
Darren J Moffat

From Darren.Reed@sun.com Fri May 16 18:33:15 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4H1XE7K015786
	for <psarc-ext@sac.sfbay.Sun.COM>; Fri, 16 May 2008 18:33:14 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4H1X8ad006541
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Sat, 17 May 2008 09:33:13 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0Z00401OBBNM00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@Sun.COM); Fri, 16 May 2008 18:33:11 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0Z00ACUOBARED0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@Sun.COM); Fri,
 16 May 2008 18:33:11 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m4H1XrQf023607	for
 <psarc-ext@Sun.COM>; Sat, 17 May 2008 01:33:53 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K0Z00601NT01B00@mail-apac.sun.com>
 (original mail from Darren.Reed@Sun.COM)
 for psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Sat,
 17 May 2008 09:31:57 +0800 (SGT)
Received: from [129.146.106.55] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K0Z009QVO978G9T@mail-apac.sun.com>; Sat,
 17 May 2008 09:31:56 +0800 (SGT)
Date: Fri, 16 May 2008 18:33:07 -0700
From: Darren Reed <Darren.Reed@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
Sender: Darren.Reed@sun.com
To: james hughes <James.Hughes@sun.com>
Cc: Bart Smaalders <Bart.Smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com
Message-id: <482E35D3.7060901@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-Accept-Language: en-au, en
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.7) Gecko/20060120
Content-Length: 2098
Status: RO
X-Status: $$$$
X-UID: 0000000043

james hughes wrote:

>
> On May 13, 2008, at 4:50 PM, Bart Smaalders wrote:
>
>>
>> How do I log into and configure a blank system image?  Is a default
>> account created that has this privilege, or does the lack of such
>> an account mean that the system must be repaired by booting
>> from alternate media?
>
>
> Loosing or breaking the administrator's account is identical to  
> loosing root password.
>
>> How will we insure that there are real administrative users present
>> in the password file?
>
>
> The real administrative users present in the password file because 
> the  initial installation put it there.
>
> This is not about the elimination of root as a much as it is the  
> ability to create a machine that has a no root password. Previous  
> methods of having root have a password are still possible.


Are you not creating a root account or are you creating a root account
but not using the root username?

If you're creating a system administration account, but simply under
another name, then there is no security benefit from this change -
except that someone now has to "guess" the administration account
name if they don't know it already...

...and this is where Windows is at today: it's come from having
"administrator" as the default "root" account to creating a user
account at install (using your name) that has full privilege,
meaning malware likely has the required privilege it needs when
opened via Outlook, even though the user who is logged in is
not called "administrator", they still have "administrator" power.
Net result: you have to guess an account name to try and login
to the system with before going further.

If there is no followup to this case to make the prescribed
changes to root then I'd like the following questions to be
answered as part of this case (if it hasn't been derailed yet):

What are the security threats that this change is intended
to provide protection from?

How does this change mitigate the security threats that
it is intending to provide protection from?

What are the security risks that this change introduces?

Darren


From gdamore@sun.com Fri May 16 18:40:03 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4H1e29F016049
	for <psarc-ext@sac.sfbay.Sun.COM>; Fri, 16 May 2008 18:40:02 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4H1dxRM008662
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Sat, 17 May 2008 09:40:01 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0Z00401OMOZE00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Fri, 16 May 2008 18:40:00 -0700 (PDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0Z00AMHOMNRED0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 16 May 2008 18:39:59 -0700 (PDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4H1dxW7028828	for
 <psarc-ext@sun.com>; Fri, 16 May 2008 18:39:59 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0Z00601OHTZ400@fe-sfbay-10.sun.com> (original mail from gdamore@sun.com)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 16 May 2008 18:39:59 -0700 (PDT)
Received: from [192.168.251.106] ([76.174.83.55])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K0Z00EQ1OMMJFE0@fe-sfbay-10.sun.com>; Fri,
 16 May 2008 18:39:59 -0700 (PDT)
Date: Fri, 16 May 2008 18:33:39 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482E35D3.7060901@Sun.COM>
Sender: Garrett.Damore@sun.com
To: Darren Reed <Darren.Reed@sun.com>
Cc: james hughes <James.Hughes@sun.com>,
        Bart Smaalders <Bart.Smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com
Message-id: <482E35F3.3040800@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482E35D3.7060901@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071023)
Content-Length: 2828
Status: RO
X-Status: $$$$
X-UID: 0000000044

Can we stop arguing about this at this point?  I think Joe asked for the 
case to be modified to remove the contentious language.  Either it will, 
and all this argument is moot, or it won't, and the case will be derailed.

If the former, then having this discussion now is a waste of time.

If the latter, then having this discussion right now is probably still a 
waste of time, because at that point the project team is probably going 
to need to prepare more complete case materials.

Submitter, I haven't noticed, has the spec for this case been updated as 
Joe requested?   Or are you declining to do so?

    -- Garrett

Darren Reed wrote:
> james hughes wrote:
>
>>
>> On May 13, 2008, at 4:50 PM, Bart Smaalders wrote:
>>
>>>
>>> How do I log into and configure a blank system image?  Is a default
>>> account created that has this privilege, or does the lack of such
>>> an account mean that the system must be repaired by booting
>>> from alternate media?
>>
>>
>> Loosing or breaking the administrator's account is identical to  
>> loosing root password.
>>
>>> How will we insure that there are real administrative users present
>>> in the password file?
>>
>>
>> The real administrative users present in the password file because 
>> the  initial installation put it there.
>>
>> This is not about the elimination of root as a much as it is the  
>> ability to create a machine that has a no root password. Previous  
>> methods of having root have a password are still possible.
>
>
> Are you not creating a root account or are you creating a root account
> but not using the root username?
>
> If you're creating a system administration account, but simply under
> another name, then there is no security benefit from this change -
> except that someone now has to "guess" the administration account
> name if they don't know it already...
>
> ...and this is where Windows is at today: it's come from having
> "administrator" as the default "root" account to creating a user
> account at install (using your name) that has full privilege,
> meaning malware likely has the required privilege it needs when
> opened via Outlook, even though the user who is logged in is
> not called "administrator", they still have "administrator" power.
> Net result: you have to guess an account name to try and login
> to the system with before going further.
>
> If there is no followup to this case to make the prescribed
> changes to root then I'd like the following questions to be
> answered as part of this case (if it hasn't been derailed yet):
>
> What are the security threats that this change is intended
> to provide protection from?
>
> How does this change mitigate the security threats that
> it is intending to provide protection from?
>
> What are the security risks that this change introduces?
>
> Darren
>


From jek3@sun.com Fri May 16 22:28:01 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4H5S0rx027779
	for <psarc-ext@sac.sfbay.Sun.COM>; Fri, 16 May 2008 22:28:00 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4H5Rd11007852;
	Sat, 17 May 2008 13:27:56 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0Z00101Z6ITR00@brm-avmta-1.central.sun.com>; Fri,
 16 May 2008 23:27:54 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0Z00MPUZ6HJQA0@brm-avmta-1.central.sun.com>; Fri,
 16 May 2008 23:27:53 -0600 (MDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4H5Rql8333096; Fri, 16 May 2008 22:27:52 -0700 (PDT)
Date: Fri, 16 May 2008 19:29:34 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482E35F3.3040800@sun.com>
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Darren Reed <Darren.Reed@sun.com>, james hughes <James.Hughes@sun.com>,
        Bart Smaalders <Bart.Smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com
Message-id: <482E6D3E.60707@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482E35D3.7060901@Sun.COM> <482E35F3.3040800@sun.com>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 3282
Status: RO
X-Status: $$$$
X-UID: 0000000045


Uh right, but should the language talking about a potential major 
release binding be removed, then I think the following discussion still 
becomes relevant.

Then again, maybe we should just derail this in general, just because 
this seems to have become rather "non-obvious"?
(That's a question, not a statement.)

GO LAKERS!

- jek3



Garrett D'Amore wrote:
> Can we stop arguing about this at this point?  I think Joe asked for 
> the case to be modified to remove the contentious language.  Either it 
> will, and all this argument is moot, or it won't, and the case will be 
> derailed.
>
> If the former, then having this discussion now is a waste of time.
>
> If the latter, then having this discussion right now is probably still 
> a waste of time, because at that point the project team is probably 
> going to need to prepare more complete case materials.
>
> Submitter, I haven't noticed, has the spec for this case been updated 
> as Joe requested?   Or are you declining to do so?
>
>    -- Garrett
>
> Darren Reed wrote:
>> james hughes wrote:
>>
>>>
>>> On May 13, 2008, at 4:50 PM, Bart Smaalders wrote:
>>>
>>>>
>>>> How do I log into and configure a blank system image?  Is a default
>>>> account created that has this privilege, or does the lack of such
>>>> an account mean that the system must be repaired by booting
>>>> from alternate media?
>>>
>>>
>>> Loosing or breaking the administrator's account is identical to  
>>> loosing root password.
>>>
>>>> How will we insure that there are real administrative users present
>>>> in the password file?
>>>
>>>
>>> The real administrative users present in the password file because 
>>> the  initial installation put it there.
>>>
>>> This is not about the elimination of root as a much as it is the  
>>> ability to create a machine that has a no root password. Previous  
>>> methods of having root have a password are still possible.
>>
>>
>> Are you not creating a root account or are you creating a root account
>> but not using the root username?
>>
>> If you're creating a system administration account, but simply under
>> another name, then there is no security benefit from this change -
>> except that someone now has to "guess" the administration account
>> name if they don't know it already...
>>
>> ...and this is where Windows is at today: it's come from having
>> "administrator" as the default "root" account to creating a user
>> account at install (using your name) that has full privilege,
>> meaning malware likely has the required privilege it needs when
>> opened via Outlook, even though the user who is logged in is
>> not called "administrator", they still have "administrator" power.
>> Net result: you have to guess an account name to try and login
>> to the system with before going further.
>>
>> If there is no followup to this case to make the prescribed
>> changes to root then I'd like the following questions to be
>> answered as part of this case (if it hasn't been derailed yet):
>>
>> What are the security threats that this change is intended
>> to provide protection from?
>>
>> How does this change mitigate the security threats that
>> it is intending to provide protection from?
>>
>> What are the security risks that this change introduces?
>>
>> Darren
>>
>
>


From gdamore@sun.com Fri May 16 22:37:16 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4H5bFwt028114
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 16 May 2008 22:37:15 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4H5bAqE014836
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Sat, 17 May 2008 06:37:14 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K0Z00207ZLZKG00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Fri, 16 May 2008 23:37:11 -0600 (MDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K0Z00M3OZLYKCA0@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 16 May 2008 23:37:10 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4H5bAtD009885	for
 <psarc-ext@sun.com>; Fri, 16 May 2008 22:37:10 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K0Z00001ZFKTC00@fe-sfbay-09.sun.com> (original mail from gdamore@sun.com)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 16 May 2008 22:37:10 -0700 (PDT)
Received: from [192.168.251.106] ([76.174.83.55])
 by fe-sfbay-09.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K0Z00C6AZLX5240@fe-sfbay-09.sun.com>; Fri,
 16 May 2008 22:37:10 -0700 (PDT)
Date: Fri, 16 May 2008 22:30:48 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <482E6D3E.60707@sun.com>
Sender: Garrett.Damore@sun.com
To: Joseph Kowalski <jek3@sun.com>
Cc: Darren Reed <Darren.Reed@sun.com>, james hughes <James.Hughes@sun.com>,
        Bart Smaalders <Bart.Smaalders@sun.com>,
        Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com
Message-id: <482E6D88.3000608@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <482A2944.2030305@Sun.COM> <98F95B2B-92ED-4FE8-A96D-8F6ADC2CF12F@Sun.COM>
 <482E35D3.7060901@Sun.COM> <482E35F3.3040800@sun.com> <482E6D3E.60707@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071023)
Content-Length: 4244
Status: RO
X-Status: $$$$
X-UID: 0000000046

Joseph Kowalski wrote:
>
> Uh right, but should the language talking about a potential major 
> release binding be removed, then I think the following discussion 
> still becomes relevant.
>
> Then again, maybe we should just derail this in general, just because 
> this seems to have become rather "non-obvious"?
> (That's a question, not a statement.)

The original case, with the controversial language removed, seemed 
relatively obvious to me.  (I.e. allow a non-root user/password pair to 
be used by sulogin.)

There are lot of administrative consequences of that (the credentials 
need to be accessible for sulogin, and if you're doing this, are you 
also doing other things to restrict access to the root account, etc.) 
but I think they get into site administrative preferences, and aren't 
*particularly* germane to this case.

I'd like to see the original case able to go forward without being 
derailed (with the controversial language removed), because I think it 
is potentially very useful to sites that want to limit the need for 
shared root passwords, and I think derailing will just deepen the 
rat-hole down which this conversation seems to be headed.

    -- Garrett
>
> GO LAKERS!
>
> - jek3
>
>
>
> Garrett D'Amore wrote:
>> Can we stop arguing about this at this point?  I think Joe asked for 
>> the case to be modified to remove the contentious language.  Either 
>> it will, and all this argument is moot, or it won't, and the case 
>> will be derailed.
>>
>> If the former, then having this discussion now is a waste of time.
>>
>> If the latter, then having this discussion right now is probably 
>> still a waste of time, because at that point the project team is 
>> probably going to need to prepare more complete case materials.
>>
>> Submitter, I haven't noticed, has the spec for this case been updated 
>> as Joe requested?   Or are you declining to do so?
>>
>>    -- Garrett
>>
>> Darren Reed wrote:
>>> james hughes wrote:
>>>
>>>>
>>>> On May 13, 2008, at 4:50 PM, Bart Smaalders wrote:
>>>>
>>>>>
>>>>> How do I log into and configure a blank system image?  Is a default
>>>>> account created that has this privilege, or does the lack of such
>>>>> an account mean that the system must be repaired by booting
>>>>> from alternate media?
>>>>
>>>>
>>>> Loosing or breaking the administrator's account is identical to  
>>>> loosing root password.
>>>>
>>>>> How will we insure that there are real administrative users present
>>>>> in the password file?
>>>>
>>>>
>>>> The real administrative users present in the password file because 
>>>> the  initial installation put it there.
>>>>
>>>> This is not about the elimination of root as a much as it is the  
>>>> ability to create a machine that has a no root password. Previous  
>>>> methods of having root have a password are still possible.
>>>
>>>
>>> Are you not creating a root account or are you creating a root account
>>> but not using the root username?
>>>
>>> If you're creating a system administration account, but simply under
>>> another name, then there is no security benefit from this change -
>>> except that someone now has to "guess" the administration account
>>> name if they don't know it already...
>>>
>>> ...and this is where Windows is at today: it's come from having
>>> "administrator" as the default "root" account to creating a user
>>> account at install (using your name) that has full privilege,
>>> meaning malware likely has the required privilege it needs when
>>> opened via Outlook, even though the user who is logged in is
>>> not called "administrator", they still have "administrator" power.
>>> Net result: you have to guess an account name to try and login
>>> to the system with before going further.
>>>
>>> If there is no followup to this case to make the prescribed
>>> changes to root then I'd like the following questions to be
>>> answered as part of this case (if it hasn't been derailed yet):
>>>
>>> What are the security threats that this change is intended
>>> to provide protection from?
>>>
>>> How does this change mitigate the security threats that
>>> it is intending to provide protection from?
>>>
>>> What are the security risks that this change introduces?
>>>
>>> Darren
>>>
>>
>>
>


From scott.rotondo@sun.com Mon May 19 11:50:28 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4JIoSTg021080
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 19 May 2008 11:50:28 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4JIoGQp011420;
	Mon, 19 May 2008 12:50:27 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K140095RPO2SN00@brm-avmta-1.central.sun.com>; Mon,
 19 May 2008 12:50:26 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K14008K4PO16610@brm-avmta-1.central.sun.com>; Mon,
 19 May 2008 12:50:26 -0600 (MDT)
Received: from [129.146.108.62] (vinifera.SFBay.Sun.COM [129.146.108.62])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4JIoP3K504273; Mon, 19 May 2008 11:50:25 -0700 (PDT)
Date: Mon, 19 May 2008 11:50:25 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805151929.m4FJTgxl022564@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>, James.Hughes@sun.com
Cc: psarc-ext@sun.com
Message-id: <4831CBF1.2050708@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805151929.m4FJTgxl022564@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.12 (X11/20080422)
Content-Length: 1294
Status: RO
X-Status: $$$$
X-UID: 0000000047

Gary Winiger wrote:
> The discussion seems to have wandered off from what the case 
> proposes. Many comments are interesting, don't appear to be this 
> case, and could be interesting other cases for some other project 
> team to pursue.
> 
> The project proposed by this case is to 1) maintain compatibility 
> with existing Solaris Roles, Rights Profiles and related mechanisms. 
> 2) permit an administrator to configure root to be a no login (passwd
> -N) account should they wish to do so.  A side effect, even without
> making root a no login account, is the ability to grant users the
> ability to boot single without the need to share the root password.

Earlier in this thread, I suggested the following change to this part of
the proposal. For single-user login, you don't really need a new 
authorization. Instead, sulogin could allow single-user access if the 
user authenticates and is allowed to assume the root role. The ability 
to assume the root role conveys the same information you would with the 
solaris.system.maintenance authorization, and it doesn't require the 
administrator to take two separate actions to configure a user with root 
access.

I don't believe the project team has responded, either to accept or 
reject this minor amendment to the proposal.

	Scott

From scott.rotondo@sun.com Mon May 19 11:58:16 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4JIwFGr021503
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 19 May 2008 11:58:16 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4JIvxn3026956;
	Mon, 19 May 2008 19:58:13 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1400A01Q10GK00@brm-avmta-1.central.sun.com>; Mon,
 19 May 2008 12:58:12 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K140083SQ105Q20@brm-avmta-1.central.sun.com>; Mon,
 19 May 2008 12:58:12 -0600 (MDT)
Received: from [129.146.108.62] (vinifera.SFBay.Sun.COM [129.146.108.62])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4JIwB5T505613; Mon, 19 May 2008 11:58:11 -0700 (PDT)
Date: Mon, 19 May 2008 11:58:11 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <5126C601-49CF-4539-BA04-9B68317EE723@elemental.org>
To: Dale Ghent <daleg@elemental.org>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        james.hughes@sun.com
Message-id: <4831CDC3.7080400@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <5126C601-49CF-4539-BA04-9B68317EE723@elemental.org>
User-Agent: Thunderbird 2.0.0.12 (X11/20080422)
Content-Length: 1505
Status: RO
X-Status: $$$$
X-UID: 0000000048

Dale Ghent wrote:
> On May 13, 2008, at 6:00 PM, Gary Winiger wrote:
> 
>> Proposal:
>> ========
>> Add a "solaris.system.maintenance" authorization.  Modify sulogin(1M) to
>> prompt for a username and password.  If the username entered is
>> authenticated by the password and has the "solaris.system.maintenance"
>> authorization, enter system maintenance mode.  If not, as before this
>> project, deny access.
> 
> I haven't been able to follow every message in this busy thread, but 
> please fill me on regarding one question I have:
> 
> At many sites, 'root' is the only local, non-locked account and all 
> other users (aside from the standard system accounts such as 
> daemon..nobody) are in NIS, LDAP, or the like and are auth'd via Kerberos.
> 
> Given that environment, what would happen in a situation where a box 
> under this proposed scheme were to boot into single-user, with network 
> access unavailable?

I'm not answering on behalf of the project team, but I believe this 
interpretation will be non-controversial.

Only local, unlocked accounts can be used to log in if name services are 
unavailable. If root is one of those accounts, it would continue to work 
as before.

Under this proposal, another local, unlocked account could be used for 
single-user login if

* it has the solaris.system.maintenance authorization [under the project 
team's original proposal], or

* it is authorized to assume the root role [under my suggested amendment 
to the original proposal].

	Scott

From Nicolas.Williams@sun.com Mon May 19 12:10:48 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4JJAm3R021766
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 19 May 2008 12:10:48 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4JJAlld028113;
	Mon, 19 May 2008 12:10:47 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1400E03QLYGW00@nwk-avmta-2.sfbay.sun.com>; Mon,
 19 May 2008 12:10:46 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K14009MKQLYO7A0@nwk-avmta-2.sfbay.sun.com>; Mon,
 19 May 2008 12:10:46 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m4JJAj70001929;
 Mon, 19 May 2008 14:10:45 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m4JJAjGa001928; Mon,
 19 May 2008 14:10:45 -0500 (CDT)
Date: Mon, 19 May 2008 14:10:45 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <4831CDC3.7080400@sun.com>
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: Dale Ghent <daleg@elemental.org>, Gary Winiger <gww@sac.sfbay.sun.com>,
        psarc-ext@sun.com, James.Hughes@sun.com
Mail-followup-to: Scott Rotondo <Scott.Rotondo@Sun.COM>,
 Dale Ghent <daleg@elemental.org>, Gary Winiger <gww@sac.sfbay.sun.com>,
 psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <20080519191044.GO26388@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805132200.m4DM0vIr008326@sac.sfbay.sun.com>
 <5126C601-49CF-4539-BA04-9B68317EE723@elemental.org> <4831CDC3.7080400@sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Content-Length: 1621
Status: RO
X-Status: $$$$
X-UID: 0000000049

On Mon, May 19, 2008 at 11:58:11AM -0700, Scott Rotondo wrote:
> Dale Ghent wrote:
> >I haven't been able to follow every message in this busy thread, but 
> >please fill me on regarding one question I have:
> >
> >At many sites, 'root' is the only local, non-locked account and all 
> >other users (aside from the standard system accounts such as 
> >daemon..nobody) are in NIS, LDAP, or the like and are auth'd via Kerberos.
> >
> >Given that environment, what would happen in a situation where a box 
> >under this proposed scheme were to boot into single-user, with network 
> >access unavailable?
> 
> I'm not answering on behalf of the project team, but I believe this 
> interpretation will be non-controversial.
> 
> Only local, unlocked accounts can be used to log in if name services are 
> unavailable. If root is one of those accounts, it would continue to work 
> as before.
> 
> Under this proposal, another local, unlocked account could be used for 
> single-user login if

Yes, but, why bother?

We can already say that root can only log in on console, but we can't do
that (unless this case adds a way to do it) for other local users.

What does the username of that one local user matter?  Either way, if
there's only one then its password will be shared, and auditing goes out
the window.

It's up to the customer to provide physical security.  It's up to the
customer to secure access to the console.  We provide a way to limit
root logins to console logins only.  All we need is a way to treat
'root' as a login on console and a non-shared-password role elsewhere.

Am I missing something?

Nico
-- 

From gww@sac.sfbay.sun.com Mon May 19 20:57:43 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4K3vhl2006369
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 19 May 2008 20:57:43 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4K3vgF1005911
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 19 May 2008 21:57:42 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1500307F06GZ00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 19 May 2008 20:57:42 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1500KDFF06WEC0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 19 May 2008 20:57:42 -0700 (PDT)
Received: from sac.sfbay.sun.com (new-sac.SFBay.Sun.COM [129.146.175.65])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m4K3vglh004390; Mon, 19 May 2008 20:57:42 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4K3vgjF006366; Mon,
 19 May 2008 20:57:42 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id m4K3vgQI006365; Mon, 19 May 2008 20:57:42 -0700 (PDT)
Date: Mon, 19 May 2008 20:57:42 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
To: James.Hughes@sun.com, gww@eng.sun.com, scott.rotondo@sun.com
Cc: psarc-ext@sun.com
Message-id: <200805200357.m4K3vgQI006365@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Content-Length: 1315
Status: RO
X-Status: $$$$
X-UID: 0000000050

> Earlier in this thread, I suggested the following change to this part of
> the proposal. For single-user login, you don't really need a new 
> authorization. Instead, sulogin could allow single-user access if the 
> user authenticates and is allowed to assume the root role. The ability 
> to assume the root role conveys the same information you would with the 
> solaris.system.maintenance authorization, and it doesn't require the 
> administrator to take two separate actions to configure a user with root 
> access.
> 
> I don't believe the project team has responded, either to accept or 
> reject this minor amendment to the proposal.

	Since you asked again and I believe the project team is traveling,
	I'll answer as part of the RBAC project team.  The suggestion
	would be mixing metaphores.  Authorizations are granted to user
	for programs to make access control decisions based on the user's
	identity.  Roles are user accounts and may or may not have
	authorizations.

	Additionally the premise of this case is that "root" not be a
	role and be able to be configured as a no login account.  As such,
	it wouldn't be granted.  Authorizations are a large name space,
	thus nothing is to be gained by not adding an authorization to the
	system and allowing it to be granted to specific users.

Gary..

From jek3@sun.com Mon May 19 21:23:08 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4K4N7er007371
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 19 May 2008 21:23:07 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4K4Mx3R006599;
	Tue, 20 May 2008 05:23:03 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1500H0BG6DS900@nwk-avmta-2.sfbay.sun.com>; Mon,
 19 May 2008 21:23:01 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K15004YRG6DLDC0@nwk-avmta-2.sfbay.sun.com>; Mon,
 19 May 2008 21:23:01 -0700 (PDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4K4N0L9574013; Mon, 19 May 2008 21:23:00 -0700 (PDT)
Date: Mon, 19 May 2008 18:24:48 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <200805200357.m4K3vgQI006365@sac.sfbay.sun.com>
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: James.Hughes@sun.com, gww@eng.sun.com, scott.rotondo@sun.com,
        psarc-ext@sun.com
Message-id: <48325290.4090706@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805200357.m4K3vgQI006365@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 346
Status: RO
X-Status: $$$$
X-UID: 0000000051


OK, I derail.

This should not be consider to be any thing negative by the project team 
(other than strange allusions to a potential Major release).  This has 
just become too complex (not obvious) and too many differing views have 
been expressed (not non-controversial).  It just ain't fast-track 
appropriate.

See you in Presidio.

- jek3


From jek3@sun.com Tue May 20 15:47:37 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4KMlb6E008217
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 20 May 2008 15:47:37 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4KMlU6q003177;
	Tue, 20 May 2008 23:47:33 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K160051NVB77A00@brm-avmta-1.central.sun.com>; Tue,
 20 May 2008 16:47:31 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1600H27VB6FY70@brm-avmta-1.central.sun.com>; Tue,
 20 May 2008 16:47:30 -0600 (MDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4KMlTxY705635; Tue, 20 May 2008 15:47:29 -0700 (PDT)
Date: Tue, 20 May 2008 12:49:19 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <48325290.4090706@sun.com>
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: James.Hughes@sun.com, gww@eng.sun.com, scott.rotondo@sun.com,
        psarc-ext@sun.com
Message-id: <4833556F.2030204@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805200357.m4K3vgQI006365@sac.sfbay.sun.com>
 <48325290.4090706@sun.com>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 1355
Status: RO
X-Status: $$$$
X-UID: 0000000052

Joseph Kowalski wrote:
>
> OK, I derail.
>
> This should not be consider to be any thing negative by the project 
> team (other than strange allusions to a potential Major release).  
> This has just become too complex (not obvious) and too many differing 
> views have been expressed (not non-controversial).  It just ain't 
> fast-track appropriate.
>
> See you in Presidio.
>
> - jek3


I spoke with Gary, the project team, a VP and other hanger-ons...  Here 
is the new, proposed process to get this case to close:

    The case is now in "waiting need spec" (not running, not derailed).

    The project team is going to spend a few days agreeing on some 
fairly minor points.

    When they are done, they will resubmit the specification and the 
case will then be running (not derailed) with a new time-out (business 
as usual).

    The expectation of the recrafted specification is that...

       1)   It will not specify anything about a potential "major release".

       2)   It will restate a few points which seem to have caused 
confusion and/or disagreement withing the project team.

       3)   It will probably (re)state a few points around what this 
case is *not* about, because the mail trail has gone off tangent a few 
times (who PSARC? Nah,... couldn't happen).

(Any corrections by the con-call attendees are welcome.)

- jek3


From gdamore@sun.com Tue May 20 16:21:28 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4KNLRdh010521
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 20 May 2008 16:21:27 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4KNLMMS015845
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 21 May 2008 00:21:26 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K160073LWVOWS00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 20 May 2008 17:21:24 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1600HJPWVKFY80@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 20 May 2008 17:21:21 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4KNLKJK004408	for
 <psarc-ext@sun.com>; Tue, 20 May 2008 16:21:20 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K1600901WTT5G00@fe-sfbay-10.sun.com> (original mail from gdamore@sun.com)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 20 May 2008 16:21:20 -0700 (PDT)
Received: from [192.168.251.106] ([76.174.83.55])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K1600K5SWVB0O50@fe-sfbay-10.sun.com>; Tue,
 20 May 2008 16:21:11 -0700 (PDT)
Date: Tue, 20 May 2008 16:14:34 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <4833556F.2030204@sun.com>
Sender: Garrett.Damore@sun.com
To: Joseph Kowalski <jek3@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, James.Hughes@sun.com,
        gww@eng.sun.com, Scott.Rotondo@sun.com, psarc-ext@sun.com
Message-id: <48335B5A.5040107@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805200357.m4K3vgQI006365@sac.sfbay.sun.com>
 <48325290.4090706@sun.com> <4833556F.2030204@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071023)
Content-Length: 2002
Status: RO
X-Status: $$$$
X-UID: 0000000053

Just a quick question/thought.  Given that the e-mail trail has gone off 
the weeds, wouldn't it be simpler to withdraw this case, and resubmit 
new materials under a different number (and with a fresh e-mail log?)  
I'm thinking of the situation when in the future, someone wants to back 
reference -- it seems kind of unfortunate that one has to go back 
through a bunch of stuff that is irrelevant.

(In other words, perhaps instead of "waiting need spec", we should be 
more willing to withdraw and resubmit under new materials and case number.)

    -- Garrett

Joseph Kowalski wrote:
> Joseph Kowalski wrote:
>>
>> OK, I derail.
>>
>> This should not be consider to be any thing negative by the project 
>> team (other than strange allusions to a potential Major release).  
>> This has just become too complex (not obvious) and too many differing 
>> views have been expressed (not non-controversial).  It just ain't 
>> fast-track appropriate.
>>
>> See you in Presidio.
>>
>> - jek3
>
>
> I spoke with Gary, the project team, a VP and other hanger-ons...  
> Here is the new, proposed process to get this case to close:
>
>    The case is now in "waiting need spec" (not running, not derailed).
>
>    The project team is going to spend a few days agreeing on some 
> fairly minor points.
>
>    When they are done, they will resubmit the specification and the 
> case will then be running (not derailed) with a new time-out (business 
> as usual).
>
>    The expectation of the recrafted specification is that...
>
>       1)   It will not specify anything about a potential "major 
> release".
>
>       2)   It will restate a few points which seem to have caused 
> confusion and/or disagreement withing the project team.
>
>       3)   It will probably (re)state a few points around what this 
> case is *not* about, because the mail trail has gone off tangent a few 
> times (who PSARC? Nah,... couldn't happen).
>
> (Any corrections by the con-call attendees are welcome.)
>
> - jek3
>


From carlsonj@phorcys.east.sun.com Tue May 20 16:30:29 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4KNUTBG011152
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 20 May 2008 16:30:29 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4KNUQTi022579;
	Tue, 20 May 2008 16:30:29 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1600807XARNQ00@brm-avmta-1.central.sun.com>; Tue,
 20 May 2008 17:30:27 -0600 (MDT)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1600H3JXARG080@brm-avmta-1.central.sun.com>; Tue,
 20 May 2008 17:30:27 -0600 (MDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.2+Sun/8.14.2) with ESMTP id m4KNUP2G004456; Tue,
 20 May 2008 19:30:25 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.2+Sun/8.14.2/Submit) id m4KNUPuB004453; Tue,
 20 May 2008 19:30:25 -0400 (EDT)
Date: Tue, 20 May 2008 19:30:25 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <48335B5A.5040107@sun.com>
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Joseph Kowalski <jek3@sun.com>, Gary Winiger <gww@sac.sfbay.sun.com>,
        James.Hughes@sun.com, gww@eng.sun.com, Scott.Rotondo@sun.com,
        psarc-ext@sun.com
Message-id: <18483.24337.215632.554701@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805200357.m4K3vgQI006365@sac.sfbay.sun.com>
 <48325290.4090706@sun.com> <4833556F.2030204@sun.com>
 <48335B5A.5040107@sun.com>
Content-Length: 1120
Status: RO
X-Status: $$$$
X-UID: 0000000054

Garrett D'Amore writes:
> Just a quick question/thought.  Given that the e-mail trail has gone off 
> the weeds, wouldn't it be simpler to withdraw this case, and resubmit 
> new materials under a different number (and with a fresh e-mail log?)  
> I'm thinking of the situation when in the future, someone wants to back 
> reference -- it seems kind of unfortunate that one has to go back 
> through a bunch of stuff that is irrelevant.
> 
> (In other words, perhaps instead of "waiting need spec", we should be 
> more willing to withdraw and resubmit under new materials and case number.)

I disagree that's very useful.  I'd prefer to have a "spec.txt" file
in the case directory with the final specification.

If the specification is complete (and it should be) then that future
person should be looking at the specification first ... and for most
purposes, should be looking at that alone.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From jek3@sun.com Tue May 20 19:26:42 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4L2QfIF020148
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 20 May 2008 19:26:42 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4L2Qa0D016949;
	Wed, 21 May 2008 03:26:38 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1700N0D5GD2C00@brm-avmta-1.central.sun.com>; Tue,
 20 May 2008 20:26:37 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1700MSS5GCK700@brm-avmta-1.central.sun.com>; Tue,
 20 May 2008 20:26:36 -0600 (MDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m4L2QZI8730142; Tue, 20 May 2008 19:26:35 -0700 (PDT)
Date: Tue, 20 May 2008 16:28:25 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: No Root Login [PSARC/2008/321 FastTrack timeout 05/20/2008]
In-reply-to: <48335B5A.5040107@sun.com>
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, James.Hughes@sun.com,
        gww@eng.sun.com, Scott.Rotondo@sun.com, psarc-ext@sun.com
Message-id: <483388C9.2040909@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805200357.m4K3vgQI006365@sac.sfbay.sun.com>
 <48325290.4090706@sun.com> <4833556F.2030204@sun.com>
 <48335B5A.5040107@sun.com>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Content-Length: 866
Status: RO
X-Status: $$$$
X-UID: 0000000055

Garrett D'Amore wrote:
> Just a quick question/thought.  Given that the e-mail trail has gone 
> off the weeds, wouldn't it be simpler to withdraw this case, and 
> resubmit new materials under a different number (and with a fresh 
> e-mail log?)  I'm thinking of the situation when in the future, 
> someone wants to back reference -- it seems kind of unfortunate that 
> one has to go back through a bunch of stuff that is irrelevant.
>
> (In other words, perhaps instead of "waiting need spec", we should be 
> more willing to withdraw and resubmit under new materials and case 
> number.)
>
>    -- Garrett
A little known fact is that the **final** specification of the proposal 
is supposed to be installed in the case directory.

One should never need to start with the original specification and then 
apply all the deltas accepted in the mail file.

- jek3


From gww@eng.sun.com Tue Jul  1 08:08:20 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61F8JLY024175
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 1 Jul 2008 08:08:19 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m61F8HhT013865
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 1 Jul 2008 08:08:19 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C00F1H21TDT00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 01 Jul 2008 08:08:17 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00CGU21STX60@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 08:08:16 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m61F8G1j039954; Tue, 01 Jul 2008 08:08:16 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id m61F9ksg019245; Tue,
 01 Jul 2008 08:09:46 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id m61F9kr5019244; Tue,
 01 Jul 2008 08:09:46 -0700 (PDT)
Date: Tue, 01 Jul 2008 08:09:46 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Restart: PSARC/2008/321 - No Root Login
To: psarc-ext@sun.com
Cc: gww@marduk.eng.sun.com, james.hughes@sun.com
Message-id: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 3676

I'm restarting this Fast Track for Jim Hugnes.

It requests a Patch release binding.
References to Major release bindings and permission to do things
at such a release boundary are no longer part of this case.
The Problem statement has been modified to reflect this.
The interface taxonomies remain unchanged.

The timer is set for 9 July, 2008

Gary..
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Problem:
========
| Other operating systems  that have implemented roles (such as
| Ubuntu, MacOS, Windows) have eliminated the need for a "root"
| to be a login account. Solaris's only remaining requirement for "root"
| to be a login account is sulogin(1M).  Requiring "root" be a login account
| is an unnecessary imposition for simple single user machines (such as a
| machine used by application developers).

Background:
==========
Since SunOS 5.8, Solaris has had the ability, through rbac(5), to
administer the system without a "root" user login.
Historically, the "root" user exists as an "owner" of system objects.
(It would be possible to have system objects "owned" by different system
users.  There may be marginal value in doing so.  This project does not
propose changing system object ownership.)

Historically, running with euid of 0 granted full system access.
Since SunOS 5.10 Solaris has had the ability, through privileges(5),
to administer the system without requiring full system access.
The "root" (system) user can be controlled by making "root" a role.
If a site doesn't grant the role to any user, no user can become "root".
Alternatively, it was suggested that in other OS distros, "root" is,
by default, not an account that can ever be directly used.  In SunOS
5.10 terms that would be a no login account (see passwd(1) -N).

It has been suggested that Solaris should permit "root" to be a no login
account.

Proposal:
========
Add a "solaris.system.maintenance" authorization.  Modify sulogin(1M) to
prompt for a username and password.  If the username entered is
authenticated by the password and has the "solaris.system.maintenance"
authorization, enter system maintenance mode.  If not, as before this
project, deny access.

Notes:
======
This proposal allows for administrators to grant users system maintenance
mode access without giving them the knowledge of the "root" password.

+ The existing capabilities of "root" users or systems where "root" is a
+ login account is unchanged.  Both the "root" user and any user granted
+ the Primary Administrator Rights Profile have all "solaris" authorizations.

+ Users without local accounts have no change.

+ Just as today, if an administrator has chosen to make "root" a no login
+ account in a zone, "pfexec /usr/sbin/zlogin -S" must be used to enter
+ that zone.  The Zone Management Rights Profile contains "zlogin"

This proposal does not ensure that the authenticated username is not
a role.

The "root" user is by default granted all authorizations.  So, there
is no regression if "root" is not made a no login account.

A no login account ("root" or otherwise) can still run cron jobs.
The solaris.jobs.admin authorization permits a user to manage all cron jobs.

Non-"root" users may be granted Rights Profiles or roles that permit
the users to administer the entire system.

The current authorizations in solaris.system space are:
	solaris.system.:::Machine Administration::help=SysHeader.html
	solaris.system.date:::Set Date & Time::help=SysDate.html
	solaris.system.shutdown:::Shutdown the System::help=SysShutdown.html

This project enables a policy where "root" can never be used
directly by administrators as an account providing full system access.

From Darren.Moffat@sun.com Tue Jul  1 08:26:29 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61FQSl5024651
	for <psarc-ext@sac.sfbay.Sun.COM>; Tue, 1 Jul 2008 08:26:29 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m61FQOuG011583
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 1 Jul 2008 23:26:27 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C00N012W20400@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 01 Jul 2008 08:26:26 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00GFB2W117F0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 08:26:26 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m61FQOnR002513	for
 <psarc-ext@sun.com>; Tue, 01 Jul 2008 15:26:24 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3C00M011MLEN00@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 16:26:24 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K3C00DVG2VUWSA0@fe-emea-09.sun.com>; Tue,
 01 Jul 2008 16:26:20 +0100 (BST)
Date: Tue, 01 Jul 2008 16:26:17 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
Sender: Darren.Moffat@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <486A4C99.3010405@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080602)
Status: RO
Content-Length: 556

Gary Winiger wrote:
> I'm restarting this Fast Track for Jim Hugnes.
> 
> It requests a Patch release binding.

I think this is too much surprise for Patch and this is one of the areas 
where I would distinguish Patch from Micro.  Given there are no Micro 
releases planned I'd be much more comfortable with this case if it had a 
release binding of Minor.

The above is all assuming there is no real intent to backport this to a 
Solaris 10 update (ie patch binding) release anyway.

Technically I'm happy with the case as specified.

-- 
Darren J Moffat

From James.Hughes@sun.com Tue Jul  1 08:49:05 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61Fn5mf025050
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 1 Jul 2008 08:49:05 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m61Fn1Yc029671
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 1 Jul 2008 08:49:04 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C0040F3XRJ500@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 01 Jul 2008 09:49:03 -0600 (MDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00JLG3XQNS60@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 09:49:03 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m61Fn2L2005381	for
 <psarc-ext@sun.com>; Tue, 01 Jul 2008 08:49:02 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3C009013LNNW00@fe-sfbay-10.sun.com>
 (original mail from James.Hughes@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 08:49:02 -0700 (PDT)
Received: from [129.146.226.135] by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K3C001T63XM2U50@fe-sfbay-10.sun.com>; Tue,
 01 Jul 2008 08:48:58 -0700 (PDT)
Date: Tue, 01 Jul 2008 08:47:58 -0700
From: hughes <James.Hughes@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <486A4C99.3010405@Sun.COM>
Sender: James.Hughes@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, psarc-ext@sun.com
Message-id: <1214927279.6946.4.camel@JimsOSmm>
MIME-version: 1.0
X-Mailer: Evolution 2.12.2
Content-type: multipart/alternative;
 boundary="Boundary_(ID_+qX5TTw5nXhZNljHoKMS8w)"
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486A4C99.3010405@Sun.COM>
Status: RO
Content-Length: 2139


--Boundary_(ID_+qX5TTw5nXhZNljHoKMS8w)
Content-type: text/plain
Content-transfer-encoding: 7BIT


On Tue, 2008-07-01 at 16:26 +0100, Darren J Moffat wrote:

> Gary Winiger wrote:
> > I'm restarting this Fast Track for Jim Hugnes.
> > 
> > It requests a Patch release binding.
> 
> I think this is too much surprise for Patch and this is one of the
> areas 
> where I would distinguish Patch from Micro.  Given there are no Micro 
> releases planned I'd be much more comfortable with this case if it had
> a 
> release binding of Minor.
> 
> The above is all assuming there is no real intent to backport this to
> a 
> Solaris 10 update (ie patch binding) release anyway.

The intent was for OpenSolaris, not S10. 



--Boundary_(ID_+qX5TTw5nXhZNljHoKMS8w)
Content-type: text/html; charset=utf-8
Content-transfer-encoding: 7BIT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 TRANSITIONAL//EN">
<HTML>
<HEAD>
  <META HTTP-EQUIV="Content-Type" CONTENT="text/html; CHARSET=UTF-8">
  <META NAME="GENERATOR" CONTENT="GtkHTML/3.16.2">
</HEAD>
<BODY>
<BR>
On Tue, 2008-07-01 at 16:26 +0100, Darren J Moffat wrote:<BR>
<BLOCKQUOTE TYPE=CITE>
    <FONT COLOR="#000000">Gary Winiger wrote:</FONT><BR>
    <FONT COLOR="#000000">&gt; I'm restarting this Fast Track for Jim Hugnes.</FONT><BR>
    <FONT COLOR="#000000">&gt; </FONT><BR>
    <FONT COLOR="#000000">&gt; It requests a Patch release binding.</FONT><BR>
    <BR>
    <FONT COLOR="#000000">I think this is too much surprise for Patch and this is one of the areas </FONT><BR>
    <FONT COLOR="#000000">where I would distinguish Patch from Micro.  Given there are no Micro </FONT><BR>
    <FONT COLOR="#000000">releases planned I'd be much more comfortable with this case if it had a </FONT><BR>
    <FONT COLOR="#000000">release binding of Minor.</FONT><BR>
    <BR>
    <FONT COLOR="#000000">The above is all assuming there is no real intent to backport this to a </FONT><BR>
    <FONT COLOR="#000000">Solaris 10 update (ie patch binding) release anyway.</FONT><BR>
</BLOCKQUOTE>
The intent was for OpenSolaris, not S10. <BR>
<BR>
<BR>
</BODY>
</HTML>

--Boundary_(ID_+qX5TTw5nXhZNljHoKMS8w)--

From gdamore@sun.com Tue Jul  1 08:50:20 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61FoKhX025073
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 1 Jul 2008 08:50:20 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m61FnXH5058068
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 1 Jul 2008 09:50:19 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C00G193ZOQ600@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 01 Jul 2008 08:50:12 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00CUS3ZNTXA0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 08:50:11 -0700 (PDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m61FoBSq005568	for
 <psarc-ext@sun.com>; Tue, 01 Jul 2008 08:50:11 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3C005011623200@fe-sfbay-10.sun.com> (original mail from gdamore@sun.com)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 08:50:11 -0700 (PDT)
Received: from [192.168.251.106] ([76.174.83.55])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K3C0019Z3ZK2U60@fe-sfbay-10.sun.com>; Tue,
 01 Jul 2008 08:50:08 -0700 (PDT)
Date: Tue, 01 Jul 2008 08:47:45 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <486A4C99.3010405@Sun.COM>
Sender: Garrett.Damore@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <486A51A1.8000409@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486A4C99.3010405@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071023)
Status: RO
Content-Length: 1085

Darren J Moffat wrote:
> Gary Winiger wrote:
>> I'm restarting this Fast Track for Jim Hugnes.
>>
>> It requests a Patch release binding.
>
> I think this is too much surprise for Patch and this is one of the 
> areas where I would distinguish Patch from Micro.  Given there are no 
> Micro releases planned I'd be much more comfortable with this case if 
> it had a release binding of Minor.
>
> The above is all assuming there is no real intent to backport this to 
> a Solaris 10 update (ie patch binding) release anyway.
>
> Technically I'm happy with the case as specified.

Ditto.

If there is a desire to backport to S10, could the new behavior of 
prompting for a username (instead of assuming root) be made conditional 
(e.g. based on some configuration in /etc/?)  I would think if this 
behavior were optional, and not enabled by default, then a Patch binding 
would be non-controversial.  (Note that I think making the behavior 
conditional is only required for Patch releases... for minor/micro 
releases the behavior as specified here seems good to me.)

    -- Garrett


From Nicolas.Williams@sun.com Tue Jul  1 09:49:13 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61GnDPC027553
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 1 Jul 2008 09:49:13 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m61GnCRM021426;
	Tue, 1 Jul 2008 09:49:13 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C0080T6Q0AS00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 01 Jul 2008 09:49:12 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00N366PX0H60@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 01 Jul 2008 09:49:10 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m61Gn8sN007308;
 Tue, 01 Jul 2008 11:49:08 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m61Gn88c007307; Tue,
 01 Jul 2008 11:49:08 -0500 (CDT)
Date: Tue, 01 Jul 2008 11:49:08 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>
Cc: psarc-ext@sun.com, gww@marduk.eng.sun.com, James.Hughes@sun.com
Mail-followup-to: Gary Winiger <gww@eng.sun.com>, psarc-ext@sun.com,
 gww@marduk.eng.sun.com, James.Hughes@sun.com
Message-id: <20080701164907.GS2735@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 484

On Tue, Jul 01, 2008 at 08:09:46AM -0700, Gary Winiger wrote:
> Proposal:
> ========
> Add a "solaris.system.maintenance" authorization.  Modify sulogin(1M) to
> prompt for a username and password.  [...]

But only if root is a no login account, right?

Otherwise this could create problems (first, there's the surprise
factor, second people have expect scripted around sulogin's existing
prompt -- even if the prompt is not an interface, it's been stable for a
long time).

Nico
-- 

From Darren.Moffat@Sun.COM Tue Jul  1 10:02:59 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61H2x8H028225
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 1 Jul 2008 10:02:59 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m61H2vi6022859
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 1 Jul 2008 11:02:58 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C0090R7CXL300@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@Sun.COM); Tue, 01 Jul 2008 10:02:57 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00NTD7CW0S90@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@Sun.COM); Tue,
 01 Jul 2008 10:02:57 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m61H2t6V009918	for
 <psarc-ext@Sun.COM>; Tue, 01 Jul 2008 17:02:55 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3C00701797VI00@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Tue,
 01 Jul 2008 18:02:55 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K3C00DM17CUWSD0@fe-emea-09.sun.com>; Tue,
 01 Jul 2008 18:02:55 +0100 (BST)
Date: Tue, 01 Jul 2008 18:02:54 +0100
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <20080701164907.GS2735@Sun.COM>
Sender: Darren.Moffat@Sun.COM
To: Gary Winiger <gww@eng.sun.com>, psarc-ext@Sun.COM, James.Hughes@Sun.COM
Message-id: <486A633E.70309@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <20080701164907.GS2735@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (X11/20080602)
Status: RO
Content-Length: 753

Nicolas Williams wrote:
> On Tue, Jul 01, 2008 at 08:09:46AM -0700, Gary Winiger wrote:
>> Proposal:
>> ========
>> Add a "solaris.system.maintenance" authorization.  Modify sulogin(1M) to
>> prompt for a username and password.  [...]
> 
> But only if root is a no login account, right?

That isn't how I read it.  I read that it would always be the new way.

> Otherwise this could create problems (first, there's the surprise
> factor, second people have expect scripted around sulogin's existing
> prompt -- even if the prompt is not an interface, it's been stable for a
> long time).

I think the surprise is fine for a Micro but not patch release.  The 
project team has already said there is no intent to patch this into S10.

-- 
Darren J Moffat

From gdamore@sun.com Tue Jul  1 10:17:42 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61HHf67029119
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 1 Jul 2008 10:17:42 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m61HHdeU023716
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 1 Jul 2008 18:17:41 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C00A0181GZM00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 01 Jul 2008 11:17:40 -0600 (MDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00JGU81FN7B0@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 11:17:39 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m61HHdHQ016134	for
 <psarc-ext@sun.com>; Tue, 01 Jul 2008 10:17:39 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3C003017TGN900@fe-sfbay-10.sun.com> (original mail from gdamore@sun.com)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 01 Jul 2008 10:17:39 -0700 (PDT)
Received: from [192.168.251.106] ([76.174.83.55])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K3C00G6N818MWD0@fe-sfbay-10.sun.com>; Tue,
 01 Jul 2008 10:17:33 -0700 (PDT)
Date: Tue, 01 Jul 2008 10:15:10 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <486A633E.70309@Sun.COM>
Sender: Garrett.Damore@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <486A661E.10908@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <20080701164907.GS2735@Sun.COM> <486A633E.70309@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071023)
Status: RO
Content-Length: 1448

Darren J Moffat wrote:
> Nicolas Williams wrote:
>> On Tue, Jul 01, 2008 at 08:09:46AM -0700, Gary Winiger wrote:
>>> Proposal:
>>> ========
>>> Add a "solaris.system.maintenance" authorization.  Modify 
>>> sulogin(1M) to
>>> prompt for a username and password.  [...]
>>
>> But only if root is a no login account, right?
>
> That isn't how I read it.  I read that it would always be the new way.
>
>> Otherwise this could create problems (first, there's the surprise
>> factor, second people have expect scripted around sulogin's existing
>> prompt -- even if the prompt is not an interface, it's been stable for a
>> long time).
>
> I think the surprise is fine for a Micro but not patch release.  The 
> project team has already said there is no intent to patch this into S10.
>
I'd be shocked to find anyone has expect scripted sulogin (possibly 
excepting some test code here inside Sun to test failure scenarios, 
although even that seems doubtful).

When sulogin is invoked, the machine is typically already at the point 
of failure, and its hard to imagine people building scripts around 
recovery actions.  (You'd have to look at "why" the machine is in single 
user, and determine a course of repair action, etc.  That probably means 
parsing the rest of the console output, not just the login prompt.  I 
doubt there's any software in use that is sophisticated enough to do 
this without the help of an administrator.)

    -- Garrett


From Nicolas.Williams@sun.com Tue Jul  1 10:31:53 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61HVrfH001092
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 1 Jul 2008 10:31:53 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m61HVquJ022505;
	Tue, 1 Jul 2008 10:31:52 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C00C038P31F00@brm-avmta-1.central.sun.com>; Tue,
 01 Jul 2008 11:31:51 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00JL28P3MUD0@brm-avmta-1.central.sun.com>; Tue,
 01 Jul 2008 11:31:51 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m61HVom6007348;
 Tue, 01 Jul 2008 12:31:50 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m61HVo95007347; Tue,
 01 Jul 2008 12:31:50 -0500 (CDT)
Date: Tue, 01 Jul 2008 12:31:50 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <486A633E.70309@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, psarc-ext@sun.com, James.Hughes@sun.com
Mail-followup-to: Darren J Moffat <Darren.Moffat@Sun.COM>,
 Gary Winiger <gww@eng.sun.com>, psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <20080701173150.GU2735@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <20080701164907.GS2735@Sun.COM> <486A633E.70309@Sun.COM>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 895

On Tue, Jul 01, 2008 at 06:02:54PM +0100, Darren J Moffat wrote:
> Nicolas Williams wrote:
> >On Tue, Jul 01, 2008 at 08:09:46AM -0700, Gary Winiger wrote:
> >>Proposal:
> >>========
> >>Add a "solaris.system.maintenance" authorization.  Modify sulogin(1M) to
> >>prompt for a username and password.  [...]
> >
> >But only if root is a no login account, right?
> 
> That isn't how I read it.  I read that it would always be the new way.

The word "always" would have helped.

> >Otherwise this could create problems (first, there's the surprise
> >factor, second people have expect scripted around sulogin's existing
> >prompt -- even if the prompt is not an interface, it's been stable for a
> >long time).
> 
> I think the surprise is fine for a Micro but not patch release.  The 
> project team has already said there is no intent to patch this into S10.

Right, I agree with that.

Nico
-- 

From jek3@sun.com Tue Jul  1 12:00:45 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m61J0i9R004185
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 1 Jul 2008 12:00:45 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m61J0fFO007893;
	Tue, 1 Jul 2008 20:00:42 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3C00I0ZCT5IR00@brm-avmta-1.central.sun.com>; Tue,
 01 Jul 2008 13:00:41 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3C00FO7CT4RP50@brm-avmta-1.central.sun.com>; Tue,
 01 Jul 2008 13:00:40 -0600 (MDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id m61J0dGG268854; Tue, 01 Jul 2008 12:00:39 -0700 (PDT)
Date: Tue, 01 Jul 2008 09:04:04 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <486A633E.70309@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, psarc-ext@sun.com, James.Hughes@sun.com
Message-id: <486A7FA4.6090009@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <20080701164907.GS2735@Sun.COM> <486A633E.70309@Sun.COM>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Status: RO
Content-Length: 239


> I think the surprise is fine for a Micro but not patch release.  The 
> project team has already said there is no intent to patch this into S10.

Yea, but please make it formal in the proposal.  Minor Binding.

(Heh, Deja Vu!)

- jek3


From Joerg.Schilling@fokus.fraunhofer.de Thu Jul  3 01:23:19 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m638NJTu008320
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 3 Jul 2008 01:23:19 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m638NILl006779;
	Thu, 3 Jul 2008 01:23:19 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3F00A0J8MTZM00@brm-avmta-1.central.sun.com>; Thu,
 03 Jul 2008 02:23:17 -0600 (MDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3F00A6O8MSTI00@brm-avmta-1.central.sun.com>; Thu,
 03 Jul 2008 02:23:17 -0600 (MDT)
Received: from relay41i.sun.com ([192.5.209.70])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m638K1m7006896; Thu,
 03 Jul 2008 08:23:16 +0000 (GMT)
Received: from mms49es.mms.us.syntegra.com ([160.41.221.232] [160.41.221.232])
 by relay41i.sun.com with ESMTP id BT-MMP-268467; Thu,
 03 Jul 2008 08:23:16 +0000 (Z)
Received: from relay42i.sun.com (relay42i.sun.com [192.5.209.72])
 by mms49es.mms.us.syntegra.com with ESMTP id BT-MMP-62633879; Thu,
 03 Jul 2008 08:23:16 +0000 (Z)
Received: from mailgw1.fraunhofer.de ([153.96.1.17] [153.96.1.17])
 by relay4i.sun.com with ESMTP id BT-MMP-9107810; Thu,
 03 Jul 2008 08:23:15 +0000 (Z)
Received: from mailgw1.fraunhofer.de (localhost [127.0.0.1])
	by mailgw1.fraunhofer.de[host mailgw13] (8.14.2+/8.14.2)
 with ESMTP id m638N0Tm026041; Thu, 03 Jul 2008 10:23:00 +0200 (CEST)
Received: from pluto.fokus.fraunhofer.de
 (pluto.fokus.fraunhofer.de [195.37.77.164])
	by mailgw1.fraunhofer.de (8.14.2+/8.14.2) with ESMTP id m638N0tt026034
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Thu,
 03 Jul 2008 10:23:00 +0200 (CEST)
Received: from EXCHSRV.fokus.fraunhofer.de (bohr [10.147.9.231])
	by pluto.fokus.fraunhofer.de (8.13.7/8.13.7) with SMTP id m638MuLl020025; Thu,
 03 Jul 2008 10:22:59 +0200 (MEST)
Received: from rigel ([10.147.65.195]) by EXCHSRV.fokus.fraunhofer.de with
 Microsoft SMTPSVC(6.0.3790.3959); Thu, 03 Jul 2008 10:22:58 +0200
Date: Thu, 03 Jul 2008 10:22:58 +0200
From: Joerg.Schilling@fokus.fraunhofer.de (Joerg Schilling)
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
To: psarc-ext@sun.com, gww@eng.sun.com
Cc: james.hughes@sun.com, gww@marduk.eng.sun.com
Message-id: <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Fraunhofer-Email-Policy: accepted
X-Antispam: No, score=0.0/5.0, scanned in 0.066sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
User-Agent: nail 11.22 3/20/05
X-OriginalArrivalTime: 03 Jul 2008 08:22:58.0421 (UTC)
 FILETIME=[00365A50:01C8DCE6]
Status: RO
Content-Length: 949

Gary Winiger <gww@eng.sun.com> wrote:

> I'm restarting this Fast Track for Jim Hugnes.
>
> It requests a Patch release binding.
> References to Major release bindings and permission to do things
> at such a release boundary are no longer part of this case.
> The Problem statement has been modified to reflect this.
> The interface taxonomies remain unchanged.

I already asked in the first run:

What happens if people use a pf*sh by default?

Will they be treated as if they logged in as root with the exception that 
the files they created are not owned by root?

I do not like to see user accounts with super user privileges as usual in MS-WIN.

Jörg

-- 
 EMail:joerg@schily.isdn.cs.tu-berlin.de (home) Jörg Schilling D-13353 Berlin
       js@cs.tu-berlin.de                (uni)  
       schilling@fokus.fraunhofer.de     (work) Blog: http://schily.blogspot.com/
 URL:  http://cdrecord.berlios.de/old/private/ ftp://ftp.berlios.de/pub/schily

From Darren.Moffat@sun.com Thu Jul  3 06:08:30 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m63D8Tei014083
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 3 Jul 2008 06:08:29 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m63D8RTH024208
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 3 Jul 2008 14:08:28 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3F0000JLU27U00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 03 Jul 2008 06:08:26 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3F00E3QLU1Y3B0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 03 Jul 2008 06:08:26 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe2.eu.sun.com [192.18.6.11])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m63D8Pah028419	for
 <psarc-ext@sun.com>; Thu, 03 Jul 2008 13:08:25 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3F00501HLNZF00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 03 Jul 2008 14:08:25 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K3F0041VLTO9TC0@fe-emea-10.sun.com>; Thu,
 03 Jul 2008 14:08:16 +0100 (BST)
Date: Thu, 03 Jul 2008 14:08:12 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
Sender: Darren.Moffat@sun.com
To: Joerg Schilling <Joerg.Schilling@fokus.fraunhofer.de>
Cc: psarc-ext@sun.com, gww@eng.sun.com, James.Hughes@sun.com
Message-id: <486CCF3C.3050607@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
User-Agent: Thunderbird 2.0.0.14 (X11/20080602)
Status: RO
Content-Length: 2589

Joerg Schilling wrote:
> Gary Winiger <gww@eng.sun.com> wrote:
> 
>> I'm restarting this Fast Track for Jim Hugnes.
>>
>> It requests a Patch release binding.
>> References to Major release bindings and permission to do things
>> at such a release boundary are no longer part of this case.
>> The Problem statement has been modified to reflect this.
>> The interface taxonomies remain unchanged.
> 
> I already asked in the first run:
> 
> What happens if people use a pf*sh by default?

Nothing different happens.

> Will they be treated as if they logged in as root with the exception that 
> the files they created are not owned by root?

No this is a real root login.

> I do not like to see user accounts with super user privileges as usual in MS-WIN.

That isn't what this case does.

sulogin now asks for a username and password instead of just the root 
password.   It authenticates that user rather than root.  If the user 
has the authorisation that this case lists then sulogin does exactly the 
same as it always did before when given the root password, ie it creates 
a uid=0 privs=all (or zone) shell.  The user is NOT logged in as themselves.

Very similar to how sudo works, you get asked for *your* password and 
nobody needs to know the real root password (or their might not even be 
one).  It has the added huge bonus that now we can actually know who the 
real user is and audit it correctly during sulogin.

Note that below is my understanding of how this will look with this case 
but I'm not the project team they may choose slightly different output:

Currently:
----------

Requesting System Maintenance Mode
SINGLE USER MODE

Root password for system maintenance (control-d to bypass): ********
single-user privilege assigned to /dev/console.
Entering System Maintenance Mode
#  pcred -a $$
100136: euid=0 ruid=0 suid=0  egid=0 rgid=0 sgid=0
         groups: 0 1 2 3 4 5 6 7 8 9 12
#

Post this case I expect it will look like this
-----------------------------------------------

Requesting System Maintenance Mode
SINGLE USER MODE

Enter username (control-d to bypass): darrenm
Password: ********
single-user privilege assigned to /dev/console.
Entering System Maintenance Mode
#  pcred -a $$
100136: euid=0 ruid=0 suid=0  egid=0 rgid=0 sgid=0
         groups: 0 1 2 3 4 5 6 7 8 9 12
#


Or if darrenm wasn't authorised:

Requesting System Maintenance Mode
SINGLE USER MODE

Enter username (control-d to bypass): darrenm
Password: ********
User darrenm not authorised to enter system maintenance mode
Enter username (control-d to bypass):

-- 
Darren J Moffat

From scott.rotondo@sun.com Mon Jul  7 13:25:49 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m67KPnip026237
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 7 Jul 2008 13:25:49 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m67KPm7h024556;
	Mon, 7 Jul 2008 13:25:49 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3N0080BKR08L00@brm-avmta-1.central.sun.com>; Mon,
 07 Jul 2008 14:25:48 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3N000ZMKR08O80@brm-avmta-1.central.sun.com>; Mon,
 07 Jul 2008 14:25:48 -0600 (MDT)
Received: from [129.146.108.62] (vinifera.SFBay.Sun.COM [129.146.108.62])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id m67KPllP763734; Mon, 07 Jul 2008 13:25:47 -0700 (PDT)
Date: Mon, 07 Jul 2008 13:25:47 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <486CCF3C.3050607@Sun.COM>
To: psarc-ext@sun.com
Cc: gww@eng.sun.com, James.Hughes@sun.com
Message-id: <48727BCB.8000107@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
 <486CCF3C.3050607@Sun.COM>
User-Agent: Thunderbird 2.0.0.12 (X11/20080422)
Status: RO
Content-Length: 758

Darren J Moffat wrote:
> 
> Post this case I expect it will look like this
> -----------------------------------------------
> 
> Requesting System Maintenance Mode
> SINGLE USER MODE
> 
> Enter username (control-d to bypass): darrenm

Implementation suggestion: It would be nice for hitting carriage return 
at this point to be acceptable as a synonym for "root". I don't think 
it's necessary to clutter the prompt with that information, but it would 
be a reasonable interpretation for a null string entered at this prompt.

	Scott

> Password: ********
> single-user privilege assigned to /dev/console.
> Entering System Maintenance Mode
> #  pcred -a $$
> 100136: euid=0 ruid=0 suid=0  egid=0 rgid=0 sgid=0
>         groups: 0 1 2 3 4 5 6 7 8 9 12
> #


From Darren.Moffat@sun.com Tue Jul  8 03:29:08 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m68AT85h020451
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 8 Jul 2008 03:29:08 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m68AT44U015210
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 8 Jul 2008 11:29:07 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3O00J01NSI6P00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 08 Jul 2008 03:29:06 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3O003VKNSHNRE0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 08 Jul 2008 03:29:06 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m68AT5Rv021167	for
 <psarc-ext@sun.com>; Tue, 08 Jul 2008 10:29:05 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3O00H01NLXA900@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 08 Jul 2008 11:29:05 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K3O001DRNRUME10@fe-emea-10.sun.com>; Tue,
 08 Jul 2008 11:28:43 +0100 (BST)
Date: Tue, 08 Jul 2008 11:28:42 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <48727BCB.8000107@sun.com>
Sender: Darren.Moffat@sun.com
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: psarc-ext@sun.com, James.Hughes@sun.com, gww@eng.sun.com
Message-id: <4873415A.90900@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
 <486CCF3C.3050607@Sun.COM> <48727BCB.8000107@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080602)
Status: RO
Content-Length: 742

Scott Rotondo wrote:
> Darren J Moffat wrote:
>> Post this case I expect it will look like this
>> -----------------------------------------------
>>
>> Requesting System Maintenance Mode
>> SINGLE USER MODE
>>
>> Enter username (control-d to bypass): darrenm
> 
> Implementation suggestion: It would be nice for hitting carriage return 
> at this point to be acceptable as a synonym for "root". I don't think 
> it's necessary to clutter the prompt with that information, but it would 
> be a reasonable interpretation for a null string entered at this prompt.

IMO that is not an implementation issue but an interface.  If the 
project team intends to take you up on that then I believe it should be 
part of the spec.

-- 
Darren J Moffat

From scott.rotondo@sun.com Tue Jul  8 09:56:05 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m68Gu4Dr001462
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 8 Jul 2008 09:56:04 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m68Gu292001094;
	Tue, 8 Jul 2008 10:56:02 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3P00F035PE6600@brm-avmta-1.central.sun.com>; Tue,
 08 Jul 2008 10:56:02 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3P00CU55PDFC20@brm-avmta-1.central.sun.com>; Tue,
 08 Jul 2008 10:56:01 -0600 (MDT)
Received: from [129.146.108.62] (vinifera.SFBay.Sun.COM [129.146.108.62])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id m68Gu03B425980; Tue, 08 Jul 2008 09:56:01 -0700 (PDT)
Date: Tue, 08 Jul 2008 09:56:00 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <4873415A.90900@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: psarc-ext@sun.com, James.Hughes@sun.com, gww@eng.sun.com
Message-id: <48739C20.6010808@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
 <486CCF3C.3050607@Sun.COM> <48727BCB.8000107@sun.com> <4873415A.90900@Sun.COM>
User-Agent: Thunderbird 2.0.0.12 (X11/20080422)
Status: RO
Content-Length: 1232

Darren J Moffat wrote:
> Scott Rotondo wrote:
>> Darren J Moffat wrote:
>>> Post this case I expect it will look like this
>>> -----------------------------------------------
>>>
>>> Requesting System Maintenance Mode
>>> SINGLE USER MODE
>>>
>>> Enter username (control-d to bypass): darrenm
>>
>> Implementation suggestion: It would be nice for hitting carriage 
>> return at this point to be acceptable as a synonym for "root". I don't 
>> think it's necessary to clutter the prompt with that information, but 
>> it would be a reasonable interpretation for a null string entered at 
>> this prompt.
> 
> IMO that is not an implementation issue but an interface.  If the 
> project team intends to take you up on that then I believe it should be 
> part of the spec.
> 

I see your point. I hope the project team will consider incorporating 
this refinement.

On the other hand, I really do think this could be considered a detail 
of the implementation. Under my proposal, sulogin will still prompt for 
a username and password. Even if the spec is silent on the issue, the 
implementation has to have *some* deterministic behavior when the 
username is a null string; I'm just suggesting what that behavior should be.

	Scott


From Darren.Moffat@sun.com Tue Jul  8 10:00:45 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m68H0iET001858
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 8 Jul 2008 10:00:44 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m68H0hk4002749
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 8 Jul 2008 11:00:44 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3P00B2L5X7JH00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 08 Jul 2008 10:00:43 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3P00A5E5X4ZM10@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 08 Jul 2008 10:00:41 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m68H0erH006391	for
 <psarc-ext@sun.com>; Tue, 08 Jul 2008 17:00:40 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3P005015ORKX00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 08 Jul 2008 18:00:40 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K3P00BRP5W5HR30@fe-emea-10.sun.com>; Tue,
 08 Jul 2008 18:00:05 +0100 (BST)
Date: Tue, 08 Jul 2008 18:00:05 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <48739C20.6010808@sun.com>
Sender: Darren.Moffat@sun.com
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: psarc-ext@sun.com, James.Hughes@sun.com, gww@eng.sun.com
Message-id: <48739D15.4050007@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
 <486CCF3C.3050607@Sun.COM> <48727BCB.8000107@sun.com> <4873415A.90900@Sun.COM>
 <48739C20.6010808@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080602)
Status: RO
Content-Length: 983

Scott Rotondo wrote:
> On the other hand, I really do think this could be considered a detail 
> of the implementation. Under my proposal, sulogin will still prompt for 
> a username and password. Even if the spec is silent on the issue, the 
> implementation has to have *some* deterministic behavior when the 
> username is a null string; I'm just suggesting what that behavior should 
> be.

But that behaviour should be documented otherwise we are free to change 
it and that means people can't depend on it (but probably would anyway). 
   If they can't depend on it why bother with it implying root rather 
than just giving an error message and asking for the username again.

This might seem like nits but it is stuff like this that customers 
actually notice and get annoyed about when we change it.   I know this 
from the praise and flak we got for changing the exact dialog that 
passwd(1) output (and passwd wasn't actually changed but PAM modules).

-- 
Darren J Moffat

From Nicolas.Williams@sun.com Tue Jul  8 10:00:57 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m68H0urp001879
	for <psarc-ext@sac.sfbay.Sun.COM>; Tue, 8 Jul 2008 10:00:56 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m68H0kdM014533;
	Wed, 9 Jul 2008 01:00:52 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3P00H3P5XCSR00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 08 Jul 2008 10:00:48 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3P00G865XBL430@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 08 Jul 2008 10:00:47 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m68H0k9e014204;
 Tue, 08 Jul 2008 12:00:46 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m68H0ju7014203; Tue,
 08 Jul 2008 12:00:45 -0500 (CDT)
Date: Tue, 08 Jul 2008 12:00:45 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <48727BCB.8000107@sun.com>
To: Scott Rotondo <scott.rotondo@sun.com>
Cc: psarc-ext@sun.com, gww@eng.sun.com, James.Hughes@sun.com
Mail-followup-to: Scott Rotondo <scott.rotondo@sun.com>, psarc-ext@sun.com,
 gww@eng.sun.com, James.Hughes@sun.com
Message-id: <20080708170045.GG2735@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
 <486CCF3C.3050607@Sun.COM> <48727BCB.8000107@sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 716

On Mon, Jul 07, 2008 at 01:25:47PM -0700, Scott Rotondo wrote:
> Darren J Moffat wrote:
> >
> >Post this case I expect it will look like this
> >-----------------------------------------------
> >
> >Requesting System Maintenance Mode
> >SINGLE USER MODE
> >
> >Enter username (control-d to bypass): darrenm
> 
> Implementation suggestion: It would be nice for hitting carriage return 
> at this point to be acceptable as a synonym for "root". I don't think 
> it's necessary to clutter the prompt with that information, but it would 
> be a reasonable interpretation for a null string entered at this prompt.

If so shouldn't the prompt indicate this?

> >Enter username (control-d to bypass, return for root): ...

From scott.rotondo@sun.com Tue Jul  8 11:00:14 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m68I0DDQ005909
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 8 Jul 2008 11:00:13 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m68I080a022946;
	Tue, 8 Jul 2008 12:00:12 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3P00D358OBO500@nwk-avmta-2.sfbay.sun.com>; Tue,
 08 Jul 2008 11:00:11 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3P00AK98O9ZK50@nwk-avmta-2.sfbay.sun.com>; Tue,
 08 Jul 2008 11:00:09 -0700 (PDT)
Received: from [129.146.108.62] (vinifera.SFBay.Sun.COM [129.146.108.62])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id m68I087V450815; Tue, 08 Jul 2008 11:00:08 -0700 (PDT)
Date: Tue, 08 Jul 2008 11:00:08 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <48739D15.4050007@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: psarc-ext@sun.com, James.Hughes@sun.com, gww@eng.sun.com
Message-id: <4873AB28.2000901@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
 <486CCF3C.3050607@Sun.COM> <48727BCB.8000107@sun.com> <4873415A.90900@Sun.COM>
 <48739C20.6010808@sun.com> <48739D15.4050007@Sun.COM>
User-Agent: Thunderbird 2.0.0.12 (X11/20080422)
Status: RO
Content-Length: 1090

Darren J Moffat wrote:
> Scott Rotondo wrote:
>> On the other hand, I really do think this could be considered a detail 
>> of the implementation. Under my proposal, sulogin will still prompt 
>> for a username and password. Even if the spec is silent on the issue, 
>> the implementation has to have *some* deterministic behavior when the 
>> username is a null string; I'm just suggesting what that behavior 
>> should be.
> 
> But that behaviour should be documented otherwise we are free to change 
> it and that means people can't depend on it (but probably would anyway). 
>   If they can't depend on it why bother with it implying root rather 
> than just giving an error message and asking for the username again.
> 
> This might seem like nits but it is stuff like this that customers 
> actually notice and get annoyed about when we change it.   I know this 
> from the praise and flak we got for changing the exact dialog that 
> passwd(1) output (and passwd wasn't actually changed but PAM modules).
> 

Fair enough. Including it in the spec is certainly fine with me.

	Scott


From scott.rotondo@sun.com Tue Jul  8 11:01:08 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m68I17SV005960
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 8 Jul 2008 11:01:07 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m68I12L7016162;
	Tue, 8 Jul 2008 19:01:04 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3P00J0N8PQQH00@brm-avmta-1.central.sun.com>; Tue,
 08 Jul 2008 12:01:02 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3P00CLS8PPFG90@brm-avmta-1.central.sun.com>; Tue,
 08 Jul 2008 12:01:01 -0600 (MDT)
Received: from [129.146.108.62] (vinifera.SFBay.Sun.COM [129.146.108.62])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id m68I11ve451536; Tue, 08 Jul 2008 11:01:01 -0700 (PDT)
Date: Tue, 08 Jul 2008 11:01:01 -0700
From: Scott Rotondo <scott.rotondo@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <20080708170045.GG2735@Sun.COM>
To: Scott Rotondo <scott.rotondo@sun.com>, psarc-ext@sun.com, gww@eng.sun.com,
        James.Hughes@sun.com
Message-id: <4873AB5D.8040802@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807011509.m61F9kr5019244@marduk.eng.sun.com>
 <486c8c62.6H+dboGP3odVWZsf%Joerg.Schilling@fokus.fraunhofer.de>
 <486CCF3C.3050607@Sun.COM> <48727BCB.8000107@sun.com>
 <20080708170045.GG2735@Sun.COM>
User-Agent: Thunderbird 2.0.0.12 (X11/20080422)
Status: RO
Content-Length: 854

Nicolas Williams wrote:
> On Mon, Jul 07, 2008 at 01:25:47PM -0700, Scott Rotondo wrote:
>> Darren J Moffat wrote:
>>> Post this case I expect it will look like this
>>> -----------------------------------------------
>>>
>>> Requesting System Maintenance Mode
>>> SINGLE USER MODE
>>>
>>> Enter username (control-d to bypass): darrenm
>> Implementation suggestion: It would be nice for hitting carriage return 
>> at this point to be acceptable as a synonym for "root". I don't think 
>> it's necessary to clutter the prompt with that information, but it would 
>> be a reasonable interpretation for a null string entered at this prompt.
> 
> If so shouldn't the prompt indicate this?
> 
>>> Enter username (control-d to bypass, return for root): ...

I'm not strongly opposed to including it in the prompt; I just don't 
think it's necessary.

	Scott


From gww@eng.sun.com Tue Jul  8 16:41:16 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m68NfFCd016473
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 8 Jul 2008 16:41:15 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m68NfDOV025613
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 8 Jul 2008 16:41:15 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3P0050XOGQW300@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 08 Jul 2008 16:41:14 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3P003VHOGPQS90@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 08 Jul 2008 16:41:13 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m68NfCv1062175; Tue, 08 Jul 2008 16:41:12 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id m68Ngscp004176; Tue,
 08 Jul 2008 16:42:54 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id m68Ngstx004175; Tue,
 08 Jul 2008 16:42:54 -0700 (PDT)
Date: Tue, 08 Jul 2008 16:42:54 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
To: Darren.Moffat@sun.com, James.Hughes@sun.com
Cc: gww@eng.sun.com, psarc-ext@sun.com
Message-id: <200807082342.m68Ngstx004175@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1421

> > I think this is too much surprise for Patch and this is one of the
> > areas 
> > where I would distinguish Patch from Micro.  Given there are no Micro 
> > releases planned I'd be much more comfortable with this case if it had
> > a 
> > release binding of Minor.
> > 
> > The above is all assuming there is no real intent to backport this to
> > a 
> > Solaris 10 update (ie patch binding) release anyway.
> 
> The intent was for OpenSolaris, not S10. 

	To be specific, this case requests a Minor release binding.
	An updated spec will be provided with a Minor release binding
	specified when the case completes.
	Also, for clarification, proposed man page changes are in the
	materials/sulogin.1m and a diff is in the materials directory.
	The man page changes will also be part of the updated spec.

Gary..
sulogin(1M):

DESCRIPTION
     The sulogin utility is automatically invoked  by  init  when
|    the system is first started. It prompts the user to type a
|    user name and password to enter system maintenance mode (single-user
     mode)  or to type	EOF (typically CTRL-D) for normal startup
     (multi-user mode).	The user  should  never	 directly  invoke
|    sulogin. The user must have the solaris.system.maintenance authorization.


SEE ALSO
|     auths(1), login(1), consadm(1M),  init(1M),  su(1M),  attributes(5),
     msglog(7D)

+NOTES
+    By default, the root user has all authorizations.

From jek3@sun.com Tue Jul  8 17:05:26 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6905PHW017216
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 8 Jul 2008 17:05:26 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m69059qe020280;
	Wed, 9 Jul 2008 01:05:23 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3P00I01PKW4T00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 08 Jul 2008 17:05:20 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3P005GYPKV0470@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 08 Jul 2008 17:05:19 -0700 (PDT)
Received: from [129.150.13.200]
 (vpn-129-150-13-200.SFBay.Sun.COM [129.150.13.200])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id m6905IFk539461; Tue, 08 Jul 2008 17:05:19 -0700 (PDT)
Date: Tue, 08 Jul 2008 14:08:58 -1000
From: Joseph Kowalski <jek3@sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
In-reply-to: <200807082342.m68Ngstx004175@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>
Cc: Darren.Moffat@sun.com, James.Hughes@sun.com, psarc-ext@sun.com
Message-id: <4874019A.6030804@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807082342.m68Ngstx004175@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.9 (X11/20080225)
Status: RO
Content-Length: 349


Could I request a paragraph or two in the spec as to the steps a system 
administrator would need to take to place a system into "No Root Login" 
mode?

Yea, I'm pretty sure there isn't anything really interesting here and 
this request isn't overly "architectural".  Please take it in the 
context of the "Bob Haggman memorial question".

- jek3


From gww@eng.sun.com Tue Jul  8 17:29:16 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m690TFfZ017829
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 8 Jul 2008 17:29:15 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m690TDCG004635;
	Tue, 8 Jul 2008 18:29:15 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3P00K07QOPPX00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 08 Jul 2008 17:29:13 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3P005EHQOO0880@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 08 Jul 2008 17:29:12 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m690TB4I019571; Tue, 08 Jul 2008 17:29:11 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id m690UrVR004240; Tue,
 08 Jul 2008 17:30:53 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id m690UrSf004239; Tue,
 08 Jul 2008 17:30:53 -0700 (PDT)
Date: Tue, 08 Jul 2008 17:30:53 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
To: gww@eng.sun.com, jek3@sun.com
Cc: Darren.Moffat@sun.com, James.Hughes@sun.com, psarc-ext@sun.com
Message-id: <200807090030.m690UrSf004239@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 567

> Could I request a paragraph or two in the spec as to the steps a system 
> administrator would need to take to place a system into "No Root Login" 
> mode?

	Sure.  The project team will add something to the Notes section like
	"passwd -r files -N root may be used to make root a no login account."

> Yea, I'm pretty sure there isn't anything really interesting here and 
> this request isn't overly "architectural".  Please take it in the 
> context of the "Bob Haggman memorial question".

	Yup and we all appreciated Bob's way of getting clarification.

Gary..

From gww@eng.sun.com Wed Jul  9 10:55:49 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69HtmEV019671
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 10:55:49 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m69HtmXc036992
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 9 Jul 2008 11:55:48 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R00G0D34Z3A00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 09 Jul 2008 11:55:47 -0600 (MDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R00ECU34YCR10@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 09 Jul 2008 11:55:46 -0600 (MDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m69Htj0a058882; Wed, 09 Jul 2008 10:55:45 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id m69HvSvH005313; Wed,
 09 Jul 2008 10:57:28 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id m69HvSjG005312; Wed,
 09 Jul 2008 10:57:28 -0700 (PDT)
Date: Wed, 09 Jul 2008 10:57:28 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: Restart: PSARC/2008/321 - No Root Login
To: psarc-ext@sun.com
Cc: gww@eng.sun.com, james.hughes@sun.com
Message-id: <200807091757.m69HvSjG005312@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 150

> I'm restarting this Fast Track for Jim Hugnes.

	This case was approved at today's PSARC meeting.
	The final spec is in the case directory.

Gary..

