POLKIT_DEFAULT_PRIVS
to
restrictive
in
/etc/sysconfig/security
and run
set_polkit_default_privs
as
root
afterwards. Do not modify these
two files.
In order to define your custom set of privileges, use
/etc/polkit-default-privs
.local
. Privileges defined here will always take precedence over the ones defined in
the other configuration files. To define a privilege, add a line for each policy with the
following format:
<privilege
name>
<any
session>
:
<inactive
session>
:
<active
session>
For a list of all privilege names available, run the command
polkit-action
. The
following values are valid for the session parameters:
yes
grant privilege
no
block
auth_self
user needs to authenticate with own password every time the privilege is requested
auth_self_keep_session
user needs to authenticate with own password once per session, privilege is granted
for the whole session
auth_self_keep_always
user needs to authenticate with own password once, privilege is granted for the
current and for future sessions
auth_admin
user needs to authenticate with
root
password every time the privilege is requested
auth_admin_keep_session
user needs to authenticate with
root
password once per session, privilege is
granted for the whole session
PolicyKit
127
Summary of Contents for LINUX ENTERPRISE DESKTOP 11
Page 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Page 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Page 10: ......
Page 29: ...Part I Authentication...
Page 30: ......
Page 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Page 126: ......
Page 127: ...Part II Local Security...
Page 128: ......
Page 158: ......
Page 173: ...Part III Network Security...
Page 174: ......
Page 194: ......
Page 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Page 210: ......
Page 228: ......
Page 229: ...Part IV Confining Privileges with Novell AppArmor...
Page 230: ......
Page 274: ......
Page 300: ......
Page 328: ......
Page 340: ......
Page 342: ......
Page 386: ......
Page 387: ...Part V The Linux Audit Framework...
Page 388: ......