9
PolicyKit
PolicyKit is an application framework that acts as a negotiator between the unprivileged
user session and the privileged system context. Whenever a process from the user session
tries to carry out an action in the system context, PolicyKit is queried. Based on its
configuration—specified in a so-called “policy”—the answer could be “yes”, “no”, or
needs authentication
. Unlike classical privilege authorization programs such
as sudo, PolicyKit does not grant
root
permissions to an entire process, following the
“least privilege” concept.
9.1 Available Policies and Supported
Applications
At the moment, not all applications requiring privileges make use of PolicyKit. In the
following the most important policies available on SUSE® Linux Enterprise Server
are listed.
PulseAudio
Set scheduling priorities for the PulseAudio daemon
CUPS
Add, remove, edit, enable or disable printers
PolicyKit
121
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......