Actions
Bug #579
closedroot account locking after installation
Start date:
2010-12-28
Due date:
% Done:
0%
Estimated time:
Difficulty:
Tags:
Description
By default the password for the root user is expired instead of a locked account or similar. A regular 'su -' will show a password changing prompt, allowing anyone to set a root password without previous authentication (eg. if a machine is left unattended and unlocked).
Instead the account should be locked or, if not possible due to scripts requiring this state, have a random password (like in Ubuntu), requiring user authentication prior to changing the password.
Related issues
Updated by Olivier Pinard over 12 years ago
http://www.illumos.org/issues/619
It can help you. Just have to test or have luck.
Updated by Matt Wilby over 12 years ago
- Status changed from New to Closed
Actions