Bug 814769

Summary: fips install: anaconda should add the new user to /etc/sudoers and/or group wheel
Product: [Fedora] Fedora Reporter: Paul Wouters <pwouters>
Component: firstbootAssignee: Martin Gracik <mgracik>
Status: CLOSED NOTABUG QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 17CC: anaconda-maint-list, bcl, dcantrell, dmach, g.kaviyarasu, jonathan, mgracik, vanmeeuwen+fedora
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-05-02 11:09:11 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Paul Wouters 2012-04-20 15:36:24 UTC
Description of problem:
When installing F17 the user added during install does not appear in /etc/sudoers or the wheel group. As a result, the user cannot use sudo.

In fips mode, su and direct login as root are rejected, so the result is that one needs to boot into non-fips mode just to be able to login as root to edit the groups or sudoers file

Comment 1 Jesse Keating 2012-04-20 15:50:28 UTC
Was this kickstart or interactive install?  An interactive install doesn't do user creation in the installer, that's handled post-install by firstboot.

If it's kickstart, then anaconda does create the user.  A workaround for when you're in kickstart is using %post to modify sudoers.  The user kickstart directive has a --group option that lets you specify additional groups, such as wheel.

https://fedoraproject.org/wiki/Anaconda/Kickstart#user

Comment 2 Paul Wouters 2012-04-21 23:10:31 UTC
interactive install, so re-assigned to firstboot

Comment 3 Martin Gracik 2012-05-02 11:09:11 UTC
If you check the "add to administrators group" when creating the user, it will add the user to the wheel group.