Bug 969373 - '%wheel ALL=(ALL) ALL' enabled by default in RHEL-7
'%wheel ALL=(ALL) ALL' enabled by default in RHEL-7
Status: CLOSED NOTABUG
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sudo (Show other bugs)
7.0
Unspecified Unspecified
unspecified Severity unspecified
: beta
: ---
Assigned To: Daniel Kopeček
David Spurek
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2013-05-31 06:06 EDT by Dalibor Pospíšil
Modified: 2015-03-02 00:27 EST (History)
5 users (show)

See Also:
Fixed In Version: sudo-1.8.6p7-3.el7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-01-16 08:51:47 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Dalibor Pospíšil 2013-05-31 06:06:35 EDT
'%wheel  ALL=(ALL)       ALL' enabled by default. In RHEL-6 it was commented out. So it seem to me like regression.
Comment 4 Steve Bonneville 2013-11-12 18:29:34 EST
Was just about to open a bug on this reversion of bug #656873 when I saw this was still open.  Note that members of group wheel can still 'pkexec bash' to gain root through PolicyKit, and I think that's by design to enable "administrative users".  Additional historic discussion in bug #462161.
Comment 5 Jens Petersen 2013-11-27 20:55:20 EST
I prefer the current Fedora behaviour.
If admin (wheel) users can get root anyway with pkexec
why not just allow them sudo by default?
Comment 6 Daniel Kopeček 2014-01-16 08:27:06 EST
This BZ is now considered as NOTABUG as the "%wheel enabled by default" behaviour is expected and required by anaconda and the "Make user an administrator" feature. Please read the comments and/or make complaints in rhbz#994623.

Note You need to log in before you can comment on or make changes to this bug.