Bug#683472: unblock: xen-api/1.3.2-10
Control: tags -1 + moreinfo
On Wed, 2012-08-01 at 10:19 +0800, Thomas Goirand wrote:
> Please unblock package xen-api
>
> The current version in Wheezy suffers from a wrong default PAM setting of
> PAM, giving access to XAPI to any account on th server, as per:
> http://lists.xen.org/archives/html/xen-api/2012-07/msg00059.html
The changelog and actual changes appear to disagree:
+ - Adds a xapi group.
+ - Configure PAM to only grant access to root and xapi groups.
versus
++auth sufficient pam_succeed_if.so user ingroup root
++#auth sufficient pam_succeed_if.so user ingroup xapi
Regards,
Adam
Reply to: