Removing a user's password effectively locks them out of admin privileges

Bug #1168747 reported by David D Lowe
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-control-center (Ubuntu)
New
Undecided
Unassigned

Bug Description

Steps to reproduce this bug:

- Log in with a user who has admin privileges
- Open User Accounts from System Settings
- Click "Unlock" and authenticate yourself
- Click on the "Password" field.
- Set "Action" to "Log in without a password"
- Click on "Change"

(Same steps with screenshots can be found in this answer: http://askubuntu.com/a/281093/2355 )

This successfully sets the user's password to empty. However, it does not ensure that sudoers includes a NOPASSWD directive, so the user now can longer use sudo, gksu, pkexec or PolicyKit to authenticate themself to gain admin rights.

What I expected to happen:

This functionality should be disabled for users with admin rights, or the sudoers file should be modified as appropriate, and PolicyKit made to work for users without a password.

ProblemType: Bug
DistroRelease: Ubuntu 12.10
Package: gnome-control-center 1:3.4.2-0ubuntu19.1
ProcVersionSignature: Ubuntu 3.5.0-26.42-generic 3.5.7.6
Uname: Linux 3.5.0-26-generic i686
ApportVersion: 2.6.1-0ubuntu10
Architecture: i386
Date: Sat Apr 13 20:59:29 2013
MarkForUpload: True
SourcePackage: gnome-control-center
UpgradeStatus: Upgraded to quantal on 2012-10-18 (176 days ago)
usr_lib_gnome-control-center:
 activity-log-manager-control-center 0.9.4-0ubuntu4.2
 deja-dup 24.0-0ubuntu2
 gnome-control-center-signon 0.0.18-0ubuntu1
 indicator-datetime 12.10.2-0ubuntu3.1

Revision history for this message
David D Lowe (flimm) wrote :
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.