Comment 2 for bug 21994

Revision history for this message
Sebastian (mdkuser) wrote :

I can confirm this bug. I using a encrypted /home /var /tmp and swap partition and a Floppy containing the key on it. When I boot the machine without insert the Keydisk before the crypted partitions cannot be mounted and the system drops me to a root shell withou asking for a password.
I know the sulogin shipped with Ubuntu is patched to handle disabled root account, so this is no bug in the software but should be considered as a bug in the concept. For security reasons please patch sologin to use authenthification against the password of the group admin rather than dropping a user to a root shell without authorisation. I know it's only a local issue and can only exploided locally, but if you are using Ubuntu as a Terminal for multiusers with everyone having physically access to it this is a security risk. The unpatched sulogin does ask for a root password so it must have been a reason for it. Why Ubuntu is patching the sulogin disabling the password feature rather than patching it that way sulogin asks for the user password of the first user (who is a member of group admin). Isn't that to hard to realize?