Per-user mandatory lockdown policies with dconf. Is it possible?

José Félix Ontañon <[email protected]> Fri, 23 May 2014 12:46:12 +0200
Newsgroups gmane.comp.gnome.lib.gconf,gmane.comp.gnome.devel
Message-ID <CAJjEPcED3OmUGz2RjnJi4MhLFHb9qySJFz7DpLYVsCJZ8rS=QQ@mail.gmail.com>
--===============1609179348968015384==
Content-Type: multipart/alternative; boundary=001a113ab3ec573e9104fa0ef115

--001a113ab3ec573e9104fa0ef115
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Hi,

First, I don't know which is the right mailing list to post the following
question. Otherwise, please tell me where to do.
Sorry for crossposting.

After following the instructions given by the official documentation, I
managed to set system-wide mandatory settings with dconf, but I've serious
doubt whether is possible to create a per-user schema of mandatory settings
with dconf.

https://wiki.gnome.org/action/show/Projects/dconf/SystemAdministrators

So, the question: is it dconf prepared for configuring mandatory user-level
lockdown policies? I mean, so once a setting is configured, the user
wouldn't have the chance to modify it.

Below two examples of configuration used: (1) a successful conf. for
locking down the desktop-background system-wide (no local user could be
able to change it), and (2) an unsuccessful try of having different
lockdown policies for two different users.

Any clarification would be welcomed.

Works! --- Example 1: locking down desktop-background system-wide ---

>>> /etc/dconf/profile/user
user-db:user
system-db:local

>>> /etc/dconf/db/local.d/locks
/org/gnome/desktop/background/picture-uri

Then run dconf update and restart desktop session.

--------------------

Not working :( --- Example 2: locking down desktop-background to test1
user, locking down disable-log-out to test2 user ---

>>> /etc/dconf/profile/test1
user-db:user
system-db:test1

>>> /etc/dconf/profile/test2
user-db:user
system-db:test2

>>> /etc/dconf/db/test1.d/locks
/org/gnome/desktop/background/picture-uri

>>> /etc/dconf/db/test2.d/locks
/org/gnome/desktop/lockdown/disable-log-out

Then run dconf update, ensure test1 and test2 has defined the DCONF_PROFILE
env variable with their username, and restart desktop session.

--=20
J. F=C3=A9lix Onta=C3=B1=C3=B3n Carmona
Consultor Externo

Emergya Consultor=C3=ADa
Tfno: +34 954 51 75 77 / +34 661 91 27 26
Fax: +34 954 51 64 73
www.emergya.es

--001a113ab3ec573e9104fa0ef115
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi,=C2=A0</div><div><br></div><div>First, I don&#39;t=
 know which is the right mailing list to post the following question. Other=
wise, please tell me where to do.</div><div>Sorry for crossposting.</div><d=
iv><br>

</div><div>After following the instructions given by the official documenta=
tion, I managed to set system-wide mandatory settings with dconf, but I&#39=
;ve serious doubt whether is possible to create a per-user schema of mandat=
ory settings with dconf.</div>

<div><br></div><div><a href=3D"https://wiki.gnome.org/action/show/Projects/=
dconf/SystemAdministrators">https://wiki.gnome.org/action/show/Projects/dco=
nf/SystemAdministrators</a><br></div><div><br></div><div>So, the question: =
is it dconf prepared for configuring mandatory user-level lockdown policies=
? I mean, so once a setting is configured, the user wouldn&#39;t have the c=
hance to modify it.</div>

<div><br></div><div>Below two examples of configuration used: (1) a success=
ful conf. for locking down the desktop-background system-wide (no local use=
r could be able to change it), and (2) an unsuccessful try of having differ=
ent lockdown policies for two different users.</div>

<div><br></div><div>Any clarification would be welcomed.</div><div><br></di=
v><div>Works! --- Example 1: locking down desktop-background system-wide --=
-</div><div><br></div><div>&gt;&gt;&gt; /etc/dconf/profile/user</div><div>

<div>user-db:user</div><div>system-db:local</div><div><br></div></div><div>=
&gt;&gt;&gt;=C2=A0/etc/dconf/db/local.d/locks</div><div><div>/org/gnome/des=
ktop/background/picture-uri</div></div><div><br></div><div>Then run dconf u=
pdate and restart desktop session.</div>

<div><br></div><div>--------------------</div><div><br></div><div>Not worki=
ng :( --- Example 2: locking down desktop-background to test1 user, locking=
 down disable-log-out to test2 user ---<br></div><div><br></div><div><div>

&gt;&gt;&gt; /etc/dconf/profile/test1</div><div><div>user-db:user</div><div=
>system-db:test1</div><div><div><br></div><div>&gt;&gt;&gt; /etc/dconf/prof=
ile/test2</div><div><div>user-db:user</div><div>system-db:test2</div></div>

</div></div></div><div><br></div><div><div>&gt;&gt;&gt;=C2=A0/etc/dconf/db/=
test1.d/locks</div><div>/org/gnome/desktop/background/picture-uri</div></di=
v><div><br></div><div><div>&gt;&gt;&gt;=C2=A0/etc/dconf/db/test2.d/locks</d=
iv><div>

/org/gnome/desktop/lockdown/disable-log-out</div></div><div><br></div><div>=
<div>Then run dconf update, ensure test1 and test2 has defined the DCONF_PR=
OFILE env variable with their username, and restart desktop session.</div>

</div><div><br>-- <br><div dir=3D"ltr">J. F=C3=A9lix Onta=C3=B1=C3=B3n Carm=
ona<br>Consultor Externo<br><br>Emergya Consultor=C3=ADa <br>Tfno: +34 954 =
51 75 77 / +34 661 91 27 26<br>Fax: +34 954 51 64 73<br><a href=3D"http://w=
ww.emergya.es" target=3D"_blank">www.emergya.es</a></div>


</div></div>

--001a113ab3ec573e9104fa0ef115--

--===============1609179348968015384==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
gconf-list mailing list
[email protected]
https://mail.gnome.org/mailman/listinfo/gconf-list
--===============1609179348968015384==--