Re: Bug#1064617: Passwords should not be changed frequently

Philip Hands <[email protected]> Wed, 06 Mar 2024 15:50:40 +0100
Newsgroups gmane.linux.debian.internationalization.english
Message-ID <[email protected]>
--=-=-=
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Justin B Rye <[email protected]> writes:

...
> Post-coffee (also fixing that wobbly indent):
>
>    Some account needs to have system administrative privileges. The
>    password/passphrase for that account should be something that
>    cannot be guessed.
>    .
>    To allow direct password-based access via the 'root' account, you
>    can set the password/passphrase for that account here.
>    .
>    Alternatively, you can lock root's password
>    by leaving this setting empty, and
>    instead use the system's initial user account
>    (which will be set up in the next step)
>    to become root. This will be enabled for you
>    by adding that user to the 'sudo' group.
>    .
>    Note: what you type here will be hidden (unless you select to show it).

I like that version better than mine, so commited it[1], and re-ran the
test to give a screenshot:

  https://openqa.debian.net/tests/239766#step/passwords/1

> Maybe instead of saying "use the system's initial user account to
> become root" it should say "allow the system's initial user account
> to gain administrative privileges"?  I'm not sure.  Oh, and we might
> even want to mention the word "superuser", or then again we might not.

I think Diederik's suggestion of using 'root' for the account and
'super-user' for the privileges might be the way to go.

Cheers, Phil.

[1] https://salsa.debian.org/installer-team/user-setup/-/merge_requests/7/d=
iffs?commit_id=3D2668d06de4f2de4735404a0671ecfb33f7bbd159
=2D-=20
Philip Hands -- https://hands.com/~phil

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE3/FBWs4yJ/zyBwfW0EujoAEl1cAFAmXogsAACgkQ0EujoAEl
1cCTOA//Q21KjDq69LBk73xa34C0PyMlrgDmxjdD7oM+fqurCxUU2CG5mbx88B6B
G0lUaqZJYOYvMMi076sOrOdtoulB/w43L9XSXjnamdcVL0pmWhHNJQ5Vr+cZBlHt
snQjoC2FhigYMhCe78bLoT4m+cQoIAnzZNrZ8CRQ97x03zF8cv0Dy+Yy/a3Vkojw
d9ePSGDz8lbj08w+jl8W1YMc09T4QbK3x55jkhsI/R0RyXIK4fp+6IIjgroAM2pX
N/WuX7zjDT0btKOPnaCnPMGmqC15C/dGYp1AvUnLzLNz/1COFlOM6Qo3xkelJOkK
qlTcN3q5p0JTOkceeDN8Chk/JENG+eVwwDQnUd0rC7Kzz83WpnJOkc8ZOUMfXDVv
4AUcHjFskMs7Kaq0fXVPiFkUtBTIoQBuAEUSYLFSyXuS4uKXdyVIRXS16sx4amcz
yLL+k9IKsBy+9rIez0szSebnY/OZdS0be9f1ut+oI9aR6l0+xOItr9CsgPhlsX6R
rq1E8IVuQ9YFhFvJx317MpsA9gS2mafoQw8+lg+y3kB5oVkZMsVn0ImpMfz/dxRL
6blQc+bRbvGJP0jNu5c5PsGwzyKadK9BuZj14U8uofEmi7YdRARKwsyrXD/yS43e
5iG2DceyoCIN85pRRqtXWrKQBlEclVZRbkbBSa3nqS675ZbcXqM=
=DT+Z
-----END PGP SIGNATURE-----
--=-=-=--