Re: Bug#1064617: Passwords should not be changed frequently
Philip Hands <[email protected]> Fri, 08 Mar 2024 19:58:56 +0100
| Newsgroups | gmane.linux.debian.internationalization.english |
|---|---|
| Message-ID | <[email protected]> |
--=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Justin B Rye <[email protected]> writes: > Philip Hands wrote: >>> Maybe instead of saying "use the system's initial user account to >>> become root" it should say "allow the system's initial user account >>> to gain administrative privileges"? I'm not sure. Oh, and we might >>> even want to mention the word "superuser", or then again we might not. >>=20 >> I think Diederik's suggestion of using 'root' for the account and >> 'super-user' for the privileges might be the way to go. > > Looking at what I end up with after another couple of rounds of > fiddling with it I'm not sure if it's doing quite what you asked for, > but you still might want it so here it is: Thanks for that. > - Some account needs to have system administrative privileges. The > - password/passphrase for that account should be something that > - cannot be guessed. > + Some account needs to be available with administrative super-user > + privileges. The password/passphrase for that account should be > + something that cannot be guessed. > . > To allow direct password-based access via the 'root' account, you > can set the password/passphrase for that account here. > . > - Alternatively, you can lock root's password > + Alternatively, you can lock the root account's password > by leaving this setting empty, and > instead use the system's initial user account > (which will be set up in the next step) > - to become root. This will be enabled for you > - by adding that user to the 'sudo' group. > + to gain administrative privileges. This will be enabled for you by > + adding that initial user to the 'sudo' group. > . > Note: what you type here will be hidden (unless you select to show it= ). That can be seen here: https://salsa.debian.org/philh/user-setup/-/commit/a684977100e6746725372f= 8294f271f890c50430 & https://openqa.debian.net/tests/240580#step/passwords/1 I think I prefer the previous version better for some reason. IMO Having the 'password/passphrase' throughout makes it awkward to read, and actually we've got one place where it still just says password, and fixing that would make it slightly worse IMO. How about dropping the passphrase stuff? https://salsa.debian.org/philh/user-setup/-/commit/7c8dd1bd9d5c8596e7b8f8= 2a19a075e0a5572ed7 & https://openqa.debian.net/tests/240582#step/passwords/1 which I think is more readable (and is probably fine now that we've dropped the stuff about password selection which could be read as suggesting that a password is expected to be a single word). Cheers, Phil. =2D-=20 Philip Hands -- https://hands.com/~phil --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3/FBWs4yJ/zyBwfW0EujoAEl1cAFAmXrX/AACgkQ0EujoAEl 1cBMAg/5AY130HOq8poEPdgiA7BTzfGIaX4Asug8VOuVsNz+lkHUKECcP0dXJ1au 1PSFegn3TZi+vvgiBPPnhQpzpNtetzjxvt1zAwlw7qMU47p0DIP5GjpqS1FeyLKB CQYgNSExujmFN0DAMLY7MkTs1P4H4b4CzO21m7Nrd5Ittxx2/baQtTw5eVRRSMQW AQb21RT85lwjhUb0QAgmTtyqv+EHEwJJjFjQdWGW6EFIlJHTKZ6IBYnYwNW4tvv7 mY6byioyX/v67kT3+57qTKjPGeSBrvpMi6NK1P8R+JZb5UHuR47q+No/CW2TTZtz xjxas+zKxoalzqaJJ7Zc2vJtXn0SJqM7sXVF1cIq/2uatEtjFkq4MnmHuECQYy/S nZusVJGEkvUpWajDJV+smky+zecQwu4aARvdGiWy2iR8jG2Ibm2W7M2TYntSR59V JfqhPoYcMNQFDdjY6JH4LnyEXa0oRdDsqLWWNvXXyEG4WJ88BtV5mcRNdK8+ZWHZ bne6LgrBjVvGCJZBGzuzD4DpnHHOvI2vKIEWm9MAtzp1fJOBt1zEPGlGXgLUT+sF SU1MJ/UsdKUGiVdscwRpMiF3/LkXLl6WuDxDz6HeHtPOJGPZdnCqPowq2ML9woMG vbZ9IzP9DipjDAz+gSigJUgxdik+wY+b178yIpUKH5x4WKoMot8= =WAsD -----END PGP SIGNATURE----- --=-=-=--