[PATCH] security-manual: warn about "root-login-with-empty-password" fragment

"Robert P. J. Day" <[email protected]>
Newsgroups org.yoctoproject.lists.docs
Message-ID <[email protected]>
Mention that the development-related features that make an image less
secure might have also been added via a configuration fragment.

Signed-off-by: Robert P. J. Day <[email protected]>

---

diff --git a/documentation/security-manual/securing-images.rst b/documentation/security-manual/securing-images.rst
index 952808f3b..5493b32aa 100644
--- a/documentation/security-manual/securing-images.rst
+++ b/documentation/security-manual/securing-images.rst
@@ -108,6 +108,13 @@ system to make your images more secure:
    logging in for debugging or inspection easy during development but
    also means anyone can easily log in during production.

+   .. note::
+
+      It is also possible to set those same image features by including the
+      :term:`OpenEmbedded-Core (OE-Core)` configuration fragment
+      ``root-login-with-empty-password.conf``, so make sure that that
+      fragment has not been activated for your build configuration.
+
 -  It is possible to set a root password for the image and also to set
    passwords for any extra users you might add (e.g. administrative or
    service type users). When you set up passwords for multiple images or
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.