vedetta-com / caesonia

OpenBSD Email Service
ISC License
781 stars 41 forks source link

Revert #233 #236

Closed horia closed 5 years ago

horia commented 5 years ago
Katzeilla commented 5 years ago

I am not quite sure why upstream doesn't like this, I wish I could know the reason behind that... I believe the main purposes of doas is to give users a clear sign that what they are doing might damage their system and encourage them to use root only when they have to.

horia commented 5 years ago

My interpretation reason for allowing any command as root without a password, for a period of time, isn't best practice. The premise is taken from doas.conf(5) man examples, where a specific "cmd" should "persist" the password, or use "nopass".

Although entering a password many times isn't as safe or convenient, wheel group becomes root-equivalent in the doas.conf example configuration, and must be asked for password to limit potential damage.

Katzeilla commented 5 years ago

Got it. Thanks for explanation.