tools: disallow root login by default - #17863
Conversation
|
A bunch of test failures as expected: TestConnection.testWsPackage And tests which try to login as root. |
|
This needs a new test which tests our upgrade behaviour and the default behaviour of not allowing a root login. |
|
testWsPackage fails with: |
4a2785a to
16ad2b4
Compare
|
To test upgrading we have the current installed packages in our prepared virtual machine in
|
16ad2b4 to
b599e0e
Compare
b599e0e to
f4f5240
Compare
f4f5240 to
0b5b7ad
Compare
0b5b7ad to
dc92bbe
Compare
dc92bbe to
f59edfd
Compare
f59edfd to
e6032b9
Compare
e6032b9 to
73df2e8
Compare
|
Ok great... centos-8-stream on packit upgrades cockpit so no file is created. We need to work around this in tests.. |
37138d0 to
dc0ddc2
Compare
dc0ddc2 to
700a802
Compare
700a802 to
70c4572
Compare
martinpitt
left a comment
There was a problem hiding this comment.
Dankjewel! Needs some cleanup and rebasing, but I agree to the approach. Please add a release note.
martinpitt
left a comment
There was a problem hiding this comment.
Err, I meant to say "request changes"..
Unlike other images, RHEL 8 did not erase the cockpit packages before installing. This is inconsistent with our other images and we only need to retain our already installed cockpit pacakges when testing on distropkg.
70c4572 to
de60e1b
Compare
|
arch failed with That's related to that magic SHA sum update? Does that require an image refresh? |
martinpitt
left a comment
There was a problem hiding this comment.
Thanks! Very close now, only a missing chmod. That arch failure doesn't look like a flake at first sight?
de60e1b to
b3149e7
Compare
On all operating systems logging in as root with a username/password via ssh is now disallowed. Cockpit now also disallows it by default when installing it, but still allows it when upgrading your Cockpit.
b3149e7 to
928ee68
Compare
Nope, that's validating the file I changed, I guess we should skip checksums for those files. |
martinpitt
left a comment
There was a problem hiding this comment.
Dankjewel!
(FTR, it's really cool that we cover upgrades in our test suite!)
|
@jelly : I tweaked the release note a bit, WDYT? |
LGTM! |
Disallow root login by default
On all operating systems, logging in as root with a username/password via SSH has been disallowed for a long time. Cockpit now also disallows it by default on new installations, but still allows it on upgrades for backwards compatibility. You can configure this in
/etc/cockpit/disallowed-users.