We noticed that the ACME configuration menu is missing from users logging in 'Administrators' with OpenID vs. users logging in as 'root' with Linux PAM.
Why is ACME not available to OpenID 'Administrators?
Other Linux PAM users also don't have access to this, but would you even want users to be able to change ACME-settings for nodes they might not even have access to (possibly even bringing down the web-GUI on those nodes)?
Also, from the certificate-section of each node, you can still add (new) ACME-settings through there (there is at least a working button for it, but since I don't use it, I can't test it)
You would also still need that root user for Updates (you can view updates with admin-users but only install them under root) anyway, so the account should be used often enough either way (if you want to stay on top of the updates ).
Technically not fully
A created PAM-user with sudo-rights assigned to it can still access the root shell, even from the GUI, they'll just have to log in a second time (and run sudo+password)
But indeed, if the GUI needs root permission, it needs to be done from the "real" root account
Technically not fully
A created PAM-user with sudo-rights assigned to it can still access the root shell, even from the GUI, they'll just have to log in a second time (and run sudo+password)
Sure, yet I was talking about the Server -> Shell functionality. Even if you've got all permissions to administer your PVE host, you will not be able to login as root (as in without a credentials). Sure you can always login with credentials.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.