On Thu, September 21, 2017 6:13 pm, Scott Robbins wrote:> On Thu, Sep 21, 2017 at 05:23:23PM -0500, Valeri Galtsev wrote: >> >> On Thu, September 21, 2017 12:42 pm, Joseph L. Casale wrote: >> >> Than was my first reaction when I realized that logged in with GUI >> (X11) >> >> Yes, I can understand the rationale as above - if it is somebody's >> laptop. >> Or someone's home computer. But it is arguable if it is centrally >> managed >> workstation. This ability to screw settings up is a pain for sysadmin if >> this workstation sits on common area (like library) and multiple users >> can >> access that, and even if it is workstation that is basically a single >> user >> one, but has to be managed centrally. I rest my case. Basically, all _I_ >> said on this sidetracked thread should be treated as enclosed into >> "rant" >> tags ;-) > > Well, this is my longstanding rant against RedHat and friends. Take a > look > at what Fedora is doing before blithely throwing it into RedHat. >> > Most Fedora stuff is for single user laptops, and frankly, a lot of it > seems developed by people with no concept of system administration. > Things like this. One bug, back when I cared enough to file bug reports > (at a FreeBSD shop these days, so it affects me less) was when had pkg kit > or some other GUI allow any user to install and update any package without > authorization. > > Too many things to make things easy for the less experienced user, which > makes sense for Fedora, get put into RedHat, and they shouldn't. > > I wish there were a bit more competition for commercial Linux for RedHat > here in the US so that they'd have to pay more attention to their user > base.Well, I guess we see Microsoft money invested into ("donated" to? ;-) RedHat at work. Yes, my servers are FreeBSD for long time already, but as we have to use Linux for wide variety of stuff, we may need to start looking which other distribution (better from sysadmin's prospective) to flee to. Scott, I'd be glad to hear your advise on that matter. (As CentOS public mirror maintainer I will keep maintaining that indefinitely as a token of gratitude to the project that gave us so much over long time). Valeri ++++++++++++++++++++++++++++++++++++++++ Valeri Galtsev Sr System Administrator Department of Astronomy and Astrophysics Kavli Institute for Cosmological Physics University of Chicago Phone: 773-702-4247 ++++++++++++++++++++++++++++++++++++++++
On Thu, Sep 21, 2017 at 07:00:12PM -0500, Valeri Galtsev wrote:> > On Thu, September 21, 2017 6:13 pm, Scott Robbins wrote: > > On Thu, Sep 21, 2017 at 05:23:23PM -0500, Valeri Galtsev wrote: > >> > > > > Well, this is my longstanding rant against RedHat and friends. Take a > > look > > at what Fedora is doing before blithely throwing it into RedHat. > >> > > Most Fedora stuff is for single user laptops, and frankly, a lot of it > > seems developed by people with no concept of system administration.> Well, I guess we see Microsoft money invested into ("donated" to? ;-) > RedHat at work. Yes, my servers are FreeBSD for long time already, but as > we have to use Linux for wide variety of stuff, we may need to start > looking which other distribution (better from sysadmin's prospective) to > flee to. Scott, I'd be glad to hear your advise on that matter. (As CentOS > public mirror maintainer I will keep maintaining that indefinitely as a > token of gratitude to the project that gave us so much over long time).Unfortunately, no advice. I haven't used Debian as anything but a laptop install for a long time, but their developers did, in the past, seem to have better ideas of system administration. They have their own issues, of course, nothing is perfect. -- Scott Robbins PGP keyID EB3467D6 ( 1B48 077D 66F6 9DB0 FDC2 A409 FA54 EB34 67D6 ) gpg --keyserver pgp.mit.edu --recv-keys EB3467D6
As Scott said, nothing is perfect. On Ubuntu (16.04 - the current long term support version) all home directories are world executable/readable ("Security? What's that?"). ----- Original Message ----- From: "Scott Robbins" <scottro11 at gmail.com> To: "centos" <centos at centos.org> Sent: Thursday, September 21, 2017 9:40:03 PM Subject: Re: [CentOS] prevent users from fiddling with network? On Thu, Sep 21, 2017 at 07:00:12PM -0500, Valeri Galtsev wrote:> > On Thu, September 21, 2017 6:13 pm, Scott Robbins wrote: > > On Thu, Sep 21, 2017 at 05:23:23PM -0500, Valeri Galtsev wrote: > >> > > > > Well, this is my longstanding rant against RedHat and friends. Take a > > look > > at what Fedora is doing before blithely throwing it into RedHat. > >> > > Most Fedora stuff is for single user laptops, and frankly, a lot of it > > seems developed by people with no concept of system administration.> Well, I guess we see Microsoft money invested into ("donated" to? ;-) > RedHat at work. Yes, my servers are FreeBSD for long time already, but as > we have to use Linux for wide variety of stuff, we may need to start > looking which other distribution (better from sysadmin's prospective) to > flee to. Scott, I'd be glad to hear your advise on that matter. (As CentOS > public mirror maintainer I will keep maintaining that indefinitely as a > token of gratitude to the project that gave us so much over long time).Unfortunately, no advice. I haven't used Debian as anything but a laptop install for a long time, but their developers did, in the past, seem to have better ideas of system administration. They have their own issues, of course, nothing is perfect. -- Scott Robbins PGP keyID EB3467D6 ( 1B48 077D 66F6 9DB0 FDC2 A409 FA54 EB34 67D6 ) gpg --keyserver pgp.mit.edu --recv-keys EB3467D6 _______________________________________________ CentOS mailing list CentOS at centos.org https://lists.centos.org/mailman/listinfo/centos