Commit 14264e58 authored by Jana Svarova's avatar Jana Svarova Committed by David King
Browse files

Add a sysadmin page on locking down repartioning
parent 06e796eb
<page xmlns=""
type="topic" style="task"
<link type="guide" xref="user-settings#lockdown"/>
<revision pkgversion="3.14" date="2014-11-25" status="draft"/>
<link type="seealso" xref="dconf-lockdown" />
<credit type="author copyright">
<name>Jana Svarova</name>
<email its:translate="no"></email>
<include href="legal.xml" xmlns=""/>
<desc>Prevent users from changing disk partitions.</desc>
<title>Lock down repartitioning</title>
<p><sys>polkit</sys> enables you to set permissions for individual
operations. For <sys>udisks2</sys>, the utility for disk management services,
the configuration is located at
<file>/usr/share/polkit-1/actions/org.freedesktop.udisks2.policy</file>. This
file contains a set of actions and default values, which can be overridden by
system administrator.</p>
<note style="tip">
<p>Remember that <sys>polkit</sys> configuration in <file>/etc</file>
overrides that shipped by packages in <file>/usr/share</file>.</p>
<title>To prevent users from changing disks settings:</title>
<p>Create a file with the same content as in
<code>cp /usr/share/polkit-1/actions/org.freedesktop.udisks2.policy /etc/share/polkit-1/actions/org.freedesktop.udisks2.policy</code>
<note style="important">
<p>Do not change the
file, your changes will be overwritten by the next package update.</p>
<p>Delete any actions you do not need from within the
<code>policyconfig</code> element and add the following lines to the
<action id="org.freedesktop.udisks2.modify-device">
<description>Modify the disks settings</description>
<message>Authentication is required to modify the disks settings</message>
<p>Replace <code>no</code> by <code>auth_admin</code> if you want to
ensure only the root user is able to carry out the action.</p>
<p>Save the changes.</p>
<p>When the user tries to change the disks settings, the following message is
<code>Authentication is required to modify the disks settings</code>
......@@ -20,6 +20,7 @@ HELP_FILES = \ \
legal.xml \ \ \ \ \ \
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment