Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #175592 > unrolled thread
| Started by | Mark Neidorff <mark@neidorff.com> |
|---|---|
| First post | 2016-12-09 21:30 +0100 |
| Last post | 2016-12-14 17:20 +0100 |
| Articles | 9 — 4 participants |
Back to article view | Back to linux.debian.user
Package update problem... Mark Neidorff <mark@neidorff.com> - 2016-12-09 21:30 +0100
Re: Package update problem... kamaraju kusumanchi <raju.mailinglists@gmail.com> - 2016-12-11 20:50 +0100
Re: Package update problem... Mark Neidorff <mark@neidorff.com> - 2016-12-12 18:50 +0100
Re: Package update problem... kamaraju kusumanchi <raju.mailinglists@gmail.com> - 2016-12-13 05:50 +0100
Re: Package update problem...{***SOLVED***} Mark Neidorff <mark@neidorff.com> - 2016-12-13 20:30 +0100
Re: Package update problem...{***SOLVED***} Henning Follmann <hfollmann@itcfollmann.com> - 2016-12-13 20:40 +0100
Re: Package update problem...{***SOLVED***} Mark Neidorff <mark@neidorff.com> - 2016-12-13 20:50 +0100
Re: Package update problem...{***SOLVED***} Lisi Reisz <lisi.reisz@gmail.com> - 2016-12-14 12:10 +0100
Re: Package update problem...{***SOLVED***} Mark Neidorff <mark@neidorff.com> - 2016-12-14 17:20 +0100
| From | Mark Neidorff <mark@neidorff.com> |
|---|---|
| Date | 2016-12-09 21:30 +0100 |
| Subject | Package update problem... |
| Message-ID | <sMzXP-7Mo-21@gated-at.bofh.it> |
I'm running Jesse 8.6 with a KDE desktop. I get a desktop notification that there is one or more package updates available. I select the package(s) and then I'm asked for authentication. I type in the root password, but it is rejected. I also try my user password, but that is also rejected. (Tried multiple times, so it doesn't seem to be a typo problem) If I go to the command line--as root--and do apt-get update and upgrade, then the update installs correctly. This sounds like something easy to fix, but I just don't know where to fix and what fix to apply. Please let me know. Thanks, Mark
[toc] | [next] | [standalone]
| From | kamaraju kusumanchi <raju.mailinglists@gmail.com> |
|---|---|
| Date | 2016-12-11 20:50 +0100 |
| Message-ID | <sNiid-38J-3@gated-at.bofh.it> |
| In reply to | #175592 |
On Fri, Dec 9, 2016 at 3:17 PM, Mark Neidorff <mark@neidorff.com> wrote: > I'm running Jesse 8.6 with a KDE desktop. > > I get a desktop notification that there is one or more package updates > available. I select the package(s) and then I'm asked for authentication. I > type in the root password, but it is rejected. I also try my user password, > but that is also rejected. (Tried multiple times, so it doesn't seem to be a > typo problem) > > If I go to the command line--as root--and do apt-get update and upgrade, then > the update installs correctly. > > This sounds like something easy to fix, but I just don't know where to fix and > what fix to apply. Please let me know. The technical term you are looking for is called "Privilege escalation". On a Debian system, "administrative" privileges are required to install/upgrade/remove packages. When you run the command as root, you have all the necessary privileges. A normal user does not have them enabled by default. This explains why the commands fail unless they are run as root. One possible approach (I am only guessing here and have not tested this) is to grant the necessary privileges to this user and see if the KDE application respects that. You can do this by modifying /etc/sudoers which is explained in https://www.debian.org/doc/manuals/debian-reference/ch01.en.html#_sudo_configuration https://www.debian.org/doc/manuals/debian-reference/ch04.en.html#_sudo https://debian-handbook.info/browse/stable/sect.config-misc.html#sect.sharing-admin-rights The only caution is that /etc/sudoers can't be edited interactively in an editor. You need to use another program called visudo to do that. You can accomplish some really complex tasks by tweaking the sudoers configuration file (see man sudoers for all the gory details). But for your use case, granting ALL permissions to one normal user should probably be sufficient. hope that helps raju -- Kamaraju S Kusumanchi | http://raju.shoutwiki.com/wiki/Blog
[toc] | [prev] | [next] | [standalone]
| From | Mark Neidorff <mark@neidorff.com> |
|---|---|
| Date | 2016-12-12 18:50 +0100 |
| Message-ID | <sNCTD-7fH-3@gated-at.bofh.it> |
| In reply to | #175630 |
[Multipart message — attachments visible in raw view] — view raw
On Sunday, 12/11/16 02:45:41 PM kamaraju kusumanchi wrote: > On Fri, Dec 9, 2016 at 3:17 PM, Mark Neidorff <mark@neidorff.com> wrote: > > I'm running Jesse 8.6 with a KDE desktop. > > > > I get a desktop notification that there is one or more package updates > > available. I select the package(s) and then I'm asked for authentication. > > I type in the root password, but it is rejected. I also try my user > > password, but that is also rejected. (Tried multiple times, so it doesn't > > seem to be a typo problem) > > > > If I go to the command line--as root--and do apt-get update and upgrade, > > then the update installs correctly. > > > > This sounds like something easy to fix, but I just don't know where to fix > > and what fix to apply. Please let me know. > > The technical term you are looking for is called "Privilege escalation". > > On a Debian system, "administrative" privileges are required to > install/upgrade/remove packages. When you run the command as root, you > have all the necessary privileges. A normal user does not have them > enabled by default. This explains why the commands fail unless they > are run as root. One possible approach (I am only guessing here and > have not tested this) is to grant the necessary privileges to this > user and see if the KDE application respects that. > > You can do this by modifying /etc/sudoers which is explained in > https://www.debian.org/doc/manuals/debian-reference/ch01.en.html#_sudo_confi > guration > https://www.debian.org/doc/manuals/debian-reference/ch04.en.html#_sudo > https://debian-handbook.info/browse/stable/sect.config-misc.html#sect.shari > ng-admin-rights > > The only caution is that /etc/sudoers can't be edited interactively in > an editor. You need to use another program called visudo to do that. > > You can accomplish some really complex tasks by tweaking the sudoers > configuration file (see man sudoers for all the gory details). But for > your use case, granting ALL permissions to one normal user should > probably be sufficient. > > hope that helps > raju Sorry to seem stubborn, but I don't consider giving a user account full administrative access acceptable, even if there is only one user on the system. My reasoning is that by default if the user goes to a "naughty" web page and somehow downloads destructive software only the user's files are at risk. But, with full administrative access, the entire system (plus any attached networks) are at risk. Question: Is not allowing an administrative (software update)task to run when the root password is given a bug or is it by design? If by design, why? I see two alternatives to your suggestion, neither of which is convenient. 1. When I get a notification, log off and then log in as root. Then when the updates are downloaded and applied, log back in as the user. 2. When I get a notification, use "su" to change to the root user and then do the updates. Both of these add more steps. If I have to add these steps, then I have to. But, I have been using linux (and KDE) for a long time and up until now, when an update arrives I select to apply the update, give the root password, and the update is installed. Now, when I get an update notification and supply the root password to apply the update, the update is not applied. (I am returned to the password prompt) Thanks, Mark
[toc] | [prev] | [next] | [standalone]
| From | kamaraju kusumanchi <raju.mailinglists@gmail.com> |
|---|---|
| Date | 2016-12-13 05:50 +0100 |
| Message-ID | <sNNcl-56a-1@gated-at.bofh.it> |
| In reply to | #175647 |
On Mon, Dec 12, 2016 at 12:50 PM, Mark Neidorff <mark@neidorff.com> wrote: > > Sorry to seem stubborn, but I don't consider giving a user account full > administrative access acceptable, even if there is only one user on the > system. My reasoning is that by default if the user goes to a "naughty" web > page and somehow downloads destructive software only the user's files are at > risk. But, with full administrative access, the entire system (plus any > attached networks) are at risk. I do not think you are being stubborn. You do not have to give the normal user ALL permissions. But you have to give him some permissions to be able to install/update/remove packages. For example, I configured my /etc/sudoers file such that my normal user account can run apt-get and install packages. Giving ALL permissions just makes things simpler but /etc/sudoers can be fine tuned to give just as much as control as needed. > Question: Is not allowing an administrative (software update)task to run > when the root password is given a bug or is it by design? If by design, why? I do not understand the question. I am not here to defend any particular design choice. I can help you with how it can be done but not why it should be done one way or another. That is beyond my expertise. > I see two alternatives to your suggestion, neither of which is convenient. > > 1. When I get a notification, log off and then log in as root. Then when the > updates are downloaded and applied, log back in as the user. > No. There is no need to logoff. For example, whenever I want to install a package, I simply open a konsole and run sudo apt-get update sudo apt-get install PKGNAME as a normal user. When it asks for password, I supply the password of my user account (not the password of the root account). > 2. When I get a notification, use "su" to change to the root user and then > do the updates. That is one way. I find sudo a bit more easier than su. Since with sudo, you do not even have to know the root password (once it is setup). > But, I have been using linux (and KDE) for a long time and up until now, > when an update arrives I select to apply the update, give the root password, > and the update is installed. Now, when I get an update notification and > supply the root password to apply the update, the update is not applied. (I > am returned to the password prompt) hmm... no idea on this part. What program does KDE run when you try to update packages? May be run it from command line and see if it gives an error? hth raju -- Kamaraju S Kusumanchi | http://raju.shoutwiki.com/wiki/Blog
[toc] | [prev] | [next] | [standalone]
| From | Mark Neidorff <mark@neidorff.com> |
|---|---|
| Date | 2016-12-13 20:30 +0100 |
| Subject | Re: Package update problem...{***SOLVED***} |
| Message-ID | <sO0VX-55N-1@gated-at.bofh.it> |
| In reply to | #175653 |
On Monday, 12/12/16 11:49:01 PM kamaraju kusumanchi wrote: > On Mon, Dec 12, 2016 at 12:50 PM, Mark Neidorff <mark@neidorff.com> wrote: > > Sorry to seem stubborn, but I don't consider giving a user account full > > administrative access acceptable, even if there is only one user on the > > system. My reasoning is that by default if the user goes to a "naughty" > > web > > page and somehow downloads destructive software only the user's files are > > at risk. But, with full administrative access, the entire system (plus > > any attached networks) are at risk. > > I do not think you are being stubborn. You do not have to give the > normal user ALL permissions. But you have to give him some permissions > to be able to install/update/remove packages. For example, I > configured my /etc/sudoers file such that my normal user account can > run apt-get and install packages. Giving ALL permissions just makes > things simpler but /etc/sudoers can be fine tuned to give just as much > as control as needed. > > > Question: Is not allowing an administrative (software update)task to run > > when the root password is given a bug or is it by design? If by design, > > why? > I do not understand the question. I am not here to defend any > particular design choice. I can help you with how it can be done but > not why it should be done one way or another. That is beyond my > expertise. > > > I see two alternatives to your suggestion, neither of which is convenient. > > > > 1. When I get a notification, log off and then log in as root. Then when > > the updates are downloaded and applied, log back in as the user. > > No. There is no need to logoff. For example, whenever I want to > install a package, I simply open a konsole and run > > sudo apt-get update > sudo apt-get install PKGNAME > > as a normal user. When it asks for password, I supply the password of > my user account (not the password of the root account). > > > 2. When I get a notification, use "su" to change to the root user and then > > do the updates. > > That is one way. I find sudo a bit more easier than su. Since with > sudo, you do not even have to know the root password (once it is > setup). > > > But, I have been using linux (and KDE) for a long time and up until now, > > when an update arrives I select to apply the update, give the root > > password, and the update is installed. Now, when I get an update > > notification and supply the root password to apply the update, the update > > is not applied. (I am returned to the password prompt) > > hmm... no idea on this part. What program does KDE run when you try to > update packages? May be run it from command line and see if it gives > an error? > > hth > raju Good news! I solved the problem. This solution came from the openSUSE forums... (just giving credit where credit is due) As root, in the folder /etc/cron.* (where * is either daily, hourly, etc. depending on how often you want the check to take place): 1. Create a file called autoupdate using your favorite editor (that sounds like a good name). 2. File contents: #! /bin/bash apt-get update apt-get upgrade -y apt-get autoclean 3. Save the file, and then make it executable: #chmod 755 autoupdate Note the "apt-get autoclean" is optional. Thanks, Mark
[toc] | [prev] | [next] | [standalone]
| From | Henning Follmann <hfollmann@itcfollmann.com> |
|---|---|
| Date | 2016-12-13 20:40 +0100 |
| Subject | Re: Package update problem...{***SOLVED***} |
| Message-ID | <sO15D-58V-15@gated-at.bofh.it> |
| In reply to | #175678 |
> > > Good news! I solved the problem. This solution came from the openSUSE > forums... (just giving credit where credit is due) > > As root, in the folder /etc/cron.* (where * is either daily, hourly, etc. > depending on how often you want the check to take place): > > 1. Create a file called autoupdate using your favorite editor (that sounds like > a good name). > > 2. File contents: > #! /bin/bash > > apt-get update > apt-get upgrade -y > apt-get autoclean > > 3. Save the file, and then make it executable: > #chmod 755 autoupdate > > > Note the "apt-get autoclean" is optional. > Well, not what yousked though. The answer given to you (adding the user to sudo group) was the right answer. Anyway if you want unsupwerwised updated apt-get install cron-apt Would have been the right choice. -H -- Henning Follmann | hfollmann@itcfollmann.com
[toc] | [prev] | [next] | [standalone]
| From | Mark Neidorff <mark@neidorff.com> |
|---|---|
| Date | 2016-12-13 20:50 +0100 |
| Subject | Re: Package update problem...{***SOLVED***} |
| Message-ID | <sO1fk-5cf-11@gated-at.bofh.it> |
| In reply to | #175679 |
On Tuesday, 12/13/16 02:34:00 PM Henning Follmann wrote: > > Good news! I solved the problem. This solution came from the openSUSE > > forums... (just giving credit where credit is due) > > > > As root, in the folder /etc/cron.* (where * is either daily, hourly, etc. > > depending on how often you want the check to take place): > > > > 1. Create a file called autoupdate using your favorite editor (that sounds > > like a good name). > > > > 2. File contents: > > #! /bin/bash > > > > apt-get update > > apt-get upgrade -y > > apt-get autoclean > > > > 3. Save the file, and then make it executable: > > #chmod 755 autoupdate > > > > > > Note the "apt-get autoclean" is optional. > > Well, not what yousked though. > The answer given to you (adding the user to sudo group) was the right > answer. > > Anyway if you want unsupwerwised updated > > apt-get install cron-apt > > Would have been the right choice. > > > -H Good to know about cron-apt. I'll check it out. Many thanks, Mark
[toc] | [prev] | [next] | [standalone]
| From | Lisi Reisz <lisi.reisz@gmail.com> |
|---|---|
| Date | 2016-12-14 12:10 +0100 |
| Subject | Re: Package update problem...{***SOLVED***} |
| Message-ID | <sOfBD-5IY-15@gated-at.bofh.it> |
| In reply to | #175678 |
On Tuesday 13 December 2016 19:23:49 Mark Neidorff wrote: > On Monday, 12/12/16 11:49:01 PM kamaraju kusumanchi wrote: > > On Mon, Dec 12, 2016 at 12:50 PM, Mark Neidorff <mark@neidorff.com> wrote: > > > Sorry to seem stubborn, but I don't consider giving a user account full > > > administrative access acceptable, even if there is only one user on the > > > system. My reasoning is that by default if the user goes to a "naughty" > > > web > > > page and somehow downloads destructive software only the user's files > > > are at risk. But, with full administrative access, the entire system > > > (plus any attached networks) are at risk. > > > > I do not think you are being stubborn. You do not have to give the > > normal user ALL permissions. But you have to give him some permissions > > to be able to install/update/remove packages. For example, I > > configured my /etc/sudoers file such that my normal user account can > > run apt-get and install packages. Giving ALL permissions just makes > > things simpler but /etc/sudoers can be fine tuned to give just as much > > as control as needed. > > > > > Question: Is not allowing an administrative (software update)task to > > > run when the root password is given a bug or is it by design? If by > > > design, why? > > > > I do not understand the question. I am not here to defend any > > particular design choice. I can help you with how it can be done but > > not why it should be done one way or another. That is beyond my > > expertise. > > > > > I see two alternatives to your suggestion, neither of which is > > > convenient. > > > > > > 1. When I get a notification, log off and then log in as root. Then > > > when the updates are downloaded and applied, log back in as the user. > > > > No. There is no need to logoff. For example, whenever I want to > > install a package, I simply open a konsole and run > > > > sudo apt-get update > > sudo apt-get install PKGNAME > > > > as a normal user. When it asks for password, I supply the password of > > my user account (not the password of the root account). > > > > > 2. When I get a notification, use "su" to change to the root user and > > > then do the updates. > > > > That is one way. I find sudo a bit more easier than su. Since with > > sudo, you do not even have to know the root password (once it is > > setup). > > > > > But, I have been using linux (and KDE) for a long time and up until > > > now, when an update arrives I select to apply the update, give the root > > > password, and the update is installed. Now, when I get an update > > > notification and supply the root password to apply the update, the > > > update is not applied. (I am returned to the password prompt) > > > > hmm... no idea on this part. What program does KDE run when you try to > > update packages? May be run it from command line and see if it gives > > an error? > > > > hth > > raju > > Good news! I solved the problem. This solution came from the openSUSE > forums... (just giving credit where credit is due) It isn't the solution to the problem you posed - how to make KDE update work. It is a solution to the problem of how to update automatically. Quite different. Though apparently it is a suitable alternative for you - and for many others. Personally, I want control over updates. I don't like "update". But at least it doesn't run until you tell it to do so! Lisi > As root, in the folder /etc/cron.* (where * is either daily, hourly, etc. > depending on how often you want the check to take place): > > 1. Create a file called autoupdate using your favorite editor (that sounds > like a good name). > > 2. File contents: > #! /bin/bash > > apt-get update > apt-get upgrade -y > apt-get autoclean > > 3. Save the file, and then make it executable: > #chmod 755 autoupdate > > > Note the "apt-get autoclean" is optional. > > Thanks, > > Mark
[toc] | [prev] | [next] | [standalone]
| From | Mark Neidorff <mark@neidorff.com> |
|---|---|
| Date | 2016-12-14 17:20 +0100 |
| Subject | Re: Package update problem...{***SOLVED***} |
| Message-ID | <sOkrE-9J-49@gated-at.bofh.it> |
| In reply to | #175703 |
On Wednesday, 12/14/16 11:06:52 AM Lisi Reisz wrote: > On Tuesday 13 December 2016 19:23:49 Mark Neidorff wrote: > > On Monday, 12/12/16 11:49:01 PM kamaraju kusumanchi wrote: > > > On Mon, Dec 12, 2016 at 12:50 PM, Mark Neidorff <mark@neidorff.com> wrote: > > > > Sorry to seem stubborn, but I don't consider giving a user account > > > > full > > > > administrative access acceptable, even if there is only one user on > > > > the > > > > system. My reasoning is that by default if the user goes to a > > > > "naughty" > > > > web > > > > page and somehow downloads destructive software only the user's files > > > > are at risk. But, with full administrative access, the entire system > > > > (plus any attached networks) are at risk. > > > > > > I do not think you are being stubborn. You do not have to give the > > > normal user ALL permissions. But you have to give him some permissions > > > to be able to install/update/remove packages. For example, I > > > configured my /etc/sudoers file such that my normal user account can > > > run apt-get and install packages. Giving ALL permissions just makes > > > things simpler but /etc/sudoers can be fine tuned to give just as much > > > as control as needed. > > > > > > > Question: Is not allowing an administrative (software update)task to > > > > run when the root password is given a bug or is it by design? If by > > > > design, why? > > > > > > I do not understand the question. I am not here to defend any > > > particular design choice. I can help you with how it can be done but > > > not why it should be done one way or another. That is beyond my > > > expertise. > > > > > > > I see two alternatives to your suggestion, neither of which is > > > > convenient. > > > > > > > > 1. When I get a notification, log off and then log in as root. Then > > > > when the updates are downloaded and applied, log back in as the user. > > > > > > No. There is no need to logoff. For example, whenever I want to > > > install a package, I simply open a konsole and run > > > > > > sudo apt-get update > > > sudo apt-get install PKGNAME > > > > > > as a normal user. When it asks for password, I supply the password of > > > my user account (not the password of the root account). > > > > > > > 2. When I get a notification, use "su" to change to the root user and > > > > then do the updates. > > > > > > That is one way. I find sudo a bit more easier than su. Since with > > > sudo, you do not even have to know the root password (once it is > > > setup). > > > > > > > But, I have been using linux (and KDE) for a long time and up until > > > > now, when an update arrives I select to apply the update, give the > > > > root > > > > password, and the update is installed. Now, when I get an update > > > > notification and supply the root password to apply the update, the > > > > update is not applied. (I am returned to the password prompt) > > > > > > hmm... no idea on this part. What program does KDE run when you try to > > > update packages? May be run it from command line and see if it gives > > > an error? > > > > > > hth > > > raju > > > > Good news! I solved the problem. This solution came from the openSUSE > > forums... (just giving credit where credit is due) > > It isn't the solution to the problem you posed - how to make KDE update > work. It is a solution to the problem of how to update automatically. > Quite different. Though apparently it is a suitable alternative for you - > and for many others. Personally, I want control over updates. I don't > like "update". But at least it doesn't run until you tell it to do so! > > Lisi > > > As root, in the folder /etc/cron.* (where * is either daily, hourly, etc. > > depending on how often you want the check to take place): > > > > 1. Create a file called autoupdate using your favorite editor (that sounds > > like a good name). > > > > 2. File contents: > > #! /bin/bash > > > > apt-get update > > apt-get upgrade -y > > apt-get autoclean > > > > 3. Save the file, and then make it executable: > > #chmod 755 autoupdate > > > > > > Note the "apt-get autoclean" is optional. > > > > Thanks, > > > > Mark You are right Lisi. It is working around a KDE problem rather than fixing it. One of the e-mails that I got in this chain (which I think I have lost) warned of config files either getting overwritten or, due to syntax changes, not having the package work properly. I'm going to rethink this again. To put this in full context, the machine is a backup server that I'm building. So, my first thought was to have updates applied automatically. As I said, I'm rethinking that idea. Mark
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web