PolicyKit
PolicyKit is an application framework that acts as a negotiator between the unprivileged
user session and the privileged system context. Whenever a process from the user session
tries to carry out an action in the system context, PolicyKit is queried. Based on its
configuration—specified in a so-called "policy"—the answer could be "yes", "no", or
needs authentication. Unlike classical privilege authorization programs such
as sudo, PolicyKit does not grant root permissions to an entire process, following the
"least privilege" concept.
9.1 Available Policies and Supported
Applications
At the moment, not all applications requiring privileges make use of PolicyKit. In the
following the most important policies available on SUSE® Linux Enterprise Server
are listed.
PulseAudio
Set scheduling priorities for the PulseAudio daemon
CUPS
Add, remove, edit, enable or disable printers
9
PolicyKit
121
Need help?
Do you have a question about the LINUX ENTERPRISE SERVER 11 - SECURITY and is the answer not in the manual?