network-manager-openvpn does not allow you to make openvpn drop privileges
Bug #295691 reported by
James Clemence
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
network-manager-openvpn (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: network-
Unlike manually setting the details in a file such as client.conf, the network manager openvpn plugin does not allow you to make it drop privileges from the root user to another. I tend to use an 'openvpn' user for all my openvpn connections, and manage this through the openvpn .conf file with:
# Downgrade privileges after initialization (non-Windows only)
user openvpn
group openvpn
It would be good if you could set a user/group for openvpn to run as once initiated. Could this be incorporated? Do you think it would be worthwhile?
Il
To post a comment you must log in.
A further enhancement could be the creation of such a user if they don't exist when the package is installed. After all having user and group openvpn is preferable to simply nobody for logs etc. Perhaps the privilege drop could be incorporated by default?
Il