Can't revoke "superuser" right for "everyone" on RT 3.8.1

We are refining our security needs now as we expand, and want to
revoke the global “superuser” right for the group “everyone”, but RT
refuses to revoke that right. I am logged in as root, and are using
RT 3.8.1. Any suggestions short of going into the database to change
this directly?

Thanks,
Tim

Just made a test: granted everyone with SuperUser, then revoked it and
everything went fine. I do believe that RT can refuse such operation
if user has no personal SuperUser right when you’re revoking global.On Tue, Oct 28, 2008 at 5:11 PM, Tim Thomas tthomas@local-motors.com wrote:

We are refining our security needs now as we expand, and want to
revoke the global “superuser” right for the group “everyone”, but RT
refuses to revoke that right. I am logged in as root, and are using
RT 3.8.1. Any suggestions short of going into the database to change
this directly?

Thanks,
Tim


http://lists.bestpractical.com/cgi-bin/mailman/listinfo/rt-users

Community help: http://wiki.bestpractical.com
Commercial support: sales@bestpractical.com

Discover RT’s hidden secrets with RT Essentials from O’Reilly Media.
Buy a copy at http://rtbook.bestpractical.com

Best regards, Ruslan.

Hmm, I have tried this with 2 log-ins including root (see attached)
and no luck. Any other suggestions, or thoughts on manually revoking
this in the DB?

Thanks,
Tim

Are any users explicitly granted SuperUser rights? If not, the system
may reject the attempt to remove it from everyone as that would leave no
SuperUsers.

Tim Thomas wrote:

Hmm, I have tried this with 2 log-ins including root (see attached)
and no luck. Any other suggestions, or thoughts on manually revoking
this in the DB?

Thanks,
Tim



Just made a test: granted everyone with SuperUser, then revoked it and
everything went fine. I do believe that RT can refuse such operation
if user has no personal SuperUser right when you’re revoking global.

We are refining our security needs now as we expand, and want to
revoke the global “superuser” right for the group “everyone”, but RT
refuses to revoke that right. I am logged in as root, and are using
RT 3.8.1. Any suggestions short of going into the database to change
this directly?

Thanks,
Tim



http://lists.bestpractical.com/cgi-bin/mailman/listinfo/rt-users

Community help: http://wiki.bestpractical.com
Commercial support: sales@bestpractical.com

Discover RT’s hidden secrets with RT Essentials from O’Reilly Media.
Buy a copy at http://rtbook.bestpractical.com

Drew Barnes
Applications Analyst
Network Resources Department
Raymond Walters College
University of Cincinnati

Yes, my user and root both have global superuser rights granted.On Oct 29, 2008, at 8:35 AM, Drew Barnes wrote:

Are any users explicitly granted SuperUser rights? If not, the
system may reject the attempt to remove it from everyone as that
would leave no SuperUsers.

Tim Thomas wrote:

Hmm, I have tried this with 2 log-ins including root (see attached)
and no luck. Any other suggestions, or thoughts on manually
revoking this in the DB?

Thanks,
Tim

On Oct 28, 2008, at 12:43 PM, Ruslan Zakirov wrote:

Just made a test: granted everyone with SuperUser, then revoked it
and
everything went fine. I do believe that RT can refuse such operation
if user has no personal SuperUser right when you’re revoking global.

On Tue, Oct 28, 2008 at 5:11 PM, Tim Thomas <tthomas@local-motors.com wrote:

We are refining our security needs now as we expand, and want to
revoke the global “superuser” right for the group “everyone”, but
RT
refuses to revoke that right. I am logged in as root, and are
using
RT 3.8.1. Any suggestions short of going into the database to
change
this directly?

Thanks,
Tim