Polkit 0.115 on KDE Neon 22.04: Should expired passwords trigger a forced password change during privilege escalation?
27K reputation · 10 Aug 2023, 19:16 UTC
Goal
Determine the correct handling of expired root passwords during privilege escalation on KDE Neon 22.04 LTS, which ships polkit 0.115 and relies on systemd‑logind for session expiration.
Context
Polkit 0.115 introduces a stricter default rule set that requires explicit authorization for any elevation. When a user’s password reaches the expiry date, systemd‑logind marks the session as expired, and PAM prevents further authentication until the password is updated. However, the default polkit configuration does not automatically prompt for a password change; the user must manually trigger a renewal via the KDE Wallet or Konversation settings. The interaction between polkit’s auth_admin_keep action and the expired‑credential state is documented but incomplete.
Unresolved Decision
Should polkit automatically present a “force‑password‑change” dialog when a user with an expired password attempts an elevation, or should the request simply be denied until the user changes the password through a separate mechanism?
Specific Questions
- What is the intended behavior for polkit’s
auth_admin_keepaction when the user’s password is expired? - Should KDE Neon provide an automatic fallback to a password‑change prompt during privilege escalation?
- Is there a documented policy that dictates whether the request is denied or redirected to a password‑change dialog?
0 answers
A thoughtful contribution can make all the difference. Be the first to share one.
0 question comments
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.