GNOME desktop block plus opt-in GNOME hardening #21
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Discussion
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Help Wanted
Status
Need More Info
Prio - Hoog
Prio - Laag
Prio - Middel
styling
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
MinBZK/DAWO-NixOS#21
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The image ships Plasma; some workplaces want GNOME. Propose two blocks following
the #8 interface:
desktop-gnome(GDM) as an alternative a host selects, gated ondawo.desktop.gnome.enableso importing the block does not force GNOME on everyhost.
hardening-gnome, opt-in (hardened tier, default off), shipping a locked dconfprofile: automatic screen lock, privacy (no recent-file history, clean trash and
temp), and lockdown (no user switching, no command line). Keys are locked so a
user cannot relax them. Only meaningful with
desktop-gnome. Norm: NCSCend-user device plus CIS GNOME.
Question: do you want GNOME as a first-class alternative desktop in the core, or
should desktops live in the per-organisation consumer repos and the core stay
desktop-agnostic? PR follows once the direction is clear.
@bram.buijs wrote in #21 (comment):
I see GNOME and Plasma as equally mature projects and in the Open-Source spirit I'd like to offer the choice to organizations.
I would, however, like to suggest that we keep Plasma and GNOME mutually exclusive on a system as their
.configfiles might influence each other and could wreak havoc on a user account when both are used.I would also like to point out that the GNOME interface might feel more at home to Linux or Apple native users while Plasma in the current deployment feels more at home to Windows native users. This might add the the load in documentation in support when supporting both DE's.
@rutger.putter Is it okay to move KDE to a module (opt-out) and make gnome a seperate module (opt -in) with a warning not to install both at once. This would allow us to have them both co-exist in the repo without interfering with eachother