Curt Sampson wrote:

On 2009-02-24 01:19 +0900 (Tue), Nikolay Elenkov wrote:

From 9 on, Fedora uses PolicyKit ([1]) to grant authorizations to (most) GUI apps. The config utility is in

Ah, I see. It turns out that Ubuntu 8.10 has this too. Pretty cool, in some ways.

So the issue here may just be that Ubuntu requires "authorization"
(and that the user be in some appropriate admin group), whereas Fedora
requires "admin authorization"?

Seems to be just a matter of default security policy. I've set most things to 'Authentication' so it behaves almost the same as sudo.

Does Fedora have a way of restricting
users who know the root password from doing admin tasks, a la the way
BSD systems won't let a user su if there are users in the wheel group
and that user is not?

If authorizations are set to 'Authentication' for PolicyKit, entering the root password simply doesn't work. Combined with that
should cover it. You might also want to get rid of the '(Admin) Authentication (keep indefinitely)' authorizations which are the default for quite a lot of actions (otherwise actions 'just work' after you've run them once successfully).

