sysmaint - System Maintenance User
Jump to navigation
Jump to search
Install Software
Documentation
Printing and Scanning
Previous page: Install Software
Index page: Documentation
Next page: Printing and Scanning
sysmaint - System Maintenance User
- Overview: Whonix specific
sysmaintaccount documentation and default installation status differences. - Default: Whonix LXQt comes with
user-sysmaint-splitby default. - Accounts: There are two accounts:
user: For daily activities.sysmaint: For system maintenance administrative activities, such as installing software or upgrading.
- Security rationale: This is a security feature. ( rationale
) - Administrative access: Boot into the
sysmaintsession. This is the recommended way to perform administrative tasks, to run tools such assudoorpkexec. - Troubleshooting: If you see the following errors, you are most likely in the
usersession:
permission denied: sudo
permission denied: pkexec
- Fix: Reboot into the
sysmaintsession and run administrative commands there. - Unrestricted Admin Mode: The opposite of
user-sysmaint-splitis Unrestricted Admin Mode
, which users can opt in to enable. This is generally not recommended, because it removes the security benefits of user-sysmaint-split. - Older versions: For older versions, refer to Version Overview for upgrade information.
Screenshot
[edit]Image: Whonix-Workstation - sysmaint Boot Option in GRUB boot menu
Image: Whonix-Workstation - sysmaint Boot Option in Qubes VM Manager (QVMM)
Version Overview
[edit]| Feature | Whonix-Workstation LXQt (GUI) | Whonix-Gateway LXQt (GUI) | Whonix-Workstation CLI | Whonix-Gateway CLI |
|---|---|---|---|---|
user-sysmaint-split
|
Yes, default in new images. | Yes, default in new images. | No, not default. | No, not default. |
| Old Versions | No, not auto-installed (to avoid breaking workflows). | No, not auto-installed (to avoid breaking workflows). | No, not applicable (remains sudo passwordless by default).
|
No, not applicable (remains sudo passwordless by default).
|
| New Images | Yes, includes user-sysmaint-split by default.
|
Yes, includes user-sysmaint-split by default.
|
No, does not include user-sysmaint-split.
|
No, does not include user-sysmaint-split.
|
| 17 to 18 Release Upgrade | No, does not auto-install user-sysmaint-split.
|
No, does not auto-install user-sysmaint-split.
|
No, does not include user-sysmaint-split.
|
No, does not include user-sysmaint-split.
|
| Opt-Out | Yes, via Unrestricted Admin Mode |
Yes, via Unrestricted Admin Mode |
Yes | Yes |
| Opt-In | Yes, can be installed anytime. | Yes, can be installed anytime. | Yes | Yes |
user-sysmaint-split - Whonix-Workstation versus Whonix-Gateway - Default Installation Status Differences
[edit]In the past, in earlier versions, there have been differences between Whonix-Workstation and Whonix-Gateway. [1] There are no more differences since Whonix 18. [2]
user-sysmaint-split - GUI vs CLI - Default Installation Status Differences
[edit]- Default installation status:
user-sysmaint-splitdefault installation status (installed by default versus not installed by default) differs between the graphical user interface (GUI) and command line interface (CLI) versions. - Future direction: In the future, the CLI version will be improved to be more suitable for servers.
- Server support: Server support for
user-sysmaint-splitis not yet as sophisticated as it is for the GUI version. - Server use cases: For some server use cases,
user-sysmaint-splitmay be less needed or unnecessary. - Further reading: This topic is elaborated in the development chapter
user-sysmaint-splitServer Support
.
- Server support: Server support for
Upstream
[edit]
Footnotes
[edit]We believe security software like Whonix needs to remain open source and independent. Would you help sustain and grow the project? Learn more about our 13 year success story and maybe DONATE!



