Subject: Re: CVS commit: src/etc
To: Jachym Holecek <freza@liberouter.org>
From: Luke Mewburn <lukem@NetBSD.org>
List: tech-security
Date: 04/07/2005 10:58:07
--Z/kiM2A+9acXa48/
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Thu, Apr 07, 2005 at 02:54:06AM +0200, Jachym Holecek wrote:
| > Generally, yes, although we'd need to consider any deviations away
| > from our new general policy of
| > ``namespace protecting per service user (and group) names
| > with a leading `_' to prevent nameclashes with user accounts
| > on end user systems.''
|=20
| Just curious:
|=20
| - Do such clashes occur really often enough to require special policy?
At least one user reported there being a problem with a `squid' user
in the past. I know of a couple of people (including myself) who
had a conflict when NetBSD added a `named' and `ntpd' user.
| - Is leading underscore in login name guaranteed to not clash with exis=
ting
| account names on end systems? Perhaps one of the characters discourag=
ed
| by passwd.conf(5) would be a better candidate?
No, but it's good prior art from FreeBSD/OpenBSD.
At least, in my 15 years involved in system administration across
a diverse range of sites I've never seen the practice before.
| - Will this policy extend to system users and groups added via Pkgsrc?
That for tech-pkg to consider, but I would suggest that 'yes' is the
answer.
--Z/kiM2A+9acXa48/
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (NetBSD)
iD8DBQFCVIWfpBhtmn8zJHIRAoX6AKCyo1qty1ttSeHj04A3QnKcP0mH7QCeM15Z
TvKShzre/oZPzdSv4VL2R9E=
=W1QE
-----END PGP SIGNATURE-----
--Z/kiM2A+9acXa48/--