创建 UID < 500 的普通用户有什么危险?假设 UID 不是现有 UID 的重复项,会出现什么问题?
这不是我想做的事情,而是我亲眼所见并想知道为什么不应该做的事情。在这个例子中,它在 RHEL5 上。
slm*_*slm 18
我不相信有任何固有的风险,这样做只是为了在被认为是系统帐户和用户帐户之间创建分离。根据我的经验,使用 500 以下数字的做法是一种 Redhat 主义,实际上仅此而已。
在 Solaris 上,我也看到用户被分配了从 100 开始的编号,但几年后才发现,将 2 个较小部门的系统合并在一起会导致各种噩梦,因为 2 个部门中有多个用户具有相同的 UID /GID 已分配。
这确实是分配 UID 时的主要风险/头痛。由于 UID 是最终写入用户给定文件/目录的 inode 的内容,因此您不希望一直执行大量find查找 UID 1234 拥有的文件并且必须将它们更改为 5678 .
因此,通过对 UID 的选择进行一些思考,管理员可以避免以后的麻烦。
使用 500 及以上只是 Redhat(和其他 Unix)尝试为自己提供足够的缓冲区,以便可能需要创建的任何系统帐户不会与分配给用户的 UID 混合。
顺便提一下,数字 500 是由配置文件/etc/login.defs.
#
# Min/max values for automatic uid selection in useradd
#
UID_MIN 500
UID_MAX 60000
#
# Min/max values for automatic gid selection in groupadd
#
GID_MIN 500
GID_MAX 60000
Run Code Online (Sandbox Code Playgroud)
如果您想通过useradd/adduser命令覆盖默认行为,您可以将其更改为您想要的任何内容。
如果您查看useradd手册页,您会注意到这一部分讨论了 GID 的默认值,但此评论也适用于 UID:
摘抄
-g, --gid GROUP
The group name or number of the user´s initial login group. The group name
must exist. A group number must refer to an already existing group.
If not specified, the behavior of useradd will depend on the USERGROUPS_ENAB
variable in /etc/login.defs. If this variable is set to yes
(or -U/--user-group is specified on the command line), a group will be
created for the user, with the same name as her loginname. If the variable
is set to no (or -N/--no-user-group is specified on the command line),
useradd will set the primary group of the new user to the value specified by
the GROUP variable in /etc/default/useradd, or 100 by default.
Run Code Online (Sandbox Code Playgroud)
useradd手册页中需要注意的另一件事是关于系统帐户生成的这一点。
摘抄
-r, --system
Create a system account.
System users will be created with no aging information in /etc/shadow,
and their numeric identifiers are choosen in the SYS_UID_MIN-SYS_UID_MAX
range, defined in /etc/login.defs, instead of UID_MIN-UID_MAX (and their
GID counterparts for the creation of groups).
Note that useradd will not create a home directory for such an user,
regardless of the default setting in /etc/login.defs (CREATE_HOME). You
have to specify the -m options if you want a home directory for a system
account to be created.
Run Code Online (Sandbox Code Playgroud)
正是这种方法 ( useradd -r ...) 经常被脚本使用,它在安装包时被合并到各种包管理器中,例如 RPM。以这种方式编写脚本允许系统在给定系统上自动选择下一个可用的 UID/GID,而不会有踩到已经分配给系统用户的 UID/GID 的风险。
| 归档时间: |
|
| 查看次数: |
24561 次 |
| 最近记录: |