创建 UID < 500 的普通用户有什么危险?

Jef*_*eff 15 users rhel

创建 UID < 500 的普通用户有什么危险?假设 UID 不是现有 UID 的重复项,会出现什么问题?

这不是我想做的事情,而是我亲眼所见并想知道为什么不应该做的事情。在这个例子中,它在 RHEL5 上。

slm*_*slm 18

我不相信有任何固有的风险,这样做只是为了在被认为是系统帐户和用户帐户之间创建分离。根据我的经验,使用 500 以下数字的做法是一种 Redhat 主义,实际上仅此而已。

在 Solaris 上,我也看到用户被分配了从 100 开始的编号,但几年后才发现,将 2 个较小部门的系统合并在一起会导致各种噩梦,因为 2 个部门中有多个用户具有相同的 UID /GID 已分配。

这确实是分配 UID 时的主要风险/头痛。由于 UID 是最终写入用户给定文件/目录的 inode 的内容,因此您不希望一直执行大量find查找 UID 1234 拥有的文件并且必须将它们更改为 5678 .

因此,通过对 UID 的选择进行一些思考,管理员可以避免以后的麻烦。

使用 500 及以上只是 Redhat(和其他 Unix)尝试为自己提供足够的缓冲区,以便可能需要创建的任何系统帐户不会与分配给用户的 UID 混合。

/etc/login.defs

顺便提一下,数字 500 是由配置文件/etc/login.defs.

#
# Min/max values for automatic uid selection in useradd
#
UID_MIN           500
UID_MAX         60000

#
# Min/max values for automatic gid selection in groupadd
#
GID_MIN           500
GID_MAX         60000
Run Code Online (Sandbox Code Playgroud)

如果您想通过useradd/adduser命令覆盖默认行为,您可以将其更改为您想要的任何内容。

用户添加手册页

如果您查看useradd手册页,您会注意到这一部分讨论了 GID 的默认值,但此评论也适用于 UID:

摘抄

-g, --gid GROUP
    The group name or number of the user´s initial login group. The group name 
    must exist. A group number must refer to an already existing group.

    If not specified, the behavior of useradd will depend on the USERGROUPS_ENAB 
    variable in /etc/login.defs. If this variable is set to yes 
    (or -U/--user-group is specified on the command line), a group will be 
    created for the user, with the same name as her loginname. If the variable 
    is set to no (or -N/--no-user-group is specified on the command line), 
    useradd will set the primary group of the new user to the value specified by 
    the GROUP variable in /etc/default/useradd, or 100 by default.
Run Code Online (Sandbox Code Playgroud)

系统账号

useradd手册页中需要注意的另一件事是关于系统帐户生成的这一点。

摘抄

-r, --system
    Create a system account.

    System users will be created with no aging information in /etc/shadow, 
    and their numeric identifiers are choosen in the SYS_UID_MIN-SYS_UID_MAX 
    range, defined in /etc/login.defs, instead of UID_MIN-UID_MAX (and their 
    GID counterparts for the creation of groups).

    Note that useradd will not create a home directory for such an user, 
    regardless of the default setting in /etc/login.defs (CREATE_HOME). You 
    have to specify the -m options if you want a home directory for a system 
    account to be created.
Run Code Online (Sandbox Code Playgroud)

正是这种方法 ( useradd -r ...) 经常被脚本使用,它在安装包时被合并到各种包管理器中,例如 RPM。以这种方式编写脚本允许系统在给定系统上自动选择下一个可用的 UID/GID,而不会有踩到已经分配给系统用户的 UID/GID 的风险。