1 |
Mike Kelly wrote: [Thu Jun 15 2006, 08:36:25PM CDT] |
2 |
> As part of my original plans for my GLEP27 implementation, I was |
3 |
> going to have my scripts automatically add the users requested by a |
4 |
> package (for example, the cron user), to all the passwd backends |
5 |
> listsed in /etc/nsswitch.conf. However, in consultation with some |
6 |
> folks, it seems that what may be more desirable is to just add |
7 |
> users/groups to the local files/compat backends instead, and not make |
8 |
> any changes to the remote databases. |
9 |
> |
10 |
> Does anyone have any strong notion of any cases where it would be |
11 |
> excessively bad for the package manager to try adding to, say, the |
12 |
> nss_nis backend in addition to the nss_files backend, or cases where |
13 |
> that would be a strongly desired behavior? |
14 |
|
15 |
I think it's unlikely that one would want to add an account to both |
16 |
files and nis/ldap, but there's no good reason that I can think of not |
17 |
to let the user choose. That said, I'm not exactly an uber-sysadmin. |
18 |
One thing that I might think would be common, though, would be to have |
19 |
system accounts pre-defined in ldap/nis, with the expectation that your |
20 |
scripts would look up the remote values and then create local accounts |
21 |
with those values. Anybody who actually has a clue want to chime in? |
22 |
|
23 |
Oh, it might be a good idea to ask in gentoo-server@g.o, too. |
24 |
|
25 |
-g2boojum- |
26 |
-- |
27 |
Grant Goodyear |
28 |
Gentoo Developer |
29 |
g2boojum@g.o |
30 |
http://www.gentoo.org/~g2boojum |
31 |
GPG Fingerprint: D706 9802 1663 DEF5 81B0 9573 A6DC 7152 E0F6 5B76 |