Gentoo Archives: gentoo-dev

From: Marc Schiffbauer <mschiff@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Determenistic system group and user id
Date: Sun, 13 Dec 2015 23:46:27
Message-Id: 20151213234605.GB32338@schiffbauer.net
In Reply to: Re: [gentoo-dev] Determenistic system group and user id by Alec Warner
1 * Alec Warner schrieb am 13.12.15 um 23:23 Uhr:
2 [...]
3 > I never understood why people would think the distro should handle unique
4 > gid / uids. Plus you usually end up running:
5 >
6 > 1) More than one distro.
7
8 not in most places
9
10 > 2) More than one 'flavor' of a single distro where for whatever reason, uid
11 > and gid decisions differed (they renumbered, etc.)
12 >
13 > So if you want a consistent GID for a group, store the group name and gid
14 > in ldap and sync it; do not rely on your distro to do it. IMHO doing so is
15 > a design error.
16
17 I disagree here. Most (enterprise) environments use just one distro. And
18 its just very useful if you have sticky UIDs for daemon users for
19 example.
20
21 One example: You build an apache two-node cluster using DRBD (and
22 pacemaker...). If you happen to install some daemons in random order on
23 both nodes you might end up with apache having different UIDs which will
24 break things. This is a PITA.
25
26 ANd you do not want another central LDAP-Cluster just to have apache
27 UIDs in sync ;)
28
29 Red Hat for example has unique distro UIDs for many years now.
30
31 I would strongly vote for making GLEP27 reality. It makes life easier in
32 many places.
33
34 -Marc
35
36 --
37 0x35A64134 - 8AAC 5F46 83B4 DB70 8317
38 3723 296C 6CCA 35A6 4134

Attachments

File name MIME type
signature.asc application/pgp-signature