1 |
On Fri, 2006-06-16 at 08:42 -0500, Grant Goodyear wrote: |
2 |
> Mike Kelly wrote: [Thu Jun 15 2006, 08:36:25PM CDT] |
3 |
> > As part of my original plans for my GLEP27 implementation, I was |
4 |
> > going to have my scripts automatically add the users requested by a |
5 |
> > package (for example, the cron user), to all the passwd backends |
6 |
> > listsed in /etc/nsswitch.conf. However, in consultation with some |
7 |
> > folks, it seems that what may be more desirable is to just add |
8 |
> > users/groups to the local files/compat backends instead, and not make |
9 |
> > any changes to the remote databases. |
10 |
> > |
11 |
> > Does anyone have any strong notion of any cases where it would be |
12 |
> > excessively bad for the package manager to try adding to, say, the |
13 |
> > nss_nis backend in addition to the nss_files backend, or cases where |
14 |
> > that would be a strongly desired behavior? |
15 |
> |
16 |
> I think it's unlikely that one would want to add an account to both |
17 |
> files and nis/ldap, but there's no good reason that I can think of not |
18 |
> to let the user choose. That said, I'm not exactly an uber-sysadmin. |
19 |
> One thing that I might think would be common, though, would be to have |
20 |
> system accounts pre-defined in ldap/nis, with the expectation that your |
21 |
> scripts would look up the remote values and then create local accounts |
22 |
> with those values. Anybody who actually has a clue want to chime in? |
23 |
|
24 |
Most things *should* not to *anything* if the account exists in |
25 |
mysql/ldap/nis/etc as the account is already present. It's just the |
26 |
case of it *not* existing that causes the real problem. |
27 |
|
28 |
> |
29 |
> Oh, it might be a good idea to ask in gentoo-server@g.o, too. |
30 |
> |
31 |
> -g2boojum- |
32 |
-- |
33 |
Chris Gianelloni |
34 |
Release Engineering - Strategic Lead |
35 |
x86 Architecture Team |
36 |
Games - Developer |
37 |
Gentoo Linux |