Changes in BOOK/boot/common/pwdgroup.xml [688b33d:c3b54fac]
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
BOOK/boot/common/pwdgroup.xml
r688b33d rc3b54fac 9 9 <?dbhtml filename="pwdgroup.html"?> 10 10 11 <title>Creating the passwd , group, and logFiles</title>11 <title>Creating the passwd and group Files</title> 12 12 13 13 <indexterm zone="ch-boot-pwdgroup"> … … 17 17 <indexterm zone="ch-boot-pwdgroup"> 18 18 <primary sortas="e-/etc/group">/etc/group</primary> 19 </indexterm>20 21 <indexterm zone="ch-boot-pwdgroup">22 <primary sortas="e-/var/run/utmp">/var/run/utmp</primary>23 </indexterm>24 25 <indexterm zone="ch-boot-pwdgroup">26 <primary sortas="e-/var/log/btmp">/var/log/btmp</primary>27 </indexterm>28 29 <indexterm zone="ch-boot-pwdgroup">30 <primary sortas="e-/var/log/lastlog">/var/log/lastlog</primary>31 </indexterm>32 33 <indexterm zone="ch-boot-pwdgroup">34 <primary sortas="e-/var/log/wtmp">/var/log/wtmp</primary>35 19 </indexterm> 36 20 … … 45 29 <screen><userinput>cat > ${CLFS}/etc/passwd << "EOF" 46 30 <literal>root::&uid-root;:&gid-root;:root:/root:/bin/bash</literal> 31 <literal>bin:x:&uid-bin;:&gid-bin;:/bin:/bin/false</literal> 32 <literal>daemon:x:&uid-daemon;:&gid-daemon;:/sbin:/bin/false</literal> 33 <literal>messagebus:x:&uid-messagebus;:&gid-messagebus;:D-Bus Message Daemon User:/dev/null:/bin/false</literal> 34 <literal>nobody:x:&uid-nobody;:&gid-nogroup;:Unprivileged User:/dev/null:/bin/false</literal> 47 35 EOF</userinput></screen> 48 36 … … 53 41 <variablelist os="c"> 54 42 55 <title>Additional users you may want to add :</title>43 <title>Additional users you may want to add if not already included:</title> 56 44 57 <varlistentry>58 <term><literal>bin:x:&uid-bin;:&gid-bin;:bin:/bin:/bin/false</literal></term>59 <listitem>60 <para>Can be useful for compatibility with legacy applications.</para>61 </listitem>62 </varlistentry>63 <varlistentry>64 <term><literal>daemon:x:&uid-daemon;:&gid-daemon;:daemon:/sbin:/bin/false</literal></term>65 <listitem>66 <para>It is often recommended to use an unprivileged User ID/Group ID67 for daemons to run as, in order to limit their access to the system.</para>68 </listitem>69 </varlistentry>70 45 <varlistentry> 71 46 <term><literal>adm:x:&uid-adm;:&gid-adm;:adm:/var/adm:/bin/false</literal></term> … … 104 79 </listitem> 105 80 </varlistentry> 106 <varlistentry>107 <term><literal>nobody:x:&uid-nobody;:&gid-nobody;:nobody:/:/bin/false</literal></term>108 <listitem>109 <para>Used by NFS</para>110 </listitem>111 </varlistentry>112 81 </variablelist> 113 82 … … 131 100 utmp:x:&gid-utmp;: 132 101 usb:x:&gid-usb;: 133 cdrom:x:&gid-cdrom;:</literal> 102 cdrom:x:&gid-cdrom;: 103 adm:x:&gid-adm;: 104 messagebus:x:&gid-messagebus;: 105 systemd-journal:x:&gid-systemd-journal;: 106 mail:x:&gid-mail;: 107 wheel:x:&gid-wheel;: 108 nogroup:x:&gid-nogroup;:</literal> 134 109 EOF</userinput></screen> 135 110 136 111 <variablelist os="d"> 137 112 138 <title>Additional groups you may want to add </title>113 <title>Additional groups you may want to add if not already included:</title> 139 114 140 <varlistentry>141 <term><literal>adm:x:&gid-adm;:root,adm,daemon</literal></term>142 <listitem>143 <para>All users in this group are allowed to do administrative tasks</para>144 </listitem>145 </varlistentry>146 115 <varlistentry> 147 116 <term><literal>console:x:&gid-console;:</literal></term> … … 154 123 <listitem> 155 124 <para>This group is allowed to use the CDRW drive</para> 156 </listitem>157 </varlistentry>158 <varlistentry>159 <term><literal>mail:x:&gid-mail;:mail</literal></term>160 <listitem>161 <para>Used by MTAs (Mail Transport Agents)</para>162 125 </listitem> 163 126 </varlistentry> … … 175 138 </varlistentry> 176 139 <varlistentry> 177 <term><literal>nogroup:x:&gid-nogroup;:</literal></term> 178 <listitem> 179 <para>This is a default group used by some programs that do not 180 require a group</para> 181 </listitem> 182 </varlistentry> 183 <varlistentry> 184 <term><literal>nobody:x:&gid-nobody;:</literal></term> 140 <term><literal>nobody:x:&gid-nogroup;:</literal></term> 185 141 <listitem> 186 142 <para>This is used by NFS</para> … … 190 146 191 147 <para os="e">The created groups are not part of any standard—they are 192 groups decided on in part by the requirements of the Eudevconfiguration148 groups decided on in part by the requirements of the Systemd configuration 193 149 in the final system, and in part by common convention employed by a 194 150 number of existing Linux distributions. The Linux Standard Base (LSB, … … 200 156 group's name.</para> 201 157 202 <para os="f">The <command>login</command>, <command>agetty</command>, and203 <command>init</command> programs (and others) use a number of log204 files to record information such as who was logged into the system and205 when. However, these programs will not write to the log files if they206 do not already exist. Initialize the log files and give them207 proper permissions:</para>208 209 <screen><userinput>touch ${CLFS}/var/run/utmp ${CLFS}/var/log/{btmp,lastlog,wtmp}210 chmod -v 664 ${CLFS}/var/run/utmp ${CLFS}/var/log/lastlog211 chmod -v 600 ${CLFS}/var/log/btmp</userinput></screen>212 213 <para>The <filename>/var/run/utmp</filename> file records the users214 that are currently logged in. The <filename>/var/log/wtmp</filename>215 file records all logins and logouts. The216 <filename>/var/log/lastlog</filename> file records when217 each user last logged in. The <filename>/var/log/btmp</filename> file218 records the bad login attempts.</para>219 220 158 </sect1>
Note:
See TracChangeset
for help on using the changeset viewer.