Re: Recommend Linux Distro, Mail/MTA/FTP daemon?

From: Nico Kadel-Garcia (nkadel_at_comcast.net)
Date: 10/14/03


Date: Tue, 14 Oct 2003 08:03:45 -0400

The little lost angel wrote:

> On Mon, 13 Oct 2003 23:50:29 -0400, Nico Kadel-Garcia
> <nkadel@comcast.net> wrote:
>
>
>>In theory, yes. In practice, it means you can't use the "passwd"
>>command, or integrate it easily with throwaway accounts and file
>>ownership. The proftpd alternate passwd file structure had to maintained
>>by hand using cut+paste and tools like "htpasswd" for generating new
>>encrypted passwords.
>
>
> Erm, that's not the way I was planning to do it :P
>
> Because pureftpd supports mySQL DB, the user/password file appears to
> be just a simple table. So it appears to be relatively easy to cook up
> a php/mySQL web front end for this sort of admin. :P
>
> If I had to do in some shell script, it will probably bomb though :P

Gack. "It can't use the standard tool that's existed in UNIX since it's
first release, so I'll write a custom front end to replace that, in
MySQL and HTML, and make it as secure and reliable."

This is why I like "passwd" and "useradd". They're simple and have been
tested out fairly robustly, and are likely to continue working.

>>Oh, goodness, you don't *give* them shell access. The shell is set to
>>/bin/false or /sbin/nologin: but as a root user, with the FTP user in
>>front of you, you can have them type in the password themselves using
>>the "passwd username" command, rather than doing other more awkward steps.
>
>
> Erm, wasn't going to be around to meet the users for this sort of
> thing. Was planning to do up a web front end, whether they are in
> Mongolia, Timbuktu or Antartica, they just log up the front end and
> change passwords or add users for their virtual domains :P

I don't let them touch my FTP server remotely for manipulating their
accounts. And writing secure, reliable CGI to manipulate user accounts
remotely makes me really, really twitchy.

> but if I tried to input ab or hit enter, it just doesn't go anywhere.

??? I work from the command line, and have never been asked something
like this. What in the heck were you using?

> In the end, I thought it was be in quotes or something and did 'ab'
> which worked, but wasn't what I wanted. Had to delete the user and
> after a few tries realized, the user name cannot be the same as the
> name I use for useradd... it's kinda DUH or is it just ME? :P

That's kind of duh, yes. This does not sound like the "useradd" tool
that *I* use....



Relevant Pages

  • Re: useradd/adduser
    ... Yes, with the pwcommand. ... If your scripts gain knowledge of the ... passwords for accounts somewhere, you can feed the passwords to pw ...
    (FreeBSD-Security)
  • Re: password expiration policy for admin and system accounts ?
    ... policy that Admins manually reset these important account passwords every ... You can still have the passwords set to never expire, ... > Privileged accounts should be the most, not the least, well guarded. ...
    (microsoft.public.security)
  • Re: password expiration policy for admin and system accounts ?
    ... policy that Admins manually reset these important account passwords every ... You can still have the passwords set to never expire, ... > Privileged accounts should be the most, not the least, well guarded. ...
    (microsoft.public.win2000.security)
  • RE: Security Logging - Passwords & Accounts
    ... Security Logging - Passwords & Accounts ... Does anybody know of any way to log changes to user & group accounts and ...
    (RedHat)
  • Antivirus programs for XP - best ones?
    ... DON'T create user accounts during setup as they will become ... Turn of transmission of passwords and user credentials in clear ... Keep your system and ALL installed applications uptodate (Microsoft ...
    (alt.computer.security)