From owner-freebsd-security Mon Aug 13 10:38: 9 2001 Delivered-To: freebsd-security@freebsd.org Received: from webs1.accretive-networks.net (webs1.accretive-networks.net [207.246.154.13]) by hub.freebsd.org (Postfix) with ESMTP id ACD2237B40D for ; Mon, 13 Aug 2001 10:38:05 -0700 (PDT) (envelope-from davidk@accretivetg.com) Received: from localhost (davidk@localhost) by webs1.accretive-networks.net (8.11.1/8.11.3) with ESMTP id f7DGX7l46656; Mon, 13 Aug 2001 09:33:12 -0700 (PDT) Date: Mon, 13 Aug 2001 09:33:07 -0700 (PDT) From: David Kirchner X-X-Sender: To: Ivan Krstic Cc: Subject: Re: bin user In-Reply-To: <20010813193429.Z3889@gnjilux.cc.fer.hr> Message-ID: <20010813093238.B38221-100000@localhost> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Mon, 13 Aug 2001, Ivan Krstic wrote: > On Mon, Aug 13, 2001 at 01:26:44PM -0400, alexus wrote: > > is it safe to allow user bin have shell but with password that no one will > > know? > > [snip] > If the only reason to give the bin user a shell is so you can su to this > account, there's no need to assign a password at all. It'd probably be better to leave the shell as /sbin/nologin, and then just use 'su -m bin' to su to bin. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message