tailieunhanh - Practical UNIX & Internet Security phần 5

Có hai trường hợp ngoại lệ khi có nhiều tên người dùng với cùng một UID là hợp lý. Đầu tiên là đăng nhập được sử dụng cho hệ thống UUCP. Trong trường hợp này, nó là mong muốn có nhiều thông tin đăng nhập UUCP với mật khẩu và tên người dùng khác nhau, nhưng tất cả đều có cùng một UID. | Chapter 4 Users Groups and the Superuser Multiple Accounts with the Same UID Simpo PDF Merge and Split Unregistered Version - http There are two exceptions when having multiple usernames with the same UID is sensible. The first is for logins used for the UUCP system. In this case it is desirable to have multiple UUCP logins with different passwords and usernames but all with the same UID. This allows you to track logins from separate sites but still allows each of them access to the shared files. Ways of securing the UUCP system are described in detail in Chapter 15 UUCP. The second exception to the rule about only one username per UID is when you have multiple people with access to a system account including the superuser account and you want to track their activities via the audit trail. By creating separate usernames with the same UID and giving the users access to only one of these identities you can do some monitoring of usage. You can also disable access for one person without disabling it for all. As an example consider the case where you may have three people helping administer your Usenet news software and files. The password file entry for news is duplicated in the etc passwd file as follows root zPDeHbougaPpA 0 1 Operator bin ksh nobody 60001 60001 tmp daemon 1 1 tmp ftp 3 3 FTP User usr spool ftp news 6 6 usr spool news bin csh newsa 6 6 News co-admin Sabrina usr spool news bin csh newsb ABll2qmPi fty 6 6 News co-admin Rachel usr spool news bin sh newsc x qnr4sa70uQz 6 6 News co-admin Fred usr spool news bin ksh Each of the three helpers has a unique password so they can be shut out of the news account if necessary without denying access to the others. Also the activities of each can now be tracked if the audit mechanisms record the account name instead of the UID most do as we describe in Chapter 10 Auditing and Logging . Because the first entry in the passwd file for UID 6 has the account name news any listing of

TỪ KHÓA LIÊN QUAN