home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!think.com!rpi!ghost.dsi.unimi.it!univ-lyon1.fr!not-for-mail
- From: Christophe.Wolfhugel@grasp.insa-lyon.fr (Christophe Wolfhugel)
- Newsgroups: comp.unix.aix
- Subject: passwd -f not resseting uid before exec ? (3.2)
- Date: 4 Jan 1993 19:29:44 +0100
- Organization: INSA Informatique, Lyon, France
- Lines: 17
- Message-ID: <1i9vmoINNs7r@grasp1.univ-lyon1.fr>
- NNTP-Posting-Host: grasp1.univ-lyon1.fr
- Summary: AIX and security, comme back another day...
-
- It is our policy not to allow users to change their GECOS field.
- But with 3.2, I did not find a solution to succeed.
-
- I have modified access rights to chfn acordingly. A simple user can't
- execute it anymore.
-
- BUT... "passwd -f" does a call of chfn, and it succeeds. So I
- guess that it does forget to reset the UIDs
- before calling the chfn.
-
- Is there any usable solution ?
-
- Are there other such jokes in AIX password handling ?
-
- --
- Christophe Wolfhugel | Email: Christophe.Wolfhugel@grasp.insa-lyon.fr
- "Premier reve de 93: l'Europe, un cauchemar."
-