4 ms·
Challenge accepted! - Here's how needless Unix users is: Every fresh server install, I have to make up a meaningless string called the 'login' of an 'admin us
by divtxt 15y ago
Challenge accepted!
- Here's how needless Unix users is:
Every fresh server install, I have to make up a meaningless string called the 'login' of an 'admin user' who belongs to a 'group' called 'admin'. Once upon a time, I could use the well known admin login 'root'. Now that's not allowed. I have to make up a name, remember this name when you connect and then remember to prefix every command with sudo.
- Here's a better way of doing it:
Give me a server distro where I don't need a 'login'.
Meanwhile, why is apache pretending to be a 'user' called 'nobody'/'http' and not using some 'capabilities' or some shit like that?!!!!
- StavrosK 15y agoNobody forces you to use a login, you can use the root account with a blank password on your server if you like, it will do exactly what you want...
- adestefan 15y agoYou don't even have to do that. You can replace init with whatever you want and you'll never see a login prompt.
- dspillett 15y ago> Every fresh server install, I have to make up a meaningless string called the 'login' If you are only doing the occasional install then this really shouldn't be a great hardship. If you are installing many servers you should have this part automated. And ti shouldn't be meaningless either. I think you are doing it wrong. > Once upon a time, I could use the well known admin login 'root'. You still can. root login can always be reenabled if you want it that badly. There is also "sudo su" (unless explicitly disabled by your admins) to avoid repeated invocations of sudo while you are performing a long admin task. > - Here's a better way of doing it: > Give me a server distro where I don't need a 'login'. No, no, and thrice no. Far too many newbies will leave it in that state and get hacked to buggery in short order. Even if it is only for local console logins, I'd consider it a bad idea. No matter how inconvenient it is, server install should default to an insecure state and allowing access without authentication is such a state. Live CDs often do this, but they are not production systems. > Meanwhile, why is apache pretending to be a 'user' Well that much is a valid point. There has been work in this area but non of it has made its way to default setups of most unix-a-like systems.
- divtxt 15y agoHere's a simple thought experiment: Imagine a distro that changed the terms 'login/password' to 'password1/password2' No commands you type would change, but you'd wonder why the password is in 2 parts. That's how redundant user is!
- seabee 15y agoCute, except that password1 has to be unique. Hope you like confusing some of your users. You'd be better off getting rid of the login altogether and using a GUID. People still share computers, you know.
- divtxt 15y agoUniqueness is not an issue - see my original point - we only create one admin user on servers! Imagine a team of 3 people running a SaaS webapp on 3 web servers & 1 db server. I guarantee no one will waste their time creating 3 'users' on each server i.e. 3x4 = 12 'users' on that cluster.
- ebiester 15y agoIt's really nice having separate users in production for a server. That way, you log sudo and know who issued an admin command. But in a larger system, you don't worry about setting them up on each server; instead, you rely on LDAP. Unix is the LISP of server operating systems. It's a multiplier. In return, it demands much more from the operator. This is not ideal for a desktop system. It's amazing when you have an admin who knows his shit.
- divtxt 15y agoLDAP is a sensible suggestion. Why can't we still kill the local login i.e. directly map LDAP user -> permissions instead of LDAP user -> local 'user' -> permissions.
- 15y ago
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- Cushman 15y agoAside from security, I think what this indicates (and maybe this is fundamental to computers?) is that Unix doesn't understand that sometimes users will lie. Some of the time when I say `rm -rf` (or run a process which contains that command somewhere) I want to delete the indicated directory, but some of the time I actually don't. I'm lying. Unix knows who I am, and it knows what I want to do, but it has no way of knowing how much. The way we get around this is by inventing an imaginary person called "root" who always actually wants what they say they want. On the other end, the imaginary person "nobody" almost never actually wants to do anything. This is obviously a half-solution, and it shouldn't be surprising that it causes weird workflow problems.
- vacri 15y agoYou've already received a few answers here, but one that seems to have been missed: Use something other than ubuntu. Although there may be others out there, I'm unaware of any other distro that disables root. Complaining about disabling root is an ubuntu-specific complaint - it doesn't apply to linux in general, let alone unix. Also, if you don't like using passwords, copy-ssh-id is your friend. As for apache, I don't play with it much so I can't comment there. It certainly scares me :)
- divtxt 15y agoHere's an example showing how a human user does not require a local unix user of each server: Jack starts Apache on one of the web servers: $ ssh jack@web4.example.com Password: secret123 [_x_@web4] $ sudo /usr/bin/apachectl start # or similar [_x_@web4] $ logout Now, there are 2 possible values for '_x_': A) 'jack' - because there's a unix user 'jack' (what we have today) B) 'sysadmin' - because there's no unix user 'jack' - only an entry in /etc/sshpasswd B is the same as A as long as you update auditing to trace the Apache start to the jack/secret123 combo. Sidenote: wow this thread blew up!