On Mon, Jan 19, 2009 at 11:35 PM, Alan Altmark <[email protected]> wrote:

> :-)  I agree that it is messy.  That's the "reducation" (I meant
> "reduction") I was talking about.... things that map uids to usernames.
> They get confused.  Anything that tests for a username of 'root' is broken
> already!

That reverse mapping is happening everywhere in Linux. Should we take
"useradd" being unwilling to do so as an omen? Sure, it's just text so
hand-edit the passwd and shadow files (yes, we can).

So do we conclude that using multiple accounts with UID 0 is not a
good idea and certainly does not achieve what you wanted? On the
subject of UID: security gets a lot easier when you can have unique
name and UID across all your servers (that's where a central LDAP
helps a lot).

PS If you really want, you could look into MultiAdmin to do what you
tried.No idea how mature that is.

Rob - amateur security weeny

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

Reply via email to