Re: System accounts with valid shells

2013-11-01 Thread Phillip Susi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 reopen 274229 thanks On 11/1/2013 3:42 PM, Russ Allbery wrote: > Phillip, given the above background, would you be willing to modify > the libuuid package to use /bin/false or /usr/sbin/nologin instead > of /bin/sh for the shell for the libuuid user?

Re: System accounts with valid shells

2013-11-01 Thread Russ Allbery
Colin Watson writes: > However, there's an awkward problem blocking the change, namely #184979. > The last time I made any change to passwd.master or group.master that > caused update-passwd to prompt everyone to accept it was in December > 2004. Since then, the policy manual has been updated to

Re: System accounts with valid shells

2013-11-01 Thread Colin Watson
severity 184979 important block 274229 by 184979 thanks On Fri, Nov 01, 2013 at 09:26:15AM -0700, Russ Allbery wrote: > Even if the risk is low, I see absolutely no reason why these accounts > should have valid shells, and therefore don't understand why we wouldn't > want to just change them to /u