Re: How to change the unix passwd from 4gl /SPL
Posted in 1996
Terry Gauchat wrote: > > I also recommend a stored procedure call over SPC, since we know any > Informix client can call a stored procedure with no new front-end > pieces. > > However, I'd recommend against writing a C program which directly > modifies the passwd/shadow file. > > Instead, according (with much thanks to Lester Knutsen, who responded > to my earlier question), try the public domain utility to interact > with TTY programs (such as "passwd") called "Expect". > BZZZT. Nope Dont do it. expect is based on having tcl available on your system. Write the C code. Don't actually do an fopen() on the passwd file. See: man 3 putpwent. Or getpwent. The C code is secure, and thread safe if done correctly. Interaction with another application adds a layer of potential problems and portability issues. The lower level routines exist and are there for proper use against the password files. THis method is against ANSI standard C and ISO Unix standards. Yes, I agree that writing your own low level routines to crypt a password string and enter it in the passwd file is dangerous. Use the routines that exist. This way you dont have to worry about NIS, shadow files, or whatever..... > It is available on the Internet: Use your favorite search engine, > since I don't have the address handy. > Well, to tease Terry, I wouldn't take the advice of anyone with an AOL (that's pronouncer A O HELLER) account. ;-) Most companies who run production shops have policies about using shareware components. Bringing in stuff from the Net has a lot of security issues as well as supportability problems. So solutions based on them may meet political and cultural problems. Being the paranoid hack that I am, I tend to look for secure solutions. Being a consultant, I try to work within the parameters set forth by my clients. > ...Terry. > tgauch@aol.com Just a few words of wisdom from your uncle mike ;-) P.S. Ever wonder why I'm so security concious .... ;-)