creating generic user in Linux
Posted in 2000
The poster wanted a generic account for PHP/Apache scripts to connect to Informix on Caldera Linux, since Informix user IDs must exist as OS users, and asked how to create a Linux user that can do nothing but serve as that database login. Replies confirmed the approach: GRANT CONNECT works for any name, but the OS account must exist. The agreed solution was to set the account's shell to /bin/false (or an equivalent script that just exits), optionally combined with an unusable/invalid password field and a .rhosts for trusted-host connections; anonymous-FTP setup was suggested as a model. The poster accepted /bin/false, though he still planned to test whether ftp and other services needed blocking too.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Platform-Specific Issues
I'm using Foundation 2000 on Caldera eServer 2.3 Linux. I also use PHP and Apache, and I want to be able to write PHP scripts that will connect to the Informix server. In order to do this, I need to have the script connect as a particular user. So I want to create a generic user that I can assign connect privileges to in the database, and select permissions to on tables, and nothing else. If I understand things rightly, Informix doesn't let anyone refer to a userid in Informix that doesn't exist in Linux. So I would need to create a Linux user with the same name as my generic Informix user. Assuming that is correct, then I'd want to create a Linux user who can do absolutely nothing within Linux, including log in. Does anyone have any tips on a good way to do this? I assume that it must be a common problem. I know that I probably should have asked a Linux group first, but I thought that I might be on the wrong path entirely.
Richard Puchalsky wrote: > I'm using Foundation 2000 on Caldera eServer 2.3 Linux. I also use PHP and > Apache, and I want to be able to write PHP scripts that will connect to the > Informix server. In order to do this, I need to have the script connect as > a particular user. So I want to create a generic user that I can assign > connect privileges to in the database, and select permissions to on tables, > and nothing else. Sounds fair enough. Also consider whether you can get people to identify themselves to your site in a reasonably secure way. However, for the general public, you're right on target. > If I understand things rightly, Informix doesn't let anyone refer to a > userid in Informix that doesn't exist in Linux. It depends a bit on what you mean by refer. If I say: GRANT CONNECT TO 'anybody' then the DBMS does not verify whether there is an 'anybody' listed as a user. On the other hand, it only uses the permission just granted if someone connects to the database claiming to be 'anybody'. > So I would need to create a Linux user with the same name as my generic > Informix user. Correct. > Assuming that is > correct, then I'd want to create a Linux user who can do absolutely nothing > within Linux, including log in. Well, the first step is to ensure that the user cannot log on. Either you fix the password so it is unknown, or you ensure that the shell logs them off. Since the connections probably won't work without a valid password, you have to fix the shell. Specifying /bin/false might work; or you may need to specify a real executable. You might want to print a message, in which case, you probably need to write a small custom program. > Does anyone have any tips on a good way to do this? I assume that it must > be a common problem. I know that I probably should have asked a Linux group > first, but I thought that I might be on the wrong path entirely. I think you're on track. The only problem will be if the security system won't let you create a user with an unrecognized shell (such as /bin/false). Then you have to work a bit harder. If the worst comes to the worst, use BASH and set the user's .profile to include the line "exit 1". The chances are, that will keep the user off the system. The snag is that there might be a small window of vulnerability before the shell finishes processing .profile when the user might be able to interrupt and connect. However, the chances of anyone timing that right are small. -- Jonathan Leffler (jleffler@informix.com, jleffler@earthlink.net) Guardian of DBD::Informix v1.00.PC1 -- see http://www.perl.com/CPAN #include <disclaimer.h>
> > Does anyone have any tips on a good way to do this? I assume that
it must
> > be a common problem. I know that I probably should have asked a
Linux group
> > first, but I thought that I might be on the wrong path entirely.
>
First create a shell script that exits
# cat /bin/dieexit 1
#
Then change /etc/passwd
merlin:x:501:501::/home/merlin:/bin/die
When a user logs the process exec's the file in /etc/passwd. So the
login dies.
Sent via Deja.com http://www.deja.com/
Before you buy.
In <8eilmo$lit$1@nnrp1.deja.com> merlindoggie@my-deja.com writes:
>First create a shell script that exits
># cat /bin/die>exit 1
Eh? Use /bin/false, it's made for exactly that purpose.
HTH,
Uli
--
Dipl. Inf. Ulrich Teichert|e-mail: Ulrich.Teichert@gmx.de
Stormweg 24 |listening to: Speed Of Life (Buzzcocks),
24539 Neumuenster, Germany|Cheap Excitement (Stratford Mercenaries)
"Richard Puchalsky" <rpuchalsky@att.net> wrote: > Assuming that is > correct, then I'd want to create a Linux user who can do absolutely nothing > within Linux, including log in. > Thanks, everyone. The consensus seems to be that creating a user with shell /bin/false should be enough (my distribution of Linux includes /bin/false). I knew about /bin/false, but I wasn't sure whether that would still let the user do anything else, like ftp or what have you, that I would have to take additional steps to block. I guess I'll have to experiment.
Why not just create the user without a valid password? Then noone can login with that userid whether with a shell or ftp etc. Remote Informix users will be able to get in without a password if their host and username are trusted. This can be accomplished securely with a .rhosts file in the user's home directory on the server. This will also prevent someone pretending to be the intended user by creating an identical login on a different PC, the users would only be authorized to connect from the named host(s). Art S. Kagel Richard Puchalsky wrote: > > "Richard Puchalsky" <rpuchalsky@att.net> wrote: > > Assuming that is > > correct, then I'd want to create a Linux user who can do absolutely > nothing > > within Linux, including log in. > > > > Thanks, everyone. The consensus seems to be that creating a user with shell > /bin/false should be enough (my distribution of Linux includes /bin/false). > I knew about /bin/false, but I wasn't sure whether that would still let the > user do anything else, like ftp or what have you, that I would have to take > additional steps to block. I guess I'll have to experiment.
> Why not just create the user without a valid password? Then noone can login > with that userid whether with a shell or ftp etc. Remote Informix users > will be able to get in without a password if their host and username are > trusted. This can be accomplished securely with a .rhosts file in the > user's home directory on the server. This will also prevent someone > pretending to be the intended user by creating an identical login on a > different PC, the users would only be authorized to connect from the named > host(s). > > Art S. Kagel What, exactly, do you mean by 'without a valid password'? If you mean a password that isn't known by anyone, it can still be cracked using easy to get password crackers. Using /bin/false is the accepted way of accomplishing this; that's what it's there for. > Richard Puchalsky wrote: > > > > "Richard Puchalsky" <rpuchalsky@att.net> wrote: > > > Assuming that is > > > correct, then I'd want to create a Linux user who can do absolutely > > nothing > > > within Linux, including log in. > > > > > > > Thanks, everyone. The consensus seems to be that creating a user with shell > > /bin/false should be enough (my distribution of Linux includes /bin/false). > > I knew about /bin/false, but I wasn't sure whether that would still let the > > user do anything else, like ftp or what have you, that I would have to take > > additional steps to block. I guess I'll have to experiment. > -- # unrm / ksh: unrm: not found # man cpio Sent via Deja.com http://www.deja.com/ Before you buy.
mars1972@my-deja.com wrote: > > > Why not just create the user without a valid password? Then noone can > login > > with that userid whether with a shell or ftp etc. Remote Informix > users > > will be able to get in without a password if their host and username > are > > trusted. This can be accomplished securely with a .rhosts file in the > > user's home directory on the server. This will also prevent someone > > pretending to be the intended user by creating an identical login on a > > different PC, the users would only be authorized to connect from the > named > > host(s). > > > > Art S. Kagel > > What, exactly, do you mean by 'without a valid password'? If you mean a > password that isn't known by anyone, it can still be cracked using easy > to get password crackers. Using /bin/false is the accepted way of > accomplishing this; that's what it's there for. "Without a valid password" means with a password that CANNOT be a valid password. In /etc/passwd installations I just put '**NO LOGIN**' into the password field manually. Since no entered text password can possibly be encrypted to that string that user is "without a valid password". There must be a way to do this in PAM and shadow file password systems, I just do not do UNIX administration anymore and use /etc/passwd on my Linux at home so I have had no need to learn how this is done. Art S. Kagel > > Richard Puchalsky wrote: > > > > > > "Richard Puchalsky" <rpuchalsky@att.net> wrote: > > > > Assuming that is > > > > correct, then I'd want to create a Linux user who can do > absolutely > > > nothing > > > > within Linux, including log in. > > > > > > > > > > Thanks, everyone. The consensus seems to be that creating a user > with shell > > > /bin/false should be enough (my distribution of Linux includes > /bin/false). > > > I knew about /bin/false, but I wasn't sure whether that would still > let the > > > user do anything else, like ftp or what have you, that I would have > to take > > > additional steps to block. I guess I'll have to experiment. > > > > -- > # unrm / > ksh: unrm: not found > # man cpio > > Sent via Deja.com http://www.deja.com/ > Before you buy.
>Subject: creating generic user in Linux >From: "Richard Puchalsky" rpuchalsky@att.net >Date: 30.04.00 06:12 W. Europe Daylight Time >Message-id: <IoOO4.29807$PV.2122245@bgtnsc06-news.ops.worldnet.att.net> > >I'm using Foundation 2000 on Caldera eServer 2.3 Linux. I also use PHP and >Apache, and I want to be able to write PHP scripts that will connect to the >Informix server. In order to do this, I need to have the script connect as >a particular user. So I want to create a generic user that I can assign >connect privileges to in the database, and select permissions to on tables, >and nothing else. > >If I understand things rightly, Informix doesn't let anyone refer to a >userid in Informix that doesn't exist in Linux. So I would need to create a >Linux user with the same name as my generic Informix user. Assuming that is >correct, then I'd want to create a Linux user who can do absolutely nothing >within Linux, including log in. > >Does anyone have any tips on a good way to do this? I assume that it must >be a common problem. I know that I probably should have asked a Linux group >first, but I thought that I might be on the wrong path entirely. > > > > > > > > that is similar to setting up an account for anonymous ftp. Just look for info on that. Nona