Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.devel > #106816 > unrolled thread
| Started by | nick black <dankamongmen@gmail.com> |
|---|---|
| First post | 2023-01-14 03:20 +0100 |
| Last post | 2023-01-15 20:10 +0100 |
| Articles | 8 — 5 participants |
Back to article view | Back to linux.debian.devel
need we support unshadowed passwords from the installer nick black <dankamongmen@gmail.com> - 2023-01-14 03:20 +0100
Re: need we support unshadowed passwords from the installer Marc Haber <mh+debian-devel@zugschlus.de> - 2023-01-14 10:00 +0100
Re: need we support unshadowed passwords from the installer nick black <dankamongmen@gmail.com> - 2023-01-14 15:20 +0100
Re: need we support unshadowed passwords from the installer Steve McIntyre <steve@einval.com> - 2023-01-15 14:30 +0100
Re: need we support unshadowed passwords from the installer Peter Pentchev <roam@ringlet.net> - 2023-01-14 13:20 +0100
Re: need we support unshadowed passwords from the installer Peter Pentchev <roam@ringlet.net> - 2023-01-14 13:20 +0100
Re: need we support unshadowed passwords from the installer Sam Hartman <hartmans@debian.org> - 2023-01-15 01:00 +0100
Re: need we support unshadowed passwords from the installer nick black <dankamongmen@gmail.com> - 2023-01-15 20:10 +0100
| From | nick black <dankamongmen@gmail.com> |
|---|---|
| Date | 2023-01-14 03:20 +0100 |
| Subject | need we support unshadowed passwords from the installer |
| Message-ID | <FNEjf-fov-3@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
it's 2023 and imho time to stop supporting unshadowed passwords
from the installer.
https://salsa.debian.org/installer-team/user-setup/-/merge_requests/5
1) nis (and possibly conserver?) seem the primary drivers of an
unshadowed passwd.=20
let me freely admit that, despite the advanced age of forty-two
(seventy-eight in UNIX years), that i know nothing about nis/yp
except that there was a big o'reilly book about it back when one
read the security book with the big safe on the front and the
scripting book with the big drill. i suspect it's basically a
halfway point between syncing /etc/passwd and /etc/hosts with
cron+rsh, and hiring someone on whom you can inflict ldap? so
please correct me wherever i'm woefully ignorant.
...but it appears that NIS can be made to work with shadowed
passwords (though without their benefits). this is from a
cursory reading of a FAQ last updated in 2003, so take it with a
grain of salt. the "linux network administrators [sic] guide"
seems to confirm this, and can also help you set up IPX or UUCP.
2) it seems that the unshadowing of passwords is only a
"/sbin/shadowconfig off" away. somewhere down the long road, we
appear to have lost shadowconfig.8, but this is what i gather
from web searches.
i'd almost suggest this might want to go into the "nis"
package, avoiding "why do we even have that lever"
situations, but i resolutely oppose feature creep for this MR.
3) if someone accidentally selects this during install, i can't
think of any means by which they'd find out during the course of
typical systems administration.
4) i don't have to answer this question in any other installer
i've used in the past decade, i'm pretty certain.
5) arch appears to support NIS without any mention of shadowing?
though admittedly that wiki page is "somewhat unfinished"[0]
6) fedora has recently discussed eliminating NIS support
entirely. it's a done deal in RHEL.
i'm absolutely not suggesting we stop supporting NIS or other
programs which rely on unshadowed passwords. it's a big ol'
tent, and we have more than enough room for you to carry forth
the torch of Solaris 2. i just don't think this belongs in the
installer anymore.
--rigorously, nick
[0] https://wiki.archlinux.org/title/NIS
--
nick black -=- https://www.nick-black.com
to make an apple pie from scratch,
you need first invent a universe.
[toc] | [next] | [standalone]
| From | Marc Haber <mh+debian-devel@zugschlus.de> |
|---|---|
| Date | 2023-01-14 10:00 +0100 |
| Message-ID | <FNKyl-jhx-3@gated-at.bofh.it> |
| In reply to | #106816 |
On Fri, 13 Jan 2023 21:11:40 -0500, nick black <dankamongmen@gmail.com> wrote: >i'm absolutely not suggesting we stop supporting NIS or other >programs which rely on unshadowed passwords. it's a big ol' >tent, and we have more than enough room for you to carry forth >the torch of Solaris 2. i just don't think this belongs in the >installer anymore. Amen. NIS-based systems usually have professional administrators who are well able to change the configuration. Greetings Marc -- -------------------------------------- !! No courtesy copies, please !! ----- Marc Haber | " Questions are the | Mailadresse im Header Mannheim, Germany | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834
[toc] | [prev] | [next] | [standalone]
| From | nick black <dankamongmen@gmail.com> |
|---|---|
| Date | 2023-01-14 15:20 +0100 |
| Message-ID | <FNPy1-mRn-1@gated-at.bofh.it> |
| In reply to | #106817 |
[Multipart message — attachments visible in raw view] — view raw
Marc Haber left as an exercise for the reader: > On Fri, 13 Jan 2023 21:11:40 -0500, nick black > <dankamongmen@gmail.com> wrote: > >i'm absolutely not suggesting we stop supporting NIS or other > >programs which rely on unshadowed passwords. it's a big ol' > >tent, and we have more than enough room for you to carry forth > >the torch of Solaris 2. i just don't think this belongs in the > >installer anymore. > > Amen. NIS-based systems usually have professional administrators who > are well able to change the configuration. hahah, yes i thought you might support the idea based off adduser changelogs circa 2005 =]. thanks to you and peter for voicing your support. i will head off to #debian-boot and try to drum up a merge. -- nick black -=- https://www.nick-black.com to make an apple pie from scratch, you need first invent a universe.
[toc] | [prev] | [next] | [standalone]
| From | Steve McIntyre <steve@einval.com> |
|---|---|
| Date | 2023-01-15 14:30 +0100 |
| Message-ID | <FObfc-AJj-5@gated-at.bofh.it> |
| In reply to | #106821 |
On Sat, Jan 14, 2023 at 09:18:59AM -0500, nick black wrote: >Marc Haber left as an exercise for the reader: >> On Fri, 13 Jan 2023 21:11:40 -0500, nick black >> <dankamongmen@gmail.com> wrote: >> >i'm absolutely not suggesting we stop supporting NIS or other >> >programs which rely on unshadowed passwords. it's a big ol' >> >tent, and we have more than enough room for you to carry forth >> >the torch of Solaris 2. i just don't think this belongs in the >> >installer anymore. >> >> Amen. NIS-based systems usually have professional administrators who >> are well able to change the configuration. > >hahah, yes i thought you might support the idea based off >adduser changelogs circa 2005 =]. > >thanks to you and peter for voicing your support. i will head >off to #debian-boot and try to drum up a merge. I'll be honest, I've been horrified for years that we can still ask the shadow question. I hadn't realised it might be relevant for NIS. Even so, +1 from me. Let's get this done, I think... -- Steve McIntyre, Cambridge, UK. steve@einval.com Is there anybody out there?
[toc] | [prev] | [next] | [standalone]
| From | Peter Pentchev <roam@ringlet.net> |
|---|---|
| Date | 2023-01-14 13:20 +0100 |
| Message-ID | <FNNFT-lq4-5@gated-at.bofh.it> |
| In reply to | #106816 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, Jan 14, 2023 at 02:11:00PM +0200, Peter Pentchev wrote: > On Fri, Jan 13, 2023 at 09:11:40PM -0500, nick black wrote: > > it's 2023 and imho time to stop supporting unshadowed passwords > > from the installer. > > > > https://salsa.debian.org/installer-team/user-setup/-/merge_requests/5 > > > > 1) nis (and possibly conserver?) seem the primary drivers of an > > unshadowed passwd.=20 > > > > let me freely admit that, despite the advanced age of forty-two > > (seventy-eight in UNIX years), that i know nothing about nis/yp > > except that there was a big o'reilly book about it back when one > > read the security book with the big safe on the front and the > > scripting book with the big drill. i suspect it's basically a > > halfway point between syncing /etc/passwd and /etc/hosts with > > cron+rsh, and hiring someone on whom you can inflict ldap? so > > please correct me wherever i'm woefully ignorant. > > > > ...but it appears that NIS can be made to work with shadowed > > passwords (though without their benefits). this is from a > > cursory reading of a FAQ last updated in 2003, so take it with a > > grain of salt. the "linux network administrators [sic] guide" > > seems to confirm this, and can also help you set up IPX or UUCP. > [snip] > > i'm absolutely not suggesting we stop supporting NIS or other > > programs which rely on unshadowed passwords. it's a big ol' > > tent, and we have more than enough room for you to carry forth > > the torch of Solaris 2. i just don't think this belongs in the > > installer anymore. > > I know what NIS/YP is, I know of a couple of places where it is > still in use, and, as Mark Haber said, the people running those Um. Many apologies. Of course it's Marc. > places know how to find and flip a switch. -- Peter Pentchev roam@ringlet.net roam@debian.org pp@storpool.com PGP key: http://people.FreeBSD.org/~roam/roam.key.asc Key fingerprint 2EE7 A7A5 17FC 124C F115 C354 651E EFB0 2527 DF13
[toc] | [prev] | [next] | [standalone]
| From | Peter Pentchev <roam@ringlet.net> |
|---|---|
| Date | 2023-01-14 13:20 +0100 |
| Message-ID | <FNNFT-lq4-7@gated-at.bofh.it> |
| In reply to | #106816 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Jan 13, 2023 at 09:11:40PM -0500, nick black wrote: > it's 2023 and imho time to stop supporting unshadowed passwords > from the installer. > > https://salsa.debian.org/installer-team/user-setup/-/merge_requests/5 > > 1) nis (and possibly conserver?) seem the primary drivers of an > unshadowed passwd.=20 > > let me freely admit that, despite the advanced age of forty-two > (seventy-eight in UNIX years), that i know nothing about nis/yp > except that there was a big o'reilly book about it back when one > read the security book with the big safe on the front and the > scripting book with the big drill. i suspect it's basically a > halfway point between syncing /etc/passwd and /etc/hosts with > cron+rsh, and hiring someone on whom you can inflict ldap? so > please correct me wherever i'm woefully ignorant. > > ...but it appears that NIS can be made to work with shadowed > passwords (though without their benefits). this is from a > cursory reading of a FAQ last updated in 2003, so take it with a > grain of salt. the "linux network administrators [sic] guide" > seems to confirm this, and can also help you set up IPX or UUCP. [snip] > i'm absolutely not suggesting we stop supporting NIS or other > programs which rely on unshadowed passwords. it's a big ol' > tent, and we have more than enough room for you to carry forth > the torch of Solaris 2. i just don't think this belongs in the > installer anymore. I know what NIS/YP is, I know of a couple of places where it is still in use, and, as Mark Haber said, the people running those places know how to find and flip a switch. G'luck, Peter -- Peter Pentchev roam@ringlet.net roam@debian.org pp@storpool.com PGP key: http://people.FreeBSD.org/~roam/roam.key.asc Key fingerprint 2EE7 A7A5 17FC 124C F115 C354 651E EFB0 2527 DF13
[toc] | [prev] | [next] | [standalone]
| From | Sam Hartman <hartmans@debian.org> |
|---|---|
| Date | 2023-01-15 01:00 +0100 |
| Message-ID | <FNYBj-shO-3@gated-at.bofh.it> |
| In reply to | #106816 |
[Multipart message — attachments visible in raw view] — view raw
>>>>> "nick" == nick black <dankamongmen@gmail.com> writes:
nick> it's 2023 and imho time to stop supporting unshadowed
nick> passwords from the installer.
Yes, absolutely.
I am familiar with nis/PAM/shadow/LDAP, have deployed NIS (although not
nisplus), and have been around long enough to understand the issues.
It is absolutely reasonable to expect people who need to do so to
unshadow their own passwords.
[toc] | [prev] | [next] | [standalone]
| From | nick black <dankamongmen@gmail.com> |
|---|---|
| Date | 2023-01-15 20:10 +0100 |
| Message-ID | <FOgye-E8e-7@gated-at.bofh.it> |
| In reply to | #106816 |
[Multipart message — attachments visible in raw view] — view raw
Sam Hartman left as an exercise for the reader: > Yes, absolutely. > I am familiar with nis/PAM/shadow/LDAP, have deployed NIS (although not > nisplus), and have been around long enough to understand the issues. > > It is absolutely reasonable to expect people who need to do so to > unshadow their own passwords. thanks Steve McIntyre for the merge! as an aside, as a fairly new DD, i've seen a lot of worry in recent years about the difficulty of getting changes through given the distributed ownership of packages, etc. i was frankly worried about this being difficult to see through, despite it being a small and agreed-upon change (there was certainly no way i was going to NMU the installer). it was merged this morning after authoring the MR through salsa two evenings ago, quite painlessly. this is anecdotal and perhaps not representative of Project dynamics as a whole, but i for one feel more comfortable about proposing and executing small changes like this now. -- nick black -=- https://www.nick-black.com to make an apple pie from scratch, you need first invent a universe.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.devel
csiph-web