This is the mail archive of the cygwin-apps@cygwin.com mailing list for the Cygwin project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

RE: [RFC] Globally creating a user and a group "root"


Corinna Vinschen wrote:
> On Thu, Nov 27, 2003 at 08:33:24AM -0000, Morrison, John wrote:
>> Corinna Vinschen wrote:
>>> any chance you can poke the base-passwd script soon, to check for a
>>> user and a group with SID S-1-1-0 in the existing /etc/passwd and
>>> /etc/group files and remove them silently?
>>> 
>>> Also it would be good if the script adds the following entry to
>>> /etc/group, if possible as the first line:
>>> 
>>>   root:S-1-5-32-544:0:
>> 
>> OK, just a few questions:
>> 
>> 1) does your script do all this?
> 
> No.  I was asking you to add the above to the passwd related
> postinstall script.  That has nothing to do with my create-root
> script. 

Sorry I thought it was your create-root.sh script we were talking
about.

>> 2) does the script need to be run after passwd-grp.sh?
> 
> Which script?  Your's should run on postinstall.  Removing S-1-1-0

err, the one refered to in point 1?

> just removes the Everyone entries which are old and superfluous
> anyway. 
> 
> I've changed mkgroup to add a root entry as above when called with -l
> but this only helps if mkgroup is called at all.  Your script should
> make sure that such an entry exists on machines which already have an
> /etc/group file. 
> 
>> 3) will your script run OK as a postinstall? (I know it prompts
>> 	for information...)
> 
> No.  I was just asking you to do the above in a postinstall script.
> This is independent of my create-root script.
> 
>> 4) I get an "Error in addUserRights (LsaAddAccountRights returned
>> 	0xc0000060=STATUS_NO_SUCH_PRIVILEGE)!" on a w2k box (I have
>> 	full, local, admin rights.  Is this OK? (or have I lost the
>> 	plot again :|
> 
> Details?  Which user right does result in that error?  Does W2K not
> have the SeDenyXXX rights, perhaps?

Sorry, you are talking double dutch (sorry all you Dutch ;).  All
I did was run the create-root.sh and enter a password.  I've not got
the time atm to go any deeper - I've a non-flexable deadline at work
that I'm up against :(

Having said that, I'll try and scavenge some time at the weekend if
not before and try and do the mods.

J.


==========================================================================
Information in this email and any attachments are confidential, and may
not be copied or used by anyone other than the addressee, nor disclosed
to any third party without our permission. There is no intention to
create any legally binding contract or other binding commitment through
the use of this electronic communication unless it is issued in accordance
with the Experian Limited standard terms and conditions of purchase or
other express written agreement between Experian Limited and the recipient
Experian Limited (registration number 653331)
Registered office: Talbot House, Talbot Street, Nottingham NG80 1TH


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]