History log of /freebsd-10.0-release/etc/master.passwd
Revision Date Author Comments
(<<< Hide modified files)
(Show modified files >>>)
# 259065 07-Dec-2013 gjb

- Copy stable/10 (r259064) to releng/10.0 as part of the
10.0-RELEASE cycle.
- Update __FreeBSD_version [1]
- Set branch name to -RC1

[1] 10.0-CURRENT __FreeBSD_version value ended at '55', so
start releng/10.0 at '100' so the branch is started with
a value ending in zero.

Approved by: re (implicit)
Sponsored by: The FreeBSD Foundation

# 256366 12-Oct-2013 rpaulo

MFC 256365
Remove most of the ATF tools and the _atf user.

Approved by: re


# 256281 10-Oct-2013 gjb

Copy head (r256279) to stable/10 as part of the 10.0-RELEASE cycle.

Approved by: re (implicit)
Sponsored by: The FreeBSD Foundation


# 255597 15-Sep-2013 des

Build and install the Unbound caching DNS resolver daemon.

Approved by: re (blanket)


# 243752 01-Dec-2012 rwatson

Merge a number of changes required to hook up OpenBSM 1.2-alpha2's
auditdistd (distributed audit daemon) to the build:

- Manual cross references
- Makefile for auditdistd
- rc.d script, rc.conf entrie
- New group and user for auditdistd; associated aliases, etc.

The audit trail distribution daemon provides reliable,
cryptographically protected (and sandboxed) delivery of audit tails
from live clients to audit server hosts in order to both allow
centralised analysis, and improve resilience in the event of client
compromises: clients are not permitted to change trail contents
after submission.

Submitted by: pjd
Sponsored by: The FreeBSD Foundation (auditdistd)


# 241823 21-Oct-2012 marcel

Add ATF to the build. This is may be a bit rought around the egdes,
but committing it helps to get everyone on the same page and makes
sure we make progress.

Tinderbox breakages that are the result of this commit are entirely
the committer's fault -- in other words: buildworld testing on amd64
only.

Credits follow:

Submitted by: Garrett Cooper <yanegomi@gmail.com>
Sponsored by: Isilon Systems
Based on work by: keramida@
Thanks to: gnn@, mdf@, mlaier@, sjg@
Special thanks to: keramida@


# 218047 28-Jan-2011 pjd

Change hast user home directory to /var/empty.

MFC after: 1 week


# 218046 28-Jan-2011 pjd

Add 'hast' user and 'hast' group that will be used by hastd (and maybe hastctl)
to drop privileges.

MFC after: 1 week


# 147062 06-Jun-2005 brooks

Add _dhcp user/group as required by the OpenBSD dhclient.


# 132981 01-Aug-2004 markm

UUCP's uucico(8) has not been in the base system for some time now,
so reflect this in the default. The uucp uid is a bit funny, and
is used by mtree in /var/spool for locks, so we can't remove it
without thinking about it a bit harder.


# 130968 23-Jun-2004 mlaier

It's /usr/sbin/nologin not /sbin/nologin

Found-by: brueffer
Pointy-hat-to: mlaier


# 130953 22-Jun-2004 mlaier

Add "privsep" user/group _pflogd:_pflogd (64:64) to make pflogd(8) work
again. This user/group is not required for install* targets, hence do not
add them to CHECK_UIDS/CHECK_GIDS in Makefile.inc1 (no need to annoy
people).

Discussed-on: -current


# 127633 30-Mar-2004 cperciva

Synchronize with reality: nologin(8) is now in /usr/sbin

Reminded by: trhodes


# 126756 08-Mar-2004 mlaier

Link pf to the build and install:
This adds the former ports registered groups: proxy and authpf as well as
the proxy user. Make sure to run mergemaster -p in oder to complete make
installworld without errors.

This also provides the passive OS fingerprints from OpenBSD (pf.os) and an
example pf.conf.

For those who want to go without pf; it provides a NO_PF knob to make.conf.

__FreeBSD_version will be bumped soon to reflect this and to be able to
change ports accordingly.

Approved by: bms(mentor)


# 114114 27-Apr-2003 imp

xten user no longer needed.


# 98700 23-Jun-2002 des

Previous commit was just a tad too hasty, the sshd peudo-user's home
directory should be /var/empty.


# 98696 23-Jun-2002 des

Add an sshd user and group for the OpenSSH privilege separation code.


# 89956 29-Jan-2002 ru

Tidy up gecos field for `bin'.


# 86510 17-Nov-2001 gshapiro

Add two new accounts/groups for sendmail:

smmsp - sendmail 8.12 operates as a set-group-ID binary (instead of
set-user-ID). This new user/group will be used for command line
submissions. UID/GID 25 is suggested in the sendmail documentation and has
been adopted by other operating systems such as OpenBSD and Solaris 9.

mailnull - The default value for DefaultUser is now set to the uid and gid
of the first existing user mailnull, sendmail, or daemon that has a
non-zero uid. If none of these exist, sendmail reverts back to the old
behavior of using uid 1 and gid 1. Currently FreeBSD uses daemon for
DefaultUser but I would prefer not to use an account used by other
programs, hence the addition of mailnull. UID/GID 26 has been chosen for
this user.

This was discussed on -arch on October 18-19, 2001.

MFC after: 1 week


# 85455 25-Oct-2001 ache

Re-commit www:www
If anybody wants to remove them for some reason, please consider "pop"
removing first.

Approved by: arch discussion from Oct 20
MFC after: 3 days


# 85110 18-Oct-2001 sheldonh

Back previous revision out until it has been discussed on -arch and
motivated. Currently, it is under dispute.


# 85056 17-Oct-2001 ache

Add www:www (80:80) for upcoming Apache changes


# 51237 13-Sep-1999 peter

Add/adjust some $FreeBSD$ tags.

Noted by: Doug <Doug@gorean.org>


# 41457 02-Dec-1998 ache

Use /sbin/nologin as shell for operator
Replace non-existent directory for operator with /
Supply by default operator with non-existent but can be created directory
and /bin/csh is kinda security risk


# 41441 01-Dec-1998 dillon

Added group bind(53), added sandbox users tty(4), kmem(5), and bind(53),
adjustd inetd.conf to run comsat and ntalk from tty sandbox, and
the (commented out) ident from the kmem sandbox.

Note that it is necessary to give each group access it's own uid to
prevent programs running under a single uid from being able to gdb
or otherwise mess with other programs (with different group perms) running
under the same uid.


# 36499 31-May-1998 jkh

Put operator in its own group rather than "staff".
Submitted by: "Yarema" <yds@ingress.com>


# 36346 25-May-1998 steve

Change shell from /nonexistent to /sbin/nologin.

PR: 6739
Submitted by: Are Bryne <are.bryne@communique.no>


# 30794 27-Oct-1997 ache

Back out moving nobody to daemon class, the problem fixed in another place:
inetd


# 30787 27-Oct-1997 ache

Move nobody to daemon class, otherwise it is impossible to start fingerd
while Apache is running, it effectively eats all default class limits for
nobody


# 30222 08-Oct-1997 ache

Add pop


# 17996 01-Sep-1996 ache

Move daemon from group 31 to group 1
One of the reasons: rwhod not work, because it got
1,31 instead of 1,1 on setuid(1) and require group 1 for directory access


# 17105 11-Jul-1996 pst

Set shells to nonexistent where appropriate


# 14592 12-Mar-1996 phk

Move user & group "xten" from [ug]id == 100 to 67.
This is less likely to collide with site policies.


# 14591 12-Mar-1996 phk

Remove ingres user.


# 8539 15-May-1995 ache

change nobody master.passwd entry to 65534:65534
change nobody group entry to 65534
Suggested-by: pst


# 8536 15-May-1995 ache

Change xten shell from /dev/null to /nonexistant, adduser
complaints instead.
Change nobody user group from non existent in /etc/group (9999) to
existent nobody (39).


# 7917 18-Apr-1995 jkh

Add xten user/group.
Submitted by: Gene Stark <gene@starkhome.cs.sunysb.edu>


# 7486 30-Mar-1995 dg

Killed Mr. "Falcon". May he rest in peace.


# 5365 03-Jan-1995 ache

Add 'news' user, present in group, but missed in master.passwd


# 1642 31-May-1994 ache

Intruduce new group for uucp, gid 66


# 1351 11-Apr-1994 wollman

/dev/null was not a very good choice of shell for login-disabled users.
Used the canonical non-existent file (/nonexistent) instead This should
probably be documented somewhere, but it's unclear where the right
place is (passwd(5)? login(8)? hier(7)? all three?).


# 1280 19-Mar-1994 jkh

As per Rod's wishes, man uses uid/gid 9 now.


# 1131 08-Feb-1994 rgrimes

A real good idea...

>From: "Chris G. Demetriou" <cgd@sun-lamp.cs.berkeley.edu>

Update of /b/source/CVS/src/etc
In directory sun-lamp.cs.berkeley.edu:/usr/src/etc

Modified Files:
master.passwd
Log Message:
disable toor by default


# 1088 04-Feb-1994 wollman

Remove more references to the U word.


# 290 13-Aug-1993 rgrimes

Wrong path for uucp login, was /usr/lib instead of /usr/libexec. Fixed


# 146 19-Jul-1993 rgrimes

Removed extranious names from master.passwd file, changed root and toor to
be in group 0 (was group 10). Changed operator to be in group 20, was 28.


# 38 20-Jun-1993 rgrimes

This commit was generated by cvs2svn to compensate for changes in r37,
which included commits to RCS files with non-trunk default branches.


# 37 20-Jun-1993 rgrimes

Initial import of 386BSD 0.1 othersrc/etc