[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Seeking consensus for some changes in adduser



On Wed, 9 Mar 2022 00:12:25 +0200, Adrian Bunk <bunk@debian.org>
wrote:
>On Tue, Mar 08, 2022 at 05:49:04PM +0100, Marc Haber wrote:
>>...
>> (2)
>> #774046 #520037
>> Which special characters should we allow for account names?
>> 
>> People demand being able to use a dot (which might break scripts using
>> chown) and non-ASCII national characters in account names. The regex
>> used to verify non-system accounts is configurable, so the policy can be
>> locally relaxed at run-time.
>> 
>> For system-accounts, I'd like to stick to ASCII letters, numbers,
>> underscores.
>>...
>
>There is a DD with the login 93sam, and this is already outside of 
>what systemd accepts.[1]

... as "User" option in system files. Not going to begin another
systemd flame war today.

Bugs like that look like they'll probably only relevant for accounts
that services run under.

>Non-ASCII characters in account names sound like a lot of breakage
>and CVEs to me.

Agreed, but people want that.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834


Reply to: