[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Remove User on Remove, or Purge?



On Wednesday 27 October 2004 20.46, Peter Karlsson wrote:
> ms419@freezone.co.uk:
> > If a package creates a user when it is installed, should it remove this
> > user when it is removed, on only when it is purged?
[...]
> how purging the package should remove it completely. To me, that includes
> removing any users or groups created by its installation.

I think not removing the user is the safe option: If ever some files 
(potentially containing sensitive information) are owned by the package's 
user and left behind after purge (perhaps because the admin moved them to 
some other place), removing the user would allow some other package inherit 
the files - and possibly would let the world access these files.

I support every effort not to clutter the system with left-overs of old 
packages, but security is more important here.

cheers
-- vbi

-- 
Oops



Reply to: