Re: Bug#329701: Local (non-NIS) users and groups

On Thu, Sep 22, 2005 at 11:25:38PM +0200, Teddy Hogeborn wrote:

> (I tried to raise this question for general discussion some time ago
> but no one replied.  See
> <http://lists.debian.org/debian-policy/1998/10/msg00198.html>.
> Therefore I now submit a more specific proposal as a wishlist bug in
> the hope of some feedback.)

> In regards to NIS (and LDAP), there is no standard place for
> domain-exported groups which are not user-private groups.  I propose
> that the "system" GID space be split in half and all GIDs at 500 and
> above be considered domain-exported and those below to be
> machine-local.

> The only change necessary in the nis package is to *not* change MINGID
> in "nis-3.13/ypserv-2.14/scripts/ypMakefile.in".  The original value
> is already 500; just leave it.

> (I guess this ought to be written into the policy manual at some
> point, but you have to start somewhere, and it's easier to change a
> package than the Debian Policy.)

This looks like a question for policy rather than the NIS package since
coordination with things like adduser seems at least desirable so I'm
reassigning the bug there.  

My instinct is that this is probably something that is best handled by
the local administrator since having it work effectively requires more
coordination between machines than is likely to be achived automatically
but I've not considerd the issues too deeply.

