Bug 229472

Summary: news account has no login shell
Product: Red Hat Enterprise Linux 4 Reporter: Bryn M. Reeves <bmr>
Component: setupAssignee: Phil Knirsch <pknirsch>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 4.4CC: ovasik, rvokal, tao
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: RHBA-2008-0130 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-03-05 12:30:46 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 345201, 367631    

Description Bryn M. Reeves 2007-02-21 13:01:57 UTC
Description of problem:
The news account is created with no login shell:

news:x:9:13:news:/etc/news:

For e.g. this would allow a password to be set, or creation of SSH key files
that would then permit this to be used as a login account.

Other system accounts use the shell /sbin/nologin to prevent this.

The account is created by the setup RPM. The maintainer has requested a review
of inn to verify that changing this setting for the account will not cause
problems for the inn package.


Version-Release number of selected component (if applicable):
Reported on RHEL4U4, but verified on FC6 & RHEL5.

How reproducible:
100%

Steps to Reproduce:
1. getent passwd news
  
Actual results:
news:x:9:13:news:/etc/news:

Expected results:
news:x:9:13:news:/etc/news:/sbin/nologin

Comment 1 Ondrej Dvoracek 2007-03-08 18:27:13 UTC
Hi,
I tried to change this setting for the account on RHEL5. The innd is runing
without any problems. Now I'm doing some other tests, but it seems to me, that
there wouldn't be any problem.

Comment 15 errata-xmlrpc 2008-03-05 12:30:46 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2008-0130.html