Simo Sorce ssorce at redhat.com
Thu Jun 14 14:14:41 UTC 2007

On Thu, 2007-06-14 at 08:44 -0500, Tom "spot" Callaway wrote:

> A possible improvement I could see would be to change the tool to ask
> pam if the user exists, as opposed to simply looking

I guess you mean NSS

> in /etc/passwd, /etc/group, as that would better cover network user
> conflicts.

If you don't already do it, you should _really_ do it and quickly.
Checking /etc/passwd directly today is not acceptable IMO, NSS has been
introduced exactly to decouple user querying from knowledge of the
underlying db and mechanisms used.


