UID/GID dynamic allocation in net/isc-dhcp3-server: why?

Kris Kennaway kris at obsecurity.org
Sat Nov 11 12:48:17 PST 2006


On Sat, Nov 11, 2006 at 09:37:31PM +0100, Simon L. Nielsen wrote:
> On 2006.11.11 21:12:09 +0200, Dmitry Pryanishnikov wrote:
> 
> >  I don't like the current behaviour of the net/isc-dhcp3-server port
> > of creating 'dhcpd' user and group using dynamic allocation instead of
> > having static one (as specified in /usr/ports/{U,G}IDs). I like the idea
> > of [ug]id ranges, and dynamic allocation doesn't keep within this idea
> > (ids of users and daemons get mixed). Is there specific reason why there
> > is no static [ug]id for net/isc-dhcp3-server?
> 
> Personally I have it precisely the other way around - I find the
> static allocations rather annoying since they are bound to collide
> with existing UID's at some point.
>
> IMO the optimal solution would be to have some magic which auto
> assigns ports/system UID/GID's from different ranges that normal
> users.

Just so :)

UIDs below 1000 are (and have been for many years) allocated to the
"system" (ports/src), and are not supposed to be allocated by
administrators.  This at least works out of the box with some of the
tools we have for allocating new users, so are you aware of any that
don't do this?

Kris
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-ports/attachments/20061111/4707e370/attachment.pgp


More information about the freebsd-ports mailing list