Subject: Re: proposed changes to /etc/security
To: Martin J. Laubach <mjl@emsi.priv.at>
From: Matthew Jacob <mjacob@feral.com>
List: tech-security
Date: 07/25/1998 12:31:17
On Sat, 25 Jul 1998, Martin J. Laubach wrote:

> | /etc/security doesn't grok YP tokens in master.passwd or group
> | files and thus the daily security output complains about these
> | tokens.
> 
> | +		if ($0 == "+:::::::::") {
> 
>   Well, let's do it right then. What about "+user:", "+user:*:",
> and whatever other variants are possible?

Ah - I hadn't really thought that through, no.... good point...

> 
>   Is it a security threat to ignore lines beginning with "+" or
> "-"?

That's what I'm asking of this list.