[Pkg-shadow-devel] Bug#75181: passwd: grpck does not check the consistency of the /etc/group and /etc/gshadow files

Nicolas François Nicolas François , 75181@bugs.debian.org
Sat, 26 Mar 2005 01:13:17 +0100


Hi,

IMHO, /etc/group and /etc/gshadow do not have to contain the same list of
members for a group.

The list of members in /etc/group is used at login, to set the list of
groups a user is in.

The list of members in /etc/gshadow indicates the users which can use the
newgrp command to set their group Id without providing the group password.

Indeed these two lists should probably always be the same, and grpck could
warn (as pwck could warn when one user do not use a shadowed password).

I may submit a patch for this after Sarge.

Best Regards,
-- 
Nekral