Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.

Bug 70414

Summary: /etc/shells misses some shells and lists /sbin/nologin
Product: [Retired] Red Hat Linux Reporter: Tomasz Kepczynski <tomek>
Component: setupAssignee: Bill Nottingham <notting>
Status: CLOSED NOTABUG QA Contact: David Lawrence <dkl>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.3CC: kas, rvokal
Target Milestone: ---   
Target Release: ---   
Hardware: i686   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2002-08-01 07:54:48 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Tomasz Kepczynski 2002-08-01 07:54:43 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.9) Gecko/20020513

Description of problem:
On my PC at least tcsh, csh and ash are missing from /etc/shells file and this
prevents users from ftp login. As far as I remember this change was not
documented in release notes.
Additionally /sbin/nologin is listed as valid shell which I believe is incorrect
and security risk, unless it is there specifically to allow ftp accounts only.

Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
Not relevant	

Additional info:

Comment 1 Bill Nottingham 2002-08-12 19:11:48 UTC
Other shells are added in their %post, and /sbin/nologin is intentional.

Comment 2 Phil Knirsch 2007-05-24 13:23:43 UTC
*** Bug 230650 has been marked as a duplicate of this bug. ***

Comment 3 Jan "Yenya" Kasprzak 2007-05-24 13:44:49 UTC
OK then, either the shells(5) manpage should be changed to reflect the fact that
[not] having a shell listed in /etc/shells is no longer a valid criteria for
distinguishing between ordinary users and pseudo users, 

or (better) there should be a hard-linked copy of /sbin/nologin (say
/sbin/nologin-noshells), and system accounts should be changed to have this
shell instead.

I have the following pseudo-accounts with /sbin/nologin shell:

bin daemon adm lp mail uucp operator games gopher ftp nobody rpm vcsa sshd rpc
rpcuser nfsnobody mailnull smmsp pcap radvd postfix dbus haldaemon named nscd