Re: [Exim] authentication with PAM

Pàgina inicial
Delete this message
Reply to this message
Autor: Chris Thompson
Data:  
A: exim-users
Assumpte: Re: [Exim] authentication with PAM
Julian King <jpk28@???> wrote:
>
> > Exim does not initialize supplementary groups. Note the existence of the
> > "initgroups" option for deliveries etc. However, it doesn't initialize
> > them for its own uid. On some operating systems, in certain
> > configurations (e.g. Solaris using NIS), running initgroups() is a
> > really expensive operation.
>
> <grumble> Only cos Sun haven't fixed their code for about 10 years.
> As can be seen from the comments in their source code.</grumble>


Specifically the problem arises if "nis" appears in the "group" entry
in /etc/nsswitch.conf, and the map is of significant size.

<jam-tomorrow>
There is an official rumour that there will be an option in Solaris 9 to
have initgroups() use the netid map as a reverse index from uid to group
list, as was done in SunOS4.1.x of blessed (not!) memory, and that it
*might* even get retrofitted to Solaris 8.
</jam-tomorrow>

Chris Thompson
Email: cet1@???