'\" t .\" Title: login.defs .\" Author: Julianne Frances Haugh .\" Generator: DocBook XSL Stylesheets vsnapshot .\" Date: 30/07/2026 .\" Manual: File Formats and Configuration Files .\" Source: shadow-utils 4.20.0 .\" Language: Ukrainian .\" .TH "login\&.defs" "5" "30/07/2026" "shadow\-utils 4\&.20\&.0" "File Formats and Configuration" .\" ----------------------------------------------------------------- .\" * Define some portability stuff .\" ----------------------------------------------------------------- .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .\" http://bugs.debian.org/507673 .\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .ie \n(.g .ds Aq \(aq .el .ds Aq ' .\" ----------------------------------------------------------------- .\" * set default formatting .\" ----------------------------------------------------------------- .\" disable hyphenation .nh .\" disable justification (adjust text to left margin only) .ad l .\" ----------------------------------------------------------------- .\" * MAIN CONTENT STARTS HERE * .\" ----------------------------------------------------------------- .SH "НАЗВА" login.defs \- Налаштування комплексу для роботи з прихованими паролями .SH "ОПИС" .PP The /etc/login\&.defs file defines the site\-specific configuration for the shadow password suite\&. This file is required\&. Absence of this file will not prevent system operation, but will probably result in undesirable operation\&. .PP Цей файл є придатним до читання текстовим файлом, кожен з рядків якого описує один параметр налаштувань\&. Рядки складаються з назви налаштування та значення, які відокремлено пробілом\&. Порожні рядки і рядки коментарів буде проігноровано\&. Коментарі позначають символом \(Fo#\(Fc, цей символ має бути першим непробільним символом рядка\&. .PP Parameter values may be of four types: strings, booleans, numbers, and long numbers\&. A string is comprised of any printable characters\&. A boolean should be either the value \fIyes\fR or \fIno\fR\&. An undefined boolean parameter or one with a value other than these will be given a \fIno\fR value\&. Numbers (both regular and long) may be either decimal values, octal values (precede the value with \fI0\fR) or hexadecimal values (precede the value with \fI0x\fR)\&. The maximum value of the regular and long numeric parameters is machine\-dependent\&. .PP This configuration file controls the behavior of system tools for user and group management\&. The parameters may be used by shadow\-utils programs, PAM modules, and other system components\&. The actual behavior depends on the system configuration and which authentication mechanisms are enabled\&. .PP У ваше розпорядження надано такі пункти налаштувань: .PP \fBCHFN_RESTRICT\fR (string) .RS 4 This parameter specifies which values in the \fIgecos\fR field of the /etc/passwd file may be changed by regular users using the \fBchfn\fR program\&. It can be any combination of letters \fIf\fR, \fIr\fR, \fIw\fR, \fIh\fR, for Full name, Room number, Work phone, and Home phone, respectively\&. For backward compatibility, \fIyes\fR is equivalent to \fIrwh\fR and \fIno\fR is equivalent to \fIfrwh\fR\&. If not specified, only the superuser can make any changes\&. The most restrictive setting is better achieved by not installing \fBchfn\fR SUID\&. .RE .PP \fBCREATE_HOME\fR (boolean) .RS 4 Визначає, чи слід створювати типовий домашній каталог для створених записів користувачів\&. .sp Цей параметр не стосується загальносистемних користувачів; його можна перевизначити у рядку команди\&. .RE .PP \fBDEFAULT_HOME\fR (boolean) .RS 4 Вказує на те, ви можливий вхід, якщо неможливо перейти до домашнього каталогу\&. Типовим варіантом є \(Foні, неможливий\(Fc\&. .sp If set to \fIyes\fR, the user will login in the root (/) directory if it is not possible to cd to her home directory\&. .RE .PP \fBENCRYPT_METHOD\fR (string) .RS 4 This defines the system default encryption algorithm for encrypting passwords (if no algorithm is specified on the command line)\&. .sp It can take one of these values: \fISHA256\fR, \fISHA512\fR (default), \fIYESCRYPT\fR\&. See crypt(5) for recommendations\&. .sp Note: this only affects the generation of group passwords\&. The generation of user passwords is done by PAM and subject to the PAM configuration\&. It is recommended to set this variable consistently with the PAM configuration\&. .sp History: This variable is used by other programs, which may still default to unsafe algorithms such as DES\&. To avoid using unsafe algorithms, the variable should always be specified\&. .RE .PP \fBENV_PATH\fR (string) .RS 4 If set, it will be used to define the PATH environment variable when a regular user login\&. The value is a colon separated list of paths (for example \fI/bin:/usr/bin\fR) and can be preceded by \fIPATH=\fR\&. The default value is \fIPATH=/bin:/usr/bin\fR\&. .RE .PP \fBENV_SUPATH\fR (string) .RS 4 If set, it will be used to define the PATH environment variable when the superuser login\&. The value is a colon separated list of paths (for example \fI/sbin:/bin:/usr/sbin:/usr/bin\fR) and can be preceded by \fIPATH=\fR\&. The default value is \fIPATH=/sbin:/bin:/usr/sbin:/usr/bin\fR\&. .RE .PP \fBFAIL_DELAY\fR (number) .RS 4 Затримка у секундах, перш ніж буде дозволено повторну спробу після невдалої спроби увійти\&. .RE .PP \fBGID_MAX\fR (number), \fBGID_MIN\fR (number) .RS 4 Range of group IDs used for the creation of regular groups by \fBuseradd\fR, \fBgroupadd\fR, or \fBnewusers\fR\&. .sp The default value for \fBGID_MIN\fR (resp\&. \fBGID_MAX\fR) is 1000 (resp\&. 60000)\&. .RE .PP \fBHOME_MODE\fR (number) .RS 4 The mode for new home directories\&. If not specified, the \fBUMASK\fR is used to create the mode\&. .sp \fBuseradd\fR and \fBnewusers\fR use this to set the mode of the home directory they create\&. .RE .PP \fBHUSHLOGIN_FILE\fR (string) .RS 4 Якщо визначено, цей файл може прибрати увесь звичайний обмін повідомленнями під час послідовності входу до системи\&. Якщо вказано повний шлях до файла, тихий режим буде увімкнено, якщо у файлі буде знайдено ім\*(Aqя або командну оболонку користувача\&. Якщо повний шлях вказано не буде, тихий режим буде увімкнено, якщо файл зберігається у домашньому каталозі користувача\&. .RE .PP \fBLASTLOG_UID_MAX\fR (number) .RS 4 Найбільший числовий ідентифікатор користувача, для якого має бути оновлено записи lastlog\&. Оскільки великі числові ідентифікатори користувачів, зазвичай, відповідають профілям віддалених користувачів і службам розпізнавання, немає потреби створювати для них величезні розріджені файли lastlog\&. .sp No \fBLASTLOG_UID_MAX\fR option present in the configuration means that there is no user ID limit for writing lastlog entries\&. .RE .PP \fBLOG_UNKFAIL_ENAB\fR (boolean) .RS 4 Увімкнути показ невідомих імен користувачів, якщо ведеться запис невдалих спроб увійти до системи\&. .sp Зауваження: записування до журналу невідомих імен користувачів може знизити рівень захисту системи: користувач може ввести пароль замість власного імені\&. .RE .PP \fBLOGIN_RETRIES\fR (number) .RS 4 Максимальна кількість можливих повторних спроб увійти, якщо пароль вказано неправильно\&. .sp Це значення, найімовірніше, буде перевизначено PAM, оскільки у типового модуля pam_unix є своє вбудоване значення \(em 3 спроби\&. Втім, це безпечне резервне значення, якщо ви використовуєте модуль розпізнавання, який не визначає примусово PAM_MAXTRIES\&. .RE .PP \fBLOGIN_TIMEOUT\fR (number) .RS 4 Максимальний час на вхід у секундах\&. .RE .PP \fBMAIL_DIR\fR (string) .RS 4 The mail spool directory\&. This is needed to manipulate the mailbox when its corresponding user account is modified or deleted\&. If not specified, a compile\-time default is used\&. The parameter CREATE_MAIL_SPOOL in /etc/default/useradd determines whether the mail spool should be created\&. .RE .PP \fBMAIL_FILE\fR (string) .RS 4 Визначає місце файлів буферів пошти користувачів відносно домашнього каталогу\&. .RE .PP The \fBMAIL_DIR\fR and \fBMAIL_FILE\fR variables are used by \fBuseradd\fR, \fBusermod\fR, and \fBuserdel\fR to create, move, or delete the user\*(Aqs mail spool\&. .PP \fBMAX_MEMBERS_PER_GROUP\fR (number) .RS 4 Maximum members per group entry\&. When the maximum is reached, a new group entry (line) is started in /etc/group (with the same name, same password, and same GID)\&. .sp Типовий є значення 0, що означає, що обмеження на кількість учасників у групі не накладатимуться\&. .sp Ця можливість (поділ груп) призначено для обмеження довжини рядків у файлі груп\&. Це корисно для забезпечення того, щоб рядки у групах NIS не ставали довшими за 1024 символів\&. .sp Якщо вам потрібно примусово встановити таке обмеження, ви можете скористатися значенням 25\&. .sp Зауваження: підтримку поділу груп не обов\*(Aqязково передбачено в усіх програмах (навіть у засобах комплексу Shadow)\&. Вам не слід користуватися цією змінною, якщо у ній немає потреби\&. .RE .PP \fBNONEXISTENT\fR (string) .RS 4 Якщо у загальносистемного облікового запису спеціально немає домашнього каталогу, можна вказати цей рядок у записі /etc/passwd для відповідного облікового запису на позначення цього\&. У результаті перевірка pwck не призведе до попередження щодо цього облікового запису\&. .RE .PP \fBPASS_MAX_DAYS\fR (number) .RS 4 Максимальна кількість днів, протягом яких можна користуватися паролем\&. Якщо вік пароля перевищить вказаний, система вимагатиме від користувача змінити пароль\&. Якщо значення не вказано, буде використано значення \-1 (обмеження вимкнено)\&. .RE .PP \fBPASS_WARN_AGE\fR (number) .RS 4 The number of days warning given before a password expires\&. A zero means warning is given only upon the day of expiration, a value of \-1 means no warning is given\&. If not specified, no warning will be provided\&. .RE .PP \fBPASS_MAX_DAYS\fR, and \fBPASS_WARN_AGE\fR are only used at the time of account creation\&. Any changes to these settings won\*(Aqt affect existing accounts\&. .PP \fBSHA_CRYPT_MIN_ROUNDS\fR (number), \fBSHA_CRYPT_MAX_ROUNDS\fR (number) .RS 4 When \fBENCRYPT_METHOD\fR is set to \fISHA256\fR or \fISHA512\fR, this defines the number of SHA rounds used by the encryption algorithm by default (when the number of rounds is not specified on the command line)\&. .sp With a lot of rounds, it is more difficult to brute force the password\&. But note also that more CPU resources will be needed to authenticate users\&. .sp Якщо не вказано, libc вибере типову кількість проходів (5000), а це значення, що на порядки нижче за можливості сучасного обладнання\&. .sp Значення мають перебувати у діапазоні 1000\-999999999\&. .sp If only one of the \fBSHA_CRYPT_MIN_ROUNDS\fR or \fBSHA_CRYPT_MAX_ROUNDS\fR values is set, then this value will be used\&. .sp If \fBSHA_CRYPT_MIN_ROUNDS\fR > \fBSHA_CRYPT_MAX_ROUNDS\fR, the highest value will be used\&. .sp Note: this only affect the generation of group passwords\&. The generation of user passwords is done by PAM and subject to the PAM configuration\&. It is recommended to set this variable consistently with the PAM configuration\&. .RE .PP \fBSUB_GID_MIN\fR (number), \fBSUB_GID_MAX\fR (number), \fBSUB_GID_COUNT\fR (number) .RS 4 If /etc/subuid exists, the commands \fBuseradd\fR and \fBnewusers\fR (unless the user already have subordinate group IDs) allocate \fBSUB_GID_COUNT\fR unused group IDs from the range \fBSUB_GID_MIN\fR to \fBSUB_GID_MAX\fR for each new user\&. .sp The default values for \fBSUB_GID_MIN\fR, \fBSUB_GID_MAX\fR, \fBSUB_GID_COUNT\fR are respectively 100000, 600100000 and 65536\&. .RE .PP \fBSUB_GID_DETERMINISTIC\fR (boolean) .RS 4 If set to \fIyes\fR, the commands \fBuseradd\fR, \fBusermod\fR, and \fBnewusers\fR will calculate subordinate GID ranges deterministically based on the user\*(Aqs UID instead of searching for the next free range\&. The formula used is: .sp .if n \{\ .RS 4 .\} .nf start = SUB_GID_MIN + ((UID \- UID_MIN) * SUB_GID_COUNT) end = start + SUB_GID_COUNT \- 1 .fi .if n \{\ .RE .\} .sp This ensures the same UID always receives the same subordinate GID range on every system, making it suitable for environments with centralized user management (LDAP, NIS, etc\&.) or synchronized UIDs across systems\&. .sp If \fBSUB_GID_DETERMINISTIC\fR is enabled, you can use \fBusermod \-\-add\-subgids \-S\fR to produce deterministic subgids\&. .sp \fBWARNING\fR: Because \fBUID_MIN\fR is used to calculate the ranges, any change of \fBUID_MIN\fR will change the ranges calculated\&. \fBSUB_GID_COUNT\fR is used to calculate the ranges, any change of \fBSUB_GID_COUNT\fR will change the ranges calculated\&. Users with identities less than \fBUID_MIN\fR are incompatible with \fBSUB_GID_DETERMINISTIC\fR, but can still be set manually\&. .sp \fBWARNING\fR: Do not mix deterministic and linear (default) allocation on the same system or across systems sharing /etc/subgid via network storage (NFS, etc\&.)\&. Mixing allocation methods \fB will cause subordinate ID range conflicts and overlaps \fR\&. .sp The default value for \fBSUB_GID_DETERMINISTIC\fR is \fIno\fR\&. .SS "Range Calculation Examples" With default configuration (\fBUID_MIN\fR=1000, \fBSUB_GID_MIN\fR=100000, \fBSUB_GID_COUNT\fR=65536): .TS allbox tab(:); lB lB lB. T{ UID T}:T{ Calculation T}:T{ Subordinate GID Range T} .T& l l l l l l l l l l l l. T{ 1000 T}:T{ 100000 + ((1000\-1000) * 65536) T}:T{ 100000\-165535 T} T{ 1001 T}:T{ 100000 + ((1001\-1000) * 65536) T}:T{ 165536\-231071 T} T{ 1002 T}:T{ 100000 + ((1002\-1000) * 65536) T}:T{ 231072\-296607 T} T{ 1100 T}:T{ 100000 + ((1100\-1000) * 65536) T}:T{ 6653600\-6719135 T} .TE .sp 1 .SS "Subordinate ID Space Planning" When planning subordinate ID allocation, calculate the maximum number of users the space can accommodate: .sp .if n \{\ .RS 4 .\} .nf capacity = (SUB_GID_MAX \- SUB_GID_MIN) / SUB_GID_COUNT .fi .if n \{\ .RE .\} .sp With default values: (600100000 \- 100000) / 65536 ≈ 9155 users\&. .sp For high\-density environments with many users and smaller allocations: .sp .if n \{\ .RS 4 .\} .nf SUB_GID_COUNT 4096 SUB_GID_MIN 100000 SUB_GID_MAX 10000000 .fi .if n \{\ .RE .\} .sp This gives: (10000000 \- 100000) / 4096 ≈ 2417 users\&. .RE .PP \fBUNSAFE_SUB_GID_DETERMINISTIC_WRAP\fR (boolean) .RS 4 \fB WARNING: SECURITY RISK \- MAY CAUSE RANGE OVERLAPS AND PRIVILEGE ESCALATION! \fR .sp Only effective when \fBSUB_GID_DETERMINISTIC\fR is set to \fIyes\fR\&. .sp When set to \fIyes\fR (WRAP MODE), allows the deterministic range calculation to wrap around using modulo arithmetic when a UID would overflow the configured subordinate ID space\&. The subordinate ID space is treated as a ring buffer\&. .sp \fBWARNING\fR: Range overlaps can lead to container escapes and privilege escalation\&. For example, with \fBSUB_GID_MIN\fR=100000, \fBSUB_GID_MAX\fR=200000, \fBSUB_GID_COUNT\fR=65536, User A (UID 1000) gets range [100000, 165535] and User B (UID 1001) wraps and overlaps with User A\&. User B\*(Aqs container can now access files from User A\*(Aqs containers\&. .sp Use \fBonly\fR in development, testing, or tightly constrained lab environments\&. .sp When set to \fIno\fR (default), any arithmetic overflow or range exceeding \fBSUB_GID_MAX\fR is a hard error\&. This guarantees non\-overlapping, monotonic allocation\&. .sp The default value for \fBUNSAFE_SUB_GID_DETERMINISTIC_WRAP\fR is \fIno\fR\&. .RE .PP \fBSUB_GID_STORE_BY_UID\fR (boolean) .RS 4 If set to \fIyes\fR, subordinate group ID entries in /etc/subgid are stored using the numeric user ID rather than the username\&. The default value is \fIno\fR\&. .RE .PP \fBSUB_UID_MIN\fR (number), \fBSUB_UID_MAX\fR (number), \fBSUB_UID_COUNT\fR (number) .RS 4 If /etc/subuid exists, the commands \fBuseradd\fR and \fBnewusers\fR (unless the user already have subordinate user IDs) allocate \fBSUB_UID_COUNT\fR unused user IDs from the range \fBSUB_UID_MIN\fR to \fBSUB_UID_MAX\fR for each new user\&. .sp The default values for \fBSUB_UID_MIN\fR, \fBSUB_UID_MAX\fR, \fBSUB_UID_COUNT\fR are respectively 100000, 600100000 and 65536\&. .RE .PP \fBSUB_UID_DETERMINISTIC\fR (boolean) .RS 4 If set to \fIyes\fR, the commands \fBuseradd\fR, \fBusermod\fR, and \fBnewusers\fR will calculate subordinate UID ranges deterministically based on the user\*(Aqs UID instead of searching for the next free range\&. The formula used is: .sp .if n \{\ .RS 4 .\} .nf start = SUB_UID_MIN + ((UID \- UID_MIN) * SUB_UID_COUNT) end = start + SUB_UID_COUNT \- 1 .fi .if n \{\ .RE .\} .sp This ensures the same UID always receives the same subordinate UID range on every system, making it suitable for environments with centralized user management (LDAP, NIS, etc\&.) or synchronized UIDs across systems\&. .sp If \fBSUB_UID_DETERMINISTIC\fR is enabled, you can use \fBusermod \-\-add\-subuids \-S\fR to produce deterministic subuids\&. .sp \fBWARNING\fR: Because \fBUID_MIN\fR is used to calculate the ranges, any change of \fBUID_MIN\fR will change the ranges calculated\&. \fBSUB_UID_COUNT\fR is used to calculate the ranges, any change of \fBSUB_UID_COUNT\fR will change the ranges calculated\&. Users with identities less than \fBUID_MIN\fR are incompatible with \fBSUB_UID_DETERMINISTIC\fR, but can still be set manually\&. .sp \fBWARNING\fR: Do not mix deterministic and linear (default) allocation on the same system or across systems sharing /etc/subuid via network storage (NFS, etc\&.)\&. Mixing allocation methods \fB will cause subordinate ID range conflicts and overlaps \fR\&. .sp The default value for \fBSUB_UID_DETERMINISTIC\fR is \fIno\fR\&. .SS "Range Calculation Examples" With default configuration (\fBUID_MIN\fR=1000, \fBSUB_UID_MIN\fR=100000, \fBSUB_UID_COUNT\fR=65536): .TS allbox tab(:); lB lB lB. T{ UID T}:T{ Calculation T}:T{ Subordinate UID Range T} .T& l l l l l l l l l l l l. T{ 1000 T}:T{ 100000 + ((1000\-1000) * 65536) T}:T{ 100000\-165535 T} T{ 1001 T}:T{ 100000 + ((1001\-1000) * 65536) T}:T{ 165536\-231071 T} T{ 1002 T}:T{ 100000 + ((1002\-1000) * 65536) T}:T{ 231072\-296607 T} T{ 1100 T}:T{ 100000 + ((1100\-1000) * 65536) T}:T{ 6653600\-6719135 T} .TE .sp 1 .SS "Subordinate ID Space Planning" When planning subordinate ID allocation, calculate the maximum number of users the space can accommodate: .sp .if n \{\ .RS 4 .\} .nf capacity = (SUB_UID_MAX \- SUB_UID_MIN) / SUB_UID_COUNT .fi .if n \{\ .RE .\} .sp With default values: (600100000 \- 100000) / 65536 ≈ 9155 users\&. .sp For high\-density environments with many users and smaller allocations: .sp .if n \{\ .RS 4 .\} .nf SUB_UID_COUNT 4096 SUB_UID_MIN 100000 SUB_UID_MAX 10000000 .fi .if n \{\ .RE .\} .sp This gives: (10000000 \- 100000) / 4096 ≈ 2417 users\&. .RE .PP \fBUNSAFE_SUB_UID_DETERMINISTIC_WRAP\fR (boolean) .RS 4 \fB WARNING: SECURITY RISK \- MAY CAUSE RANGE OVERLAPS AND PRIVILEGE ESCALATION! \fR .sp Only effective when \fBSUB_UID_DETERMINISTIC\fR is set to \fIyes\fR\&. .sp When set to \fIyes\fR (WRAP MODE), allows the deterministic range calculation to wrap around using modulo arithmetic when a UID would overflow the configured subordinate ID space\&. The subordinate ID space is treated as a ring buffer\&. .sp \fBWARNING\fR: Range overlaps can lead to container escapes and privilege escalation\&. For example, with \fBSUB_UID_MIN\fR=100000, \fBSUB_UID_MAX\fR=200000, \fBSUB_UID_COUNT\fR=65536, User A (UID 1000) gets range [100000, 165535] and User B (UID 1001) wraps and overlaps with User A\&. User B\*(Aqs container can now access files from User A\*(Aqs containers\&. .sp Use \fBonly\fR in development, testing, or tightly constrained lab environments\&. .sp When set to \fIno\fR (default), any arithmetic overflow or range exceeding \fBSUB_UID_MAX\fR is a hard error\&. This guarantees non\-overlapping, monotonic allocation\&. .sp The default value for \fBUNSAFE_SUB_UID_DETERMINISTIC_WRAP\fR is \fIno\fR\&. .RE .PP \fBSUB_UID_STORE_BY_UID\fR (boolean) .RS 4 If set to \fIyes\fR, subordinate user ID entries in /etc/subuid are stored using the numeric user ID rather than the username\&. The default value is \fIno\fR\&. .RE .PP \fBSYS_GID_MAX\fR (number), \fBSYS_GID_MIN\fR (number) .RS 4 Range of group IDs used for the creation of system groups by \fBuseradd\fR, \fBgroupadd\fR, or \fBnewusers\fR\&. .sp The default value for \fBSYS_GID_MIN\fR (resp\&. \fBSYS_GID_MAX\fR) is 101 (resp\&. \fBGID_MIN\fR\-1)\&. .RE .PP \fBSYS_UID_MAX\fR (number), \fBSYS_UID_MIN\fR (number) .RS 4 Range of user IDs used for the creation of system users by \fBuseradd\fR or \fBnewusers\fR\&. .sp The default value for \fBSYS_UID_MIN\fR (resp\&. \fBSYS_UID_MAX\fR) is 101 (resp\&. \fBUID_MIN\fR\-1)\&. .RE .PP \fBSYSLOG_SG_ENAB\fR (boolean) .RS 4 Enable "syslog" logging of \fBsg\fR activity\&. .RE .PP \fBTTYGROUP\fR (string), \fBTTYPERM\fR (number) .RS 4 The terminal permissions: the login tty will be owned by the \fBTTYGROUP\fR group, and the permissions will be set to \fBTTYPERM\fR\&. .sp \fBTTYGROUP\fR can be either the name of a group or a numeric group identifier\&. .sp If TTYGROUP is not defined, then the group ownership of the terminal is set to the user\*(Aqs primary group\&. If TTYPERM is not defined, then the permissions are set to \fI0600\fR\&. .sp If you have a \fBwrite\fR program which is "setgid" to a special group which owns the terminals, define TTYGROUP to the group number and TTYPERM to 0620\&. Otherwise leave TTYGROUP commented out and assign TTYPERM to either 622 or 600\&. .RE .PP \fBUID_MAX\fR (number), \fBUID_MIN\fR (number) .RS 4 Range of user IDs used for the creation of regular users by \fBuseradd\fR or \fBnewusers\fR\&. .sp The default value for \fBUID_MIN\fR (resp\&. \fBUID_MAX\fR) is 1000 (resp\&. 60000)\&. .RE .PP \fBUMASK\fR (number) .RS 4 Маску режиму доступу для створення файлів буде встановлено у це значення\&. Якщо не вказано, маску буде ініціалізовано у значення 022\&. .sp \fBuseradd\fR and \fBnewusers\fR use this mask to set the mode of the home directory they create if \fBHOME_MODE\fR is not set\&. .sp It is also used by \fBpam_umask\fR as the default umask value\&. .RE .PP \fBUSERDEL_CMD\fR (string) .RS 4 Якщо визначено, цю команду буде запущено при вилученні користувача\&. Вона має вилучити усі завдання at, cron, друку тощо, власником яких є користувач, обліковий запис якого буде вилучено (буде передано як перший аргумент)\&. .sp Код, повернутий скриптом, не буде взято до уваги\&. .sp Ось приклад скрипту, який вилучає завдання cron, at і друку користувача: .sp .if n \{\ .RS 4 .\} .nf #! /bin/sh # Перевіряємо обов\*(Aqязковий аргумент\&. if [ $# != 1 ]; then echo "Usage: $0 username" exit 1 fi # Вилучити завдання cron\&. crontab \-r \-u $1 # Вилучити завдання at\&. # Зауважте, що буде вилучено усі завдання, власником яких є той самий UID, # навіть якщо вони є спільними із іншим користувачем\&. AT_SPOOL_DIR=/var/spool/cron/atjobs find $AT_SPOOL_DIR \-name "[^\&.]*" \-type f \-user $1 \-delete \e; # Вилучити завдання друку\&. lprm $1 # Готово\&. exit 0 .fi .if n \{\ .RE .\} .RE .PP \fBUSERGROUPS_ENAB\fR (boolean) .RS 4 If set to \fIyes\fR, \fBuserdel\fR will remove the user\*(Aqs group if it contains no more members, and \fBuseradd\fR will create by default a group with the name of the user\&. .RE .PP \fBYESCRYPT_COST_FACTOR\fR (number) .RS 4 When \fBENCRYPT_METHOD\fR is set to \fIYESCRYPT\fR, this defines the cost factor used by the encryption algorithm by default (when the cost factor is not specified on the command line)\&. .sp With a high cost factor, it is more difficult to brute force the password\&. But note also that more CPU resources will be needed to authenticate users\&. .sp The value must be inside the 1\-11 range\&. .sp Note: this only affect the generation of group passwords\&. The generation of user passwords is done by PAM and subject to the PAM configuration\&. It is recommended to set this variable consistently with the PAM configuration\&. .RE .SH "ПЕРЕХРЕСНІ ПОСИЛАННЯ" .PP Наведені нижче посилання показують, які програми комплексу для роботи з паролями shadow використовують відповідні параметри\&. .PP chfn .RS 4 CHFN_RESTRICT .RE .PP chgpasswd .RS 4 ENCRYPT_METHOD MAX_MEMBERS_PER_GROUP SHA_CRYPT_MAX_ROUNDS SHA_CRYPT_MIN_ROUNDS YESCRYPT_COST_FACTOR .RE .PP chpasswd .RS 4 SHA_CRYPT_MAX_ROUNDS SHA_CRYPT_MIN_ROUNDS YESCRYPT_COST_FACTOR .RE .PP gpasswd .RS 4 ENCRYPT_METHOD MAX_MEMBERS_PER_GROUP SHA_CRYPT_MAX_ROUNDS SHA_CRYPT_MIN_ROUNDS YESCRYPT_COST_FACTOR .RE .PP groupadd .RS 4 GID_MAX GID_MIN MAX_MEMBERS_PER_GROUP SYS_GID_MAX SYS_GID_MIN .RE .PP groupdel .RS 4 MAX_MEMBERS_PER_GROUP .RE .PP groupmod .RS 4 MAX_MEMBERS_PER_GROUP .RE .PP grpck .RS 4 MAX_MEMBERS_PER_GROUP .RE .PP grpconv .RS 4 MAX_MEMBERS_PER_GROUP .RE .PP grpunconv .RS 4 MAX_MEMBERS_PER_GROUP .RE .PP lastlog .RS 4 LASTLOG_UID_MAX .RE .PP newgrp / sg .RS 4 SYSLOG_SG_ENAB .RE .PP newusers .RS 4 ENCRYPT_METHOD GID_MAX GID_MIN MAX_MEMBERS_PER_GROUP HOME_MODE PASS_MAX_DAYS PASS_WARN_AGE SHA_CRYPT_MAX_ROUNDS SHA_CRYPT_MIN_ROUNDS SUB_GID_COUNT SUB_GID_MAX SUB_GID_MIN SUB_GID_DETERMINISTIC SUB_GID_STORE_BY_UID SUB_UID_COUNT SUB_UID_MAX SUB_UID_MIN SUB_UID_DETERMINISTIC SUB_UID_STORE_BY_UID SYS_GID_MAX SYS_GID_MIN SYS_UID_MAX SYS_UID_MIN UID_MAX UID_MIN UMASK UNSAFE_SUB_GID_DETERMINISTIC_WRAP UNSAFE_SUB_UID_DETERMINISTIC_WRAP YESCRYPT_COST_FACTOR .RE .PP pwck .RS 4 PASS_MAX_DAYS PASS_WARN_AGE .RE .PP pwconv .RS 4 PASS_MAX_DAYS PASS_WARN_AGE .RE .PP useradd .RS 4 CREATE_HOME GID_MAX GID_MIN HOME_MODE LASTLOG_UID_MAX MAIL_DIR MAX_MEMBERS_PER_GROUP PASS_MAX_DAYS PASS_WARN_AGE SUB_GID_COUNT SUB_GID_MAX SUB_GID_MIN SUB_GID_DETERMINISTIC SUB_GID_STORE_BY_UID SUB_UID_COUNT SUB_UID_MAX SUB_UID_MIN SUB_UID_DETERMINISTIC SUB_UID_STORE_BY_UID SYS_GID_MAX SYS_GID_MIN SYS_UID_MAX SYS_UID_MIN UID_MAX UID_MIN UMASK UNSAFE_SUB_GID_DETERMINISTIC_WRAP UNSAFE_SUB_UID_DETERMINISTIC_WRAP .RE .PP userdel .RS 4 MAIL_DIR MAIL_FILE MAX_MEMBERS_PER_GROUP USERDEL_CMD USERGROUPS_ENAB .RE .PP usermod .RS 4 LASTLOG_UID_MAX MAIL_DIR MAIL_FILE MAX_MEMBERS_PER_GROUP SUB_GID_COUNT SUB_GID_MAX SUB_GID_MIN SUB_GID_DETERMINISTIC SUB_UID_COUNT SUB_UID_MAX SUB_UID_MIN SUB_UID_DETERMINISTIC UNSAFE_SUB_GID_DETERMINISTIC_WRAP UNSAFE_SUB_UID_DETERMINISTIC_WRAP .RE .SH "ВАДИ" .PP Much of the functionality that used to be provided by the shadow password suite is now handled by PAM\&. Thus, /etc/login\&.defs is no longer used by \fBpasswd\fR(1), or less used by \fBlogin\fR(1), and \fBsu\fR(1)\&. Please refer to the corresponding PAM configuration files instead\&. .SH "ДИВ\&. ТАКОЖ" .PP \fBlogin\fR(1), \fBpasswd\fR(1), \fBsu\fR(1), \fBpasswd\fR(5), \fBshadow\fR(5), \fBpam\fR(8)\&.