<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.4//EN"
  "http://www.oasis-open.org/docbook/xml/4.4/docbookx.dtd" [
  <!ENTITY % general-entities SYSTEM "../../general.ent">
  %general-entities;
]>

<sect1 id="ch-boot-pwdgroup">
  <?dbhtml filename="pwdgroup.html"?>

  <title>Creating the passwd, group, and log Files</title>

  <indexterm zone="ch-boot-pwdgroup">
    <primary sortas="e-/etc/passwd">/etc/passwd</primary>
  </indexterm>

  <indexterm zone="ch-boot-pwdgroup">
    <primary sortas="e-/etc/group">/etc/group</primary>
  </indexterm>

  <indexterm zone="ch-boot-pwdgroup">
    <primary sortas="e-/var/run/utmp">/var/run/utmp</primary>
  </indexterm>

  <indexterm zone="ch-boot-pwdgroup">
    <primary sortas="e-/var/log/btmp">/var/log/btmp</primary>
  </indexterm>

  <indexterm zone="ch-boot-pwdgroup">
    <primary sortas="e-/var/log/lastlog">/var/log/lastlog</primary>
  </indexterm>

  <indexterm zone="ch-boot-pwdgroup">
    <primary sortas="e-/var/log/wtmp">/var/log/wtmp</primary>
  </indexterm>

  <para os="a">In order for user <systemitem class="username">root</systemitem> to
  be able to login and for the name <quote>root</quote> to be recognized,
  there must be relevant entries in the <filename>/etc/passwd</filename>
  and <filename>/etc/group</filename> files.</para>

  <para>Create the <filename>${CLFS}/etc/passwd</filename> file by running
  the following command:</para>

<screen><userinput>cat &gt; ${CLFS}/etc/passwd &lt;&lt; "EOF"
<literal>root::0:0:root:/root:/bin/bash</literal>
EOF</userinput></screen>

  <para os="b">The actual password for <systemitem class="username">root</systemitem>
  (the <quote>::</quote> used here is just a placeholder and allow you to login
  with no password) will be set later.</para>

  <variablelist os="c">
  
    <title>Additional users you may want to add:</title>

    <varlistentry>
      <term><literal>bin:x:1:1:bin:/bin:/bin/false</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>daemon:x:2:6:daemon:/sbin:/bin/false</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>adm:x:3:16:adm:/var/adm:/bin/false</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>lp:x:10:9:lp:/var/spool/lp:/bin/false</literal></term>
      <listitem>
        <para>Used by programs for printing</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>mail:x:30:30:mail:/var/mail:/bin/false</literal></term>
      <listitem>
        <para>Often used by email programs</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>news:x:31:31:news:/var/spool/news:/bin/false</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>uucp:x:32:32:uucp:/var/spool/uucp:/bin/false</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>operator:x:50:0:operator:/root:/bin/bash</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>postmaster:x:51:30:postmaster:/var/spool/mail:/bin/false</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>nobody:x:65534:65534:nobody:/:/bin/false</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
  </variablelist>

  <para>Create the <filename>${CLFS}/etc/group</filename> file by running
  the following command:</para>

<screen><userinput>cat &gt; ${CLFS}/etc/group &lt;&lt; "EOF"
<literal>root:x:0:
bin:x:1:
sys:x:2:
kmem:x:3:
tty:x:4:
tape:x:5:
daemon:x:6:
floppy:x:7:
disk:x:8:
lp:x:9:
dialout:x:10:
audio:x:11:
video:x:12:
utmp:x:13:
usb:x:14:
cdrom:x:15:</literal>
EOF</userinput></screen>

  <variablelist os="d">

    <title>Additional groups you may want to add</title>

    <varlistentry>
      <term><literal>adm:x:16:root,adm,daemon</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>console:x:17:</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>cdrw:x:18:</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>mail:x:30:mail</literal></term>
      <listitem>
        <para>Used by MTAs (Mail Transport Agents)</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>news:x:31:news</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>uucp:x:32:uucp</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>users:x:1000:</literal></term>
      <listitem>
        <para>The default GID used by shadow for new users</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>nogroup:x:65533:</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
    <varlistentry>
      <term><literal>nobody:x:65534:</literal></term>
      <listitem>
        <para>To be written</para>
      </listitem>
    </varlistentry>
  </variablelist>

  <para os="e">The created groups are not part of any standard&mdash;they are
  groups decided on in part by the requirements of the Udev configuration
  in the final system, and in part by common convention employed by a
  number of existing Linux distributions. The Linux Standard Base (LSB,
  available at <ulink url="http://www.linuxbase.org"/>) recommends only
  that, besides the group <quote>root</quote> with a Group ID (GID) of 0,
  a group <quote>bin</quote> with a GID of 1 be present. All other group
  names and GIDs can be chosen freely by the system administrator since
  well-written programs do not depend on GID numbers, but rather use the
  group's name.</para>

  <para os="f">The <command>login</command>, <command>agetty</command>, and
  <command>init</command> programs (and others) use a number of log
  files to record information such as who was logged into the system and
  when. However, these programs will not write to the log files if they
  do not already exist. Initialize the log files and give them
  proper permissions:</para>

<screen><userinput>touch ${CLFS}/var/run/utmp ${CLFS}/var/log/{btmp,lastlog,wtmp}
chmod -v 664 ${CLFS}/var/run/utmp ${CLFS}/var/log/lastlog
chmod -v 600 ${CLFS}/var/log/btmp</userinput></screen>

  <para>The <filename>/var/run/utmp</filename> file records the users
  that are currently logged in. The <filename>/var/log/wtmp</filename>
  file records all logins and logouts. The
  <filename>/var/log/lastlog</filename> file records when
  each user last logged in. The <filename>/var/log/btmp</filename> file
  records the bad login attempts.</para>

</sect1>
