specified without a shadow file, and the group file can be specified without the gshadow file).
		
			
				
	
	
		
			252 lines
		
	
	
		
			6.9 KiB
		
	
	
	
		
			XML
		
	
	
	
	
	
			
		
		
	
	
			252 lines
		
	
	
		
			6.9 KiB
		
	
	
	
		
			XML
		
	
	
	
	
	
| <?xml version="1.0" encoding="UTF-8"?>
 | |
| <!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook V4.5//EN"
 | |
|   "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
 | |
| <!ENTITY PASS_MAX_DAYS         SYSTEM "login.defs.d/PASS_MAX_DAYS.xml">
 | |
| <!ENTITY PASS_MIN_DAYS         SYSTEM "login.defs.d/PASS_MIN_DAYS.xml">
 | |
| <!ENTITY PASS_WARN_AGE         SYSTEM "login.defs.d/PASS_WARN_AGE.xml">
 | |
| ]>
 | |
| <refentry id='pwck.8'>
 | |
|   <!-- $Id$ -->
 | |
|   <refmeta>
 | |
|     <refentrytitle>pwck</refentrytitle>
 | |
|     <manvolnum>8</manvolnum>
 | |
|     <refmiscinfo class="sectdesc">System Management Commands</refmiscinfo>
 | |
|   </refmeta>
 | |
|   <refnamediv id='name'>
 | |
|     <refname>pwck</refname>
 | |
|     <refpurpose>verify integrity of password files</refpurpose>
 | |
|   </refnamediv>
 | |
|   <!-- body begins here -->
 | |
|   <refsynopsisdiv id='synopsis'>
 | |
|     <cmdsynopsis>
 | |
|       <command>pwck</command>
 | |
|       <arg choice='opt'>-q </arg>
 | |
|       <arg choice='opt'>-s </arg>
 | |
|       <arg choice='opt'>
 | |
| 	<arg choice='plain'>
 | |
| 	  <replaceable>passwd</replaceable>
 | |
| 	</arg>
 | |
| 	<arg choice='opt'>
 | |
| 	  <arg choice='plain'>
 | |
| 	    <replaceable>shadow</replaceable>
 | |
| 	  </arg>
 | |
| 	</arg>
 | |
|       </arg>
 | |
|     </cmdsynopsis>
 | |
|     <cmdsynopsis>
 | |
|       <command>pwck</command>
 | |
|       <arg choice='opt'>-q </arg>
 | |
|       <arg choice='opt'>-r </arg>
 | |
|       <arg choice='opt'>
 | |
| 	<arg choice='plain'>
 | |
| 	  <replaceable>passwd</replaceable>
 | |
| 	</arg>
 | |
| 	<arg choice='plain'>
 | |
| 	  <replaceable>shadow</replaceable>
 | |
| 	</arg>
 | |
|       </arg>
 | |
|     </cmdsynopsis>
 | |
|   </refsynopsisdiv>
 | |
| 
 | |
|   <refsect1 id='description'>
 | |
|     <title>DESCRIPTION</title>
 | |
|     <para>
 | |
|       The <command>pwck</command> command verifies the integrity of the
 | |
|       system authentication information. All entries in the
 | |
|       <filename>/etc/passwd</filename> and <filename>/etc/shadow</filename>
 | |
|       are checked to see that the entry has the proper format and valid data
 | |
|       in each field. The user is prompted to delete entries that are
 | |
|       improperly formatted or which have other uncorrectable errors.
 | |
|     </para>
 | |
| 
 | |
|     <para>Checks are made to verify that each entry has:</para>
 | |
|     <itemizedlist mark='bullet'>
 | |
|       <listitem>
 | |
| 	<para>the correct number of fields</para>
 | |
|       </listitem>
 | |
|       <listitem>
 | |
| 	<para>a unique user name</para>
 | |
|       </listitem>
 | |
|       <listitem>
 | |
| 	<para>a valid user and group identifier</para>
 | |
|       </listitem>
 | |
|       <listitem>
 | |
| 	<para>a valid primary group</para>
 | |
|       </listitem>
 | |
|       <listitem>
 | |
| 	<para> a valid home directory</para>
 | |
|       </listitem>
 | |
|       <listitem>
 | |
| 	<para>a valid login shell</para>
 | |
|       </listitem>
 | |
|     </itemizedlist>
 | |
| 
 | |
|     <para>
 | |
|       The checks for correct number of fields and unique user name are
 | |
|       fatal. If the entry has the wrong number of fields, the user will be
 | |
|       prompted to delete the entire line. If the user does not answer
 | |
|       affirmatively, all further checks are bypassed. An entry with a
 | |
|       duplicated user name is prompted for deletion, but the remaining
 | |
|       checks will still be made. All other errors are warning and the user
 | |
|       is encouraged to run the <command>usermod</command> command to correct
 | |
|       the error.
 | |
|     </para>
 | |
| 
 | |
|     <para>
 | |
|       The commands which operate on the <filename>/etc/passwd</filename>
 | |
|       file are not able to alter corrupted or duplicated entries.
 | |
|       <command>pwck</command> should be used in those circumstances to
 | |
|       remove the offending entry.
 | |
|     </para>
 | |
|   </refsect1>
 | |
| 
 | |
|   <refsect1 id='options'>
 | |
|     <title>OPTIONS</title>
 | |
|     <para>
 | |
|       The options which apply to the <command>pwck</command> command are:
 | |
|     </para>
 | |
|     <variablelist remap='IP'>
 | |
|       <varlistentry>
 | |
| 	<term>
 | |
| 	  <option>-q</option>
 | |
| 	</term>
 | |
| 	<listitem>
 | |
| 	  <para>
 | |
| 	    Report errors only. The warnings which do not require any
 | |
| 	    action from the user won't be displayed.
 | |
| 	  </para>
 | |
| 	</listitem>
 | |
|       </varlistentry>
 | |
|       <varlistentry>
 | |
| 	<term>
 | |
| 	  <option>-r</option>
 | |
| 	</term>
 | |
| 	<listitem>
 | |
| 	  <para>
 | |
| 	    Execute the <command>pwck</command> command in read-only mode.
 | |
| 	  </para>
 | |
| 	</listitem>
 | |
|       </varlistentry>
 | |
|       <varlistentry>
 | |
| 	<term>
 | |
| 	  <option>-s</option>
 | |
| 	</term>
 | |
| 	<listitem>
 | |
| 	  <para>
 | |
| 	    Sort entries in <filename>/etc/passwd</filename> and
 | |
| 	    <filename>/etc/shadow</filename> by UID.
 | |
| 	  </para>
 | |
| 	</listitem>
 | |
|       </varlistentry>
 | |
|     </variablelist>
 | |
| 
 | |
|     <para>
 | |
|       By default, <command>pwck</command> operates on the files
 | |
|       <filename>/etc/passwd</filename> and <filename>/etc/shadow</filename>.
 | |
|       The user may select alternate files with the <emphasis
 | |
|       remap='I'>passwd</emphasis> and <emphasis remap='I'>shadow</emphasis>
 | |
|       parameters.
 | |
|     </para>
 | |
|   </refsect1>
 | |
| 
 | |
|   <refsect1 id='configuration'>
 | |
|     <title>CONFIGURATION</title>
 | |
|     <para>
 | |
|       The following configuration variables in
 | |
|       <filename>/etc/login.defs</filename> change the behavior of this
 | |
|       tool:
 | |
|     </para>
 | |
|     <variablelist>
 | |
|       &PASS_MAX_DAYS;
 | |
|       &PASS_MIN_DAYS;
 | |
|       &PASS_WARN_AGE;
 | |
|     </variablelist>
 | |
|   </refsect1>
 | |
| 
 | |
|   <refsect1 id='files'>
 | |
|     <title>FILES</title>
 | |
|     <variablelist>
 | |
|       <varlistentry>
 | |
| 	<term><filename>/etc/group</filename></term>
 | |
| 	<listitem>
 | |
| 	  <para>Group account information.</para>
 | |
| 	</listitem>
 | |
|       </varlistentry>
 | |
|       <varlistentry>
 | |
| 	<term><filename>/etc/passwd</filename></term>
 | |
| 	<listitem>
 | |
| 	  <para>User account information.</para>
 | |
| 	</listitem>
 | |
|       </varlistentry>
 | |
|       <varlistentry>
 | |
| 	<term><filename>/etc/shadow</filename></term>
 | |
| 	<listitem>
 | |
| 	  <para>Secure user account information.</para>
 | |
| 	</listitem>
 | |
|       </varlistentry>
 | |
|     </variablelist>
 | |
|   </refsect1>
 | |
| 
 | |
|   <refsect1 id='see_also'>
 | |
|     <title>SEE ALSO</title>
 | |
|     <para><citerefentry>
 | |
| 	<refentrytitle>group</refentrytitle><manvolnum>5</manvolnum>
 | |
|       </citerefentry>,
 | |
|       <citerefentry>
 | |
| 	<refentrytitle>passwd</refentrytitle><manvolnum>5</manvolnum>
 | |
|       </citerefentry>,
 | |
|       <citerefentry>
 | |
| 	<refentrytitle>shadow</refentrytitle><manvolnum>5</manvolnum>
 | |
|       </citerefentry>,
 | |
|       <citerefentry>
 | |
| 	<refentrytitle>usermod</refentrytitle><manvolnum>8</manvolnum>
 | |
|       </citerefentry>.
 | |
|     </para>
 | |
|   </refsect1>
 | |
| 
 | |
|   <refsect1 id='exit_values'>
 | |
|     <title>EXIT VALUES</title>
 | |
|     <para>
 | |
|       The <command>pwck</command> command exits with the following values:
 | |
|       <variablelist>
 | |
| 	<varlistentry>
 | |
| 	  <term><replaceable>0</replaceable></term>
 | |
| 	  <listitem>
 | |
| 	    <para>success</para>
 | |
| 	  </listitem>
 | |
| 	</varlistentry>
 | |
| 	<varlistentry>
 | |
| 	  <term><replaceable>1</replaceable></term>
 | |
| 	  <listitem>
 | |
| 	    <para>invalid command syntax</para>
 | |
| 	  </listitem>
 | |
| 	</varlistentry>
 | |
| 	<varlistentry>
 | |
| 	  <term><replaceable>2</replaceable></term>
 | |
| 	  <listitem>
 | |
| 	    <para>one or more bad password entries</para>
 | |
| 	  </listitem>
 | |
| 	</varlistentry>
 | |
| 	<varlistentry>
 | |
| 	  <term><replaceable>3</replaceable></term>
 | |
| 	  <listitem>
 | |
| 	    <para>can't open password files</para>
 | |
| 	  </listitem>
 | |
| 	</varlistentry>
 | |
| 	<varlistentry>
 | |
| 	  <term><replaceable>4</replaceable></term>
 | |
| 	  <listitem>
 | |
| 	    <para>can't lock password files</para>
 | |
| 	  </listitem>
 | |
| 	</varlistentry>
 | |
| 	<varlistentry>
 | |
| 	  <term><replaceable>5</replaceable></term>
 | |
| 	  <listitem>
 | |
| 	    <para>can't update password files</para>
 | |
| 	  </listitem>
 | |
| 	</varlistentry>
 | |
|       </variablelist>
 | |
|     </para>
 | |
|   </refsect1>
 | |
| </refentry>
 |