- Breaking changes in 4.0.0
- Description
- Setup - The basics of getting started with useradd
- Usage - Configuration options and additional functionality
- Reference - An under-the-hood peek at what the module is doing and how
- Limitations - OS compatibility, etc.
- Deprecations
- Development - Guide for contributing to the module
include useradd no longer writes any file. Each setting is managed only when
its parameter is set, and an unset parameter leaves the system alone. The one
exception: the 3.x /etc/profile.d/simp.sh and simp.csh are removed (see
Login scripts).
To get the 3.x behavior back, either:
-
enforce the
simp:defaultscompliance profile, which ships with this module:compliance_engine::enforcement: - simp:defaults
-
or set the parameters you need in Hiera.
Values set in site Hiera take precedence over the profile.
/etc/login.defs,/etc/default/useradd,/etc/default/nss,/etc/libuser.confand/etc/sysconfig/initare edited one key per parameter.absentremoves a key./etc/securettyand/etc/shellsare edited one entry at a time, throughsecuretty_entriesandshells_entries.- Keys and entries the module doesn't set are kept, unless you turn on the
matching
purgeparameter.simp:defaultsturns them on. - An empty or whitespace-only
login_defsvalue (such as'') is skipped with a deprecation warning.login.defscan't hold a key with no value. - A value with a space or a leading quote that ends in a backslash, or has a
backslash before both a
"and a', fails compilation. Augeas can't write it; 3.x wrote it verbatim.
3.x wrote an empty value as the key alone on a line (such as
LOGIN_STRING, perhaps followed by whitespace), which can't be parsed. While
the parameter is still empty, the module removes that line. If you have
already removed the value from Hiera, remove the line by hand, or every
login_defs edit fails on it.
useradd::sysconfig_init::single_user_login writes the emergency and rescue
drop-ins with plain file resources and its own daemon-reload.
- The drop-in directories are purged only when
purge_dropinsistrue, or, withuseradd::sysconfig_init::systemd: true, whensystemd::purge_dropin_dirsis.simp:defaultssetssystemd: true, as in 3.x. - If another module declares a
systemd::dropin_fileonemergency.serviceorrescue.service, setuseradd::sysconfig_init::systemd: trueso both declare the directory the same way. Withoutsystemd: true,purge_dropins: truealso matches whilesystemd::purge_dropin_dirsis at its default; it removes the other drop-ins for those units, assystemd::dropin_filewould.
3.x always wrote UID_MIN, UID_MAX, GID_MIN and GID_MAX to
login.defs, from simp_options::uid/gid, else the current value, else
1000/1000000/1000/500000. 4.0.0 writes them only when set, directly or through
simp_options. simp:defaults doesn't set them.
- A host that already has the keys keeps its values.
- A
login.defsmissing a key no longer gets the 3.x fallback. Set the parameter to keep it.
/etc/profile.d/simp.sh and simp.csh are replaced by one file per setting
(simp-b-tmout.sh, zz-simp-umask.sh, and so on), simp:defaults included.
- The old files are always removed, by a bare include too, unless
useradd::manage_etc_profileisfalse. Set theuseradd::etc_profileparameters, or enforcesimp:defaults, to keepTMOUT,umaskandmesgat login. - The csh
prependnow runs after the other/etc/profile.dcsh scripts that sort aftersimp.csh. - A
prependthat returns early no longer skips the other settings.
These still work, and warn when set:
- the
manage_*parameters ofuseradd, wherefalsestill skips the class; securetty,shells_defaultandshells, replaced bysecuretty_entriesandshells_entries. As in 3.x, each owns its whole file, and the matching*_entriesandpurge_*parameters are ignored;useradd::etc_profile::manage_tmout;useradd::libuser_conf::userdefaultsandgroupdefaults, replaced byuserdefaults_settingsandgroupdefaults_settings. As in 3.x, each is its whole section, and the matching Hash is ignored.
See the CHANGELOG for the full list.
useradd is a Puppet module that manages settings regarding users and user creation.
This module is a component of the System Integrity Management Platform, a compliance-management framework built on Puppet.
If you find any issues, they may be submitted to our bug tracker.
This module is optimally designed for use within a larger SIMP ecosystem, but it can be used independently:
- When included within the SIMP ecosystem, security compliance settings will be managed from the Puppet server.
- If used independently, all SIMP-managed security subsystems are disabled by default and must be explicitly opted into by administrators. Please review the
$client_nets,$enable_*and$use_*parameters inmanifests/init.ppfor details.
This module can configure:
/etc/default/useradd/etc/group/etc/group-/etc/gshadow/etc/gshadow-/etc/libuser.conf/etc/login.defs/etc/passwd/etc/passwd-/etc/profile.d//etc/securetty/etc/shadow/etc/shadow-/etc/shells/etc/systemd/system/{emergency,rescue}.service.d/
Include the class and set the parameters you want managed, or enforce the
simp:defaults profile:
---
classes:
- useradd
compliance_engine::enforcement:
- simp:defaultsSet only what you want enforced. For example, to enforce a password age and an idle-session timeout and leave everything else alone:
---
useradd::login_defs::pass_max_days: 60
useradd::etc_profile::session_timeout: 15Removing a key from Hiera later leaves the value on the node. To remove it,
set it to absent:
---
useradd::login_defs::pass_max_days: absentLists are Hashes, merged across Hiera layers, so one layer can add or remove a single entry:
---
useradd::securetty_entries:
console: {}
tty4:
ensure: absentPlease refer to the REFERENCE.md.
As of version 1.0.0, this module will no longer manage /etc/security/opasswd. Version 7.0.0 and above of the SIMP PAM Module will allow users to specify the file they wish to store historical passwords in.
SIMP Puppet modules are generally intended for use on Red Hat Enterprise Linux and compatible distributions, such as CentOS. Please see the metadata.json file for the most up-to-date list of supported operating systems, Puppet versions, and module dependencies.
Please read our [Contribution Guide] (https://simp.readthedocs.io/en/stable/contributors_guide/index.html)