域用户umask值与预期不符的排查求助
域用户umask值与预期不符的排查求助
我这边用LDAP和Kerberos管理着一个多用户的网络域环境,系统是Debian 10。为了让所有用户创建的文件默认带有组写权限(方便同组用户共享日志、运行协作应用),我通过PAM统一设置umask:在/etc/pam.d/common-session里添加了这一行配置:
session optional pam_umask.so umask=002
现在绝大多数用户执行umask命令都会返回0002,完全符合预期,但有一个用户是例外——他的umask始终是0022。这个用户和其他用户属于同一公共组,登录方式也没有区别,可他创建的文件没有组写权限,导致后续同组用户访问这些文件时频繁报错,已经影响到日常协作了。
我现在完全摸不着头绪,想请大家帮忙出出主意:我可能漏掉了哪些配置点?应该从哪些方向开始排查?
补充信息
我已经检查了这个异常用户的~/.profile,里面的umask设置是注释掉的,内容如下:
# ~/.profile: executed by the command interpreter for login shells. # This file is not read by bash(1), if ~/.bash_profile or ~/.bash_login # exists. # see /usr/share/doc/bash/examples/startup-files for examples. # the files are located in the bash-doc package. # the default umask is set in /etc/profile; for setting the umask # for ssh logins, install and configure the libpam-umask package. #umask 022 # if running bash if [ -n "$BASH_VERSION" ]; then # include .bashrc if it exists if [ -f "$HOME/.bashrc" ]; then . "$HOME/.bashrc" fi fi # set PATH so it includes user's private bin if it exists if [ -d "$HOME/bin" ] ; then PATH="$HOME/bin:$PATH" fi # set PATH so it includes user's private bin if it exists if [ -d "$HOME/.local/bin" ] ; then PATH="$HOME/.local/bin:$PATH" fi
目前我已经确认的点:
- 该用户的组归属和其他正常用户完全一致
- 他的登录方式(和其他用户一样是SSH远程登录)没有特殊配置
~/.profile里没有主动设置umask
备注:内容来源于stack exchange,提问作者tdpu
相关产品推荐
相关产品推荐

