Dell Unity: Security Scan reports some fake user IDs [User correctable]
Summary: Some IDs such as Fake, nobody, c4, log, nogroup, admin, service, ECOM etc were found while scanning the Unity Array.
Symptoms
While in RedHat any GID above 1000 is not system created but manually created, So is it okay to delete these IDs.
Cause
Resolution
Unity is a restricted shell secured array and only support personnel are able to access the Linux system on the array. This is done to prevent unauthorized users from making changes to the system that could impact its stability or security.
All the users such as Admin, Apache, Fake, Service, Root, c4, log, etc are system related users and deleting them will impact the Operating system of Unity.
Additional Information
Purpose of some of the User IDs-
- The fake user is used by the operating system to create temporary files. These files are deleted automatically when the user logs out or the system is rebooted.
- The c4 user is used by the operating system for various purposes, such as managing the file system and running processes.
- The log user is used by the operating system to collect logs and other system data.
- The admin user is the default user for the Dell EMC Unity operating system. It has full privileges to the system and is used to manage the array.
- The nobody user and nogroup group are used by the operating system to represent users with the least privileges on the system. This means that they have no access to any files or directories unless they are explicitly granted permission.
The nobody user and nogroup group are often used for background tasks, such as logging events or managing files.
- The ECOM user ID is a system-related user that is used by the Dell EMC Unity operating system to manage the array.Here are some of the specific tasks that the ECOM user ID can be used for:
- Starting and stopping services
- Managing filesystem permissions
- Logging events
- Creating new users
- Modifying system settings