There are a number of powerful user groups that are enabled to perform various administrative tasks such as manage a single Web site, manage your entire Web or mail server, or even manage the entire virtual server in the same way that you do. These groups are called special user groups. You can grant users very powerful access rights by making them members of these special user groups. Users that are members of these special user groups have access to modify key files on the system, and can run powerful administrative commands that we call super commands.
SECURITY ALERT:
It is absolutely critical that you do not make a user a member of one of these special user groups unless you have a specific need to do so and you trust the user completely. A user who is empowered to use ANY of the super commands can cause a great deal of damage to your system if they choose to do so. The special user groups are available for convenience only. Do not assume that a user who is a member of a special user group is limited only to commands and file access provided by membership in that group. It is not impossible for a user who is a member of a special user group to find a way to become a member of another, or gain additional control of the server through some other means.
The following is a list of the special user groups, the super commands they are allowed to execute, and the files and directories they have special write-access to. The user account that is initially set up for you when you order your Freedom server is sometimes referred to as the administrative user. The administrative user derives its power from being a member of all the special user groups and therefore has access to all of the super commands.
|
Group Name |
Description |
Commands |
Files / Directories |
|
sysadmin |
Users in the sysadmin group are empowered to perform general administrative tasks on your virtual server, including user and process management, as well as management of the filesystem as a whole. Sysadmins can also enable and disable network services that run from inetd. |
vadduser |
|
|
webadmin |
Users in the webadmin group are empowered to manage the Apache web server. This includes the ability to start and stop it, add new virtual hosts and Apache modules, and edit all of the Apache configuration files. These users do NOT have access to the main Web server logs. |
apachectl |
/www/conf/httpd.conf |
|
ftpadmin |
Users in the ftpadmin group are allowed to place files in the ftp root directory, thus making files available for download via anonymous FTP. Additionally the FTP admin can create welcome messages that are displayed to anonymous FTP users. |
|
/var/home/ftp/ |
|
mailadmin |
Users in the mailadmin group can edit the configuration files related to your sendmail server, as well as start and stop your mail service. |
mailctl |
/etc/mail/aliases |
|
pkgadmin |
Users in the pkgadmin group can install applications from our Software Application Library, and remove or reinstall packages that have been previously installed on your system. |
vinstall |
|
Each of the above super commands is described in more detail in other sections of this guide.