Critical System Protection

 View Only

Symantec End Point spontaneously changed group to "avdefs", when some new change is introduced 

Mar 03, 2016 02:25 PM

I recently notice, Symantec End Point spontaneously changed group to "avdefs", when some new change is introduced e. g. creating new sftp directories etc.  It seems  problems occur during Symantec installation  "avdefs" is a group local to the system (i.e., not in LDAP), so it's important to have it not conflict with existing LDAP groups Pasted output below:

 

On stage-rtr1:
[root@stage-rtr1 ~]# grep avdefs /etc/group
avdefs:x:501:

[root@stage-rtr1 ~]# ldapsearch -x cn=cacheusr -b "ou=posixGroups,dc=healthix,dc=org"
...
gidNumber: 501
...
cn: cacheusr

 

During our conversation we came to a conclusion, the possible solution to this is:

 

  1. Prompt us to enter correct group number.

  2. Query LDAP database for unused Group numbers.

     

    Can code be modified so that “avdefs” group can be changed to a different group number.  We cannot change our software and there is a conflict between the two groups?

     

    Thanks,

    Michael   

 

 

Please feel free to contact me if any questions arise.

 

Michael Verbitsky

Systems Engineer

mverbitsky@healthix.org

 

 

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Related Entries and Links

No Related Resource entered.