Gentoo Archives: gentoo-security

From: Henning Rohde <Rohde.Henning@×××.net>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] pam cracklib. Why credits are not working.
Date: Sun, 28 Nov 2004 17:02:56
Message-Id: 200411281802.09089.hr@our-home.net
In Reply to: [gentoo-security] pam cracklib. Why credits are not working. by Peter Volkov Alexandrovich
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Hi,
5
6 Am Sonntag, 28. November 2004 16:29 schrieb Peter Volkov Alexandrovich:
7 > cat /etc/pam.d/system-auth
8 > #%PAM-1.0
9 > ...
10 > password required /lib/security/pam_cracklib.so retry=3 diffok=3
11 > minlen=8 dccredit=2 upcredit=2 lcredit=2 ocredit=1 type=XXX
12 > password sufficient /lib/security/pam_unix.so nullok md5 shadow
13 > use_authtok
14 > password required /lib/security/pam_deny.so
15 ...
16 > So you see I want password to be more then 8 character long to have 2
17 > digits, 2 upper, 2 lower case and 1 other characters. Now as ordinary
18 > user I try to use passwd with password "qwertyuiop" and this works! Can
19 > anybody enlight me why I can use password without digits?
20
21 Please check the return-value of /bin/passwd:
22 it'll have non-zero $?, although the changing of your passwd has succeeded!
23 - -> http://www.kernel.org/pub/linux/libs/pam/Linux-PAM-html/pam-4.html#ss4.1
24
25 Please try:
26 # no further module should be executed after pam_cracklib has failed!
27 password requisite /lib/security/pam_cracklib.so ...
28
29 Just my 2 cents of €,
30
31 Henning
32 -----BEGIN PGP SIGNATURE-----
33 Version: GnuPG v1.2.6 (GNU/Linux)
34
35 iD8DBQFBqgSRuI8iUC+SACIRAo22AJ42kNXeFmyJRz04fuhZQdBtQip8qACgqAzF
36 I9jZVT7/2Cx19EVGQ7dpiGo=
37 =j4U7
38 -----END PGP SIGNATURE-----
39
40 --
41 gentoo-security@g.o mailing list