Subject: Re: /etc/passwd.conf
To: Jun-ichiro itojun Hagino <itojun@iijlab.net>
From: Jaromir Dolecek <jdolecek@NetBSD.org>
List: tech-security
Date: 08/15/2003 13:58:54
Jun-ichiro itojun Hagino wrote:
> 	given that DES is crackable in 3 seconds, i would like to propose the
> 	following change.  you can still use DES password entries, it only
> 	affects newly-created entries (like by passwd(1)).  what do people
> 	think?  (ypcipher is kept to "old" for backward compat)

I think this would be good for poeople who merge etc set changes
using etcupdate. It would be good to also change the sysinst so
that it would offer the blowfish cipher by default.

The libc default should stay on 'des' tho, IMHO. 

Jaromir
-- 
Jaromir Dolecek <jdolecek@NetBSD.org>            http://www.NetBSD.cz/
-=- We should be mindful of the potential goal, but as the tantric    -=-
-=- Buddhist masters say, ``You may notice during meditation that you -=-
-=- sometimes levitate or glow.   Do not let this distract you.''     -=-