tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

password strength checking



Would someone with some understanding of PAM please review my change
to libpam which fixes an old bug preventing the use of PAM modules
to check a password on attempts to change it. This is:

src/lib/libpam/modules/pam_unix/pam_unix.c rev. 1.14

I'd like to have this patch pulled up to at least the 5.x release
branch because "passwdqc" seems to be a popular tool for that
purpose (FreeBSD and DragonFly have added it to the base system
apparently), and it would look bad if it didn't work on our
official release.
passwdqc is in pkgsrc, and its homepage refers to the NetBSD port.

While we are here: I'd suggest to drop the pw_policy(3) stuff
in NetBSD's libutil. Its API (and the semantics of weighting the
strengths of a password) is so strange that I can't imagine
any use for it. Would you miss it?

best regards
Matthias



------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------
Forschungszentrum Juelich GmbH
52425 Juelich
Sitz der Gesellschaft: Juelich
Eingetragen im Handelsregister des Amtsgerichts Dueren Nr. HR B 3498
Vorsitzende des Aufsichtsrats: MinDir'in Baerbel Brumme-Bothe
Geschaeftsfuehrung: Prof. Dr. Achim Bachem (Vorsitzender),
Dr. Ulrich Krafft (stellv. Vorsitzender), Prof. Dr.-Ing. Harald Bolt,
Prof. Dr. Sebastian M. Schmidt
------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------


Home | Main Index | Thread Index | Old Index