Re: Password expiration in Solaris

Darren J Moffat <[email protected]>
Newsgroups gmane.comp.security.sun
Message-ID <Pine.GSO.4.58.0309290922510.16745@braveheart>
On Fri, 26 Sep 2003, Paul Greene wrote:

> There appears to be two different ways to apply password expiration in
> Solaris; one is the parameters set in /etc/shadow (through admintool or
> command line), and the other is the password parameters set in
>  /etc/default/passwd.

The values in /etc/default/passwd are the defaults to be applied to
accounts that have no aging information on the next password change
(including the first setting of the password on a new account).

The values in /etc/shadow are the per user values.

> Which one takes precedence if both are configured?

If there are already entries in /etc/shadow for the account those values are
preserved.  If there are no entries AND /etc/default/passwd has values for
MINWEEKS, MAXWEEKS, WARNWEEKS then those are added to the entry in /etc/shadow
when that users password is changed, they witll take effect from that
moment onwards.

--
Darren J Moffat
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.