Re: [webmin-l] how to enforce assword restrictions for doma in owners?

"Jamie Cameron" <[email protected]>
Newsgroups gmane.comp.web.webmin.general
Message-ID <[email protected]>
Unfortunately, Webmin has no way to honor PAM restrictions as it doesn't
use PAM to change passwords - instead it updates files like /etc/shadow
directly.

On 15/Nov/2016 11:06 "Przemysław.Orzechowski" <[email protected]> wrote ..
> 
> Hi
> 
> I already tried to use those options, but i can't figure out how to get
> virtualmin to actually honor pam restrictions which are quie complex or
> rather use pam to change passwords (i would preffer this solution) when
> its
> done by domain owners on a mailbox account.
> 
> When its done using Usermin pam is used and everything works. 
> 
> I also had a strange error using pam auth (in webmin config Use Pam for
> Unix authentication and Support full pam conversations checked).
>  
> Randomly virtualmin refuses to accept credentials and i needed to login
> via ssh and restart webmin service, after a "service webmin restart" it
> works again for some time (hour or two)
> 
> When the error occurs sometimes webmin/vitrualmin is continuously
> displaing the page to enter username ans sometimes it asks for password but
> login fails.
> 
> could not find the problem except in authlog i got lines like this
> >Nov 15 19:37:19 panel9 webmin[11838]: Non-existent login as popo from
> 192.168.6.223
> this is the only log line if login fails
> 
> at same time im logged in as this same user using ssh 
> >Nov 15 19:36:16 panel9 sshd[11550]: pam_unix(sshd:session): session
> opened for user popo by (uid=0)
> >Nov 15 19:36:16 panel9 systemd-logind[1302]: New session 761 of user
> popo.
> >Nov 15 19:36:16 panel9 sshd[11550]: User child is on pid 11627
> >Nov 15 19:36:16 panel9 sshd[11627]: Starting session: shell on pts/0 for
> popo from 192.168.6.223 port 59770 id 0
> 
> current /etc.pam.d/webmin 
> #%PAM-1.0
> @include common-auth
> @include common-account
> @include common-password
> @include common-session
> 
> after restarting webmin i can login and get following lines 
> >Nov 15 19:45:46 panel9 perl[13648]: pam_sss(webmin:auth): authentication
> success; logname= uid=0 euid=0 tty= ruser= rhost= user=popo
> >Nov 15 19:45:47 panel9 perl[13648]: pam_unix(webmin:session): session
> opened for user popo by (uid=0)
> >Nov 15 19:45:47 panel9 webmin[13666]: Successful login as popo from
> 192.168.6.223
> 
> i also tried to change the @include common-session 
> to @include common-session-noninteractive but it did not help.
> 
> im open to any ideas how to debug and hopefully eliminate this problem
> 
> My platform is ubuntu 16.04 and i ussed the install.sh script for
> virtualmin GPL.
> 
> Regards 
> Przemyslaw Orzechowski
> 
> On Tue, 15 Nov 2016 09:22:30 -0800 (PST), "Jamie Cameron"
> <[email protected]> wrote:
> > On 15/Nov/2016 06:51 "Przemysław.Orzechowski"
> > <[email protected]> wrote ..
> >> 
> >> 
> >> Hi  
> >> 
> >> In usermin i set up a minimum complexity and password lenght
> >> (usermin is using PAM) so when mailbox user changes password PAM
> >> restrictins are enforced 
> >> 
> >> The problem is when Virtualmin domain owner
> >> changes password for said user he can enter a single char and the
> >> password
> >> is changed !!!  
> >> 
> >> Is there a way to applay same restrictions for this as in
> >> usermin? 
> > 
> > You can configure password restrictions at Webmin -> System -> Users and
> > Groups -> Module Config (the gear icon) -> Password restrictions.
> 
> 
> ------------------------------------------------------------------------------
> -
> Forwarded by the Webmin mailing list at [email protected]
> To remove yourself from this list, go to
> http://lists.sourceforge.net/lists/listinfo/webadmin-list

------------------------------------------------------------------------------

-
Forwarded by the Webmin mailing list at [email protected]
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.