Questions about passwords

Johann Spies <jspies-/[email protected]> Tue, 22 Jun 2004 10:35:55 +0200
Newsgroups gmane.linux.admin.managers
Message-ID <[email protected]>
My manager is drawing up a password policy for the different operating
systems on the campus.  He has asked a few questions about Linux's
handling of passwords which was not so easy to answer even after a lot
of googling and reading in HOWTO's and other documentation.

I would appreciate some comments from the system administrators  on
this list on the questions below.  Here are some issues of which I am
not certain:

1. The minimum and maximum length of the password: My answer was 0 and
   128.  0 because it is possible to have a user without a password.
   The 128 was because of "#define MAXLEN 127" in getpass.c in the
   souces of the shadow library.  But why does the the "Linux Shadow
   Password HOWTO" say:

   "Most Shadow Suites contain code for doubling the length of the
   password to 16 characters. Experts in des recommend against this,
   as the encoding is simply applied first to the left half and then to
   the right half of the longer password. Because of the way crypt works,
   this may make for a less secure encoded password then if double length
   passwords were not used in the first place. Additionally, it is less
   likely that a user will be able to remember a 16 character
   password."

2. Can the reuse of previous passwords be prevented?  I found some
   references in the pam documentation about a password history but I
   am not sure how it can be used to prevent a user to reuse an old
   password.

3. Can the use of numeric, uppercase and lower case characters in
   certain positions in the password be enforced?  My answer was that
   it can be done with a wrapper script but I do not think it was a
   wise thing to do.

4. Is it possible to force a user to make changes to at least a
   certain number of characters in the password when changing the
   password?  I think it should be possible but I don't know how it
   can be done with standard libraries.  This question is related to
   question 2.

5. Can you ensure that the username and password are not the same?
   While I suppose the usage of cracklib should prevent most usernames
   to be used as passwords because are weak, I do not know of a
   spesific measure to prevent that.

6. Can the "intruder lockout count" be set?  Yes.  Can the "intruder
   locout period" be set?  I am not sure.

7. Is it possible to keep a log of password changes?  I suppose
   the logging question does not refer to the logging of the physical
   passwords, but the password-changing activities on the machine.
   How would one implement that?

Regards
Johann
--
Johann Spies          Telefoon: 021-808 4036
Informasietegnologie, Universiteit van Stellenbosch

     "What? know ye not that your body is the temple of the
      Holy Ghost which is in you, which ye have of God, and
      ye are not your own? For ye are bought with a price;
      therefore glorify God in your body, and in your
      spirit, which are God's."      I Corinthians 6:19,20

[demime 1.01d removed an attachment of type application/pgp-signature which had a name of signature.asc]
_______________________________________________
LinuxManagers mailing list - http://www.linuxmanagers.org
submissions: LinuxManagers-35TzE1X9F6582KRnZfj+bdi2O/[email protected]
subscribe/unsubscribe: http://www.linuxmanagers.org/mailman/listinfo/linuxmanagers