Questions about passwords
Johann Spies <jspies-/[email protected]> Tue, 22 Jun 2004 10:35:55 +0200
| Newsgroups | gmane.linux.admin.managers |
|---|---|
| Message-ID | <[email protected]> |
My manager is drawing up a password policy for the different operating
systems on the campus. He has asked a few questions about Linux's
handling of passwords which was not so easy to answer even after a lot
of googling and reading in HOWTO's and other documentation.
I would appreciate some comments from the system administrators on
this list on the questions below. Here are some issues of which I am
not certain:
1. The minimum and maximum length of the password: My answer was 0 and
128. 0 because it is possible to have a user without a password.
The 128 was because of "#define MAXLEN 127" in getpass.c in the
souces of the shadow library. But why does the the "Linux Shadow
Password HOWTO" say:
"Most Shadow Suites contain code for doubling the length of the
password to 16 characters. Experts in des recommend against this,
as the encoding is simply applied first to the left half and then to
the right half of the longer password. Because of the way crypt works,
this may make for a less secure encoded password then if double length
passwords were not used in the first place. Additionally, it is less
likely that a user will be able to remember a 16 character
password."
2. Can the reuse of previous passwords be prevented? I found some
references in the pam documentation about a password history but I
am not sure how it can be used to prevent a user to reuse an old
password.
3. Can the use of numeric, uppercase and lower case characters in
certain positions in the password be enforced? My answer was that
it can be done with a wrapper script but I do not think it was a
wise thing to do.
4. Is it possible to force a user to make changes to at least a
certain number of characters in the password when changing the
password? I think it should be possible but I don't know how it
can be done with standard libraries. This question is related to
question 2.
5. Can you ensure that the username and password are not the same?
While I suppose the usage of cracklib should prevent most usernames
to be used as passwords because are weak, I do not know of a
spesific measure to prevent that.
6. Can the "intruder lockout count" be set? Yes. Can the "intruder
locout period" be set? I am not sure.
7. Is it possible to keep a log of password changes? I suppose
the logging question does not refer to the logging of the physical
passwords, but the password-changing activities on the machine.
How would one implement that?
Regards
Johann
--
Johann Spies Telefoon: 021-808 4036
Informasietegnologie, Universiteit van Stellenbosch
"What? know ye not that your body is the temple of the
Holy Ghost which is in you, which ye have of God, and
ye are not your own? For ye are bought with a price;
therefore glorify God in your body, and in your
spirit, which are God's." I Corinthians 6:19,20
[demime 1.01d removed an attachment of type application/pgp-signature which had a name of signature.asc]
_______________________________________________
LinuxManagers mailing list - http://www.linuxmanagers.org
submissions: LinuxManagers-35TzE1X9F6582KRnZfj+bdi2O/[email protected]
subscribe/unsubscribe: http://www.linuxmanagers.org/mailman/listinfo/linuxmanagers