Summary: Questions about passwords

Johann Spies <jspies-/[email protected]> Fri, 2 Jul 2004 15:15:10 +0200
Newsgroups gmane.linux.admin.managers
Message-ID <[email protected]>
First my apology for a late summary.  I forgot about it.

Three persons have reacted to my question: John Robinson, Mark Street
and Tom Yates. Thank you to them.  I also include references to
documentation supplied by Tom.

My questions:

1. About the minimum and maximum length of a Linux password.

The reference to a maximum of 15 characters in the "Linux Shadow
Password HOWTO" is referring to the old DES encryption. Md5-passwords
can have a maximum length of 128 characters but to quote Tom:
"using modern md5 hashes, the password length is restricted only by
MD5's maximum message size of 264 bits[1], which means anything over
about 70 standard (8-bit clean) characters is pointless."


2. Can the reuse of previous passwords be prevented?

Yes.  John recommended npasswd for many of the issues addressed in my
questions. Npasswd keeps a record of previous (default 3) passwords
and can compare your password with it. Although PAM modules and syslog
can be used for logging changed passwords, it is undesirable.

An url for npasswd:

http://www.utexas.edu/cc/unix/software/npasswd

Tom: "if he insists, section 6.3 of [2] documents the use of the opasswd file
to enable this via pam_cracklib."

3. Can the use of numeric, uppercase and lower case characters in
   certain positions in the password be enforced?

   Using pam_craclib can test new passwords but I am not sure whether
   it can test for spesific characters in speficied positions in the
   password.

   Npasswd can do it.

4. Is it possible to force a user to make changes to at least a
    certain number of characters in the password when changing the
    password?

 John: "Not without keeping a copy of the unencrypted password. This is
      obviously a very bad idea."

Cracklib however will complain when a password is too similar to the
old one.

5. Can you ensure that the username and password are not the same?

Yes.  Both pam and npasswd can do it.

6. Can the "intruder lockout count" be set?  Yes.  Can the "intruder
   locout period" be set?  I am not sure.

   Still no certainty about the last question.

7. Is it possible to keep a log of password changes?

   Tom: "section 6.3 of [2] refers to the use of the "debug" flag with
   pam_cracklib, to make it log the results of its deliberations about the
   new password the user provides via syslog.  obviously, logging actual
   password information would be *deeply* stupid, so it doesn't do this."

[1] http://www.usenix.org/events/usenix99/provos/provos_html/node10.htm
[2] http://www.kernel.org/pub/linux/libs/pam/Linux-PAM-html/pam-6.html

Thanks for the replies.  I have learnt a lot.

Regards
Johann
--
Johann Spies          Telefoon: 021-808 4036
Informasietegnologie, Universiteit van Stellenbosch

     "And be ye kind one to another, tenderhearted,
      forgiving one another, even as God for Christ's sake
      hath forgiven you."
                                   Ephesians 4:32

[demime 1.01d removed an attachment of type application/pgp-signature which had a name of signature.asc]
_______________________________________________
LinuxManagers mailing list - http://www.linuxmanagers.org
submissions: LinuxManagers-35TzE1X9F6582KRnZfj+bdi2O/[email protected]
subscribe/unsubscribe: http://www.linuxmanagers.org/mailman/listinfo/linuxmanagers