Re: Strong password checks
Mike Jackson <[email protected]> Fri, 28 Jan 2005 22:37:57 +0200
| Newsgroups | gmane.network.directoryadmin |
|---|---|
| Message-ID | <[email protected]> |
Adam Tauno Williams wrote:
>>DA does not work through PAM. The recommended method to do so is to
>>script with PAM.d configuration files or other methods so that, upon
>>first logon, the user needs to change his password. The PAM_ldap module
>>is able to change passwords. Check the archives.
>
>
> Most DSAs include modules or overlays to enforce password
> strength/policy, including OpenLDAP. This should be up to the DSA.
There is nothing in RFC 2251 about password complexity, which means that if we support it then we
support it in a different way for every directory server. It is not transparent.
Password hashing can be done either by the server or the client in a transparent manner, so that is
fine. For example, if the client sends a plain password, then the server will hash it per
configuration, e.g. {SHA1}..., but if the client sends a {CRYPT} or {SHA1}, then the server should
not rehash that (at least Netscape DS does not rehash it when prefixed).
--
mike
-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl