Re: Cloud image user passwords encrypted by md5 by default?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, Aug 1, 2015, at 01:34 AM, Sitsofe Wheeler wrote:
> 
> The regular Fedora 22 default for password encryption seems to be
> SHA512 but I couldn't turn anything up as to why cloud images had made
> this change. Could some explain why MD5 is used?

This was just fixed:

https://git.fedorahosted.org/cgit/spin-kickstarts.git/commit/?id=9f254062c3c78d8480b04b340c1497c08126c0ca

There was nothing intentional here, but what we're fighting is the legacy defaults for
auth in Anaconda, requiring every kickstart user to override them to enable shadow passwords
and sha512.

Confusingly, Anaconda has defaults that apply *only* when used interactively:
https://github.com/rhinstaller/anaconda/blob/master/data/interactive-defaults.ks#L3

Currently then, media installs have stronger defaults than kickstart, unless overridden
explicitly by kickstart.
_______________________________________________
cloud mailing list
cloud@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/cloud
Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct




[Index of Archives]     [Fedora General Discussion]     [Older Fedora Users Archive]     [Fedora Advisory Board]     [Fedora Security]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [ATA RAID]     [Fedora Marketing]     [Fedora Mentors]     [Fedora Package Announce]     [Fedora Package Review]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Coolkey]     [Yum Users]     [Big List of Linux Books]     [Yosemite News]     [Linux Apps]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]

  Powered by Linux